Cybersecurity is about small, targeted moves: 20% of the right actions prevent 80% of the risk. Find your 20%: assess your exposure →

02. Cybersecurity

Zero Trust, segmentation and SASE under real conditions

What segmenting a live network actually costs, how you cut over without downtime, and why most Zero Trust projects stall right after the audit.

Key points

  • Segmenting a live network means accepting that something will break; the whole job is choosing what.
  • Mapping real traffic comes before design: an official architecture diagram rarely describes what actually flows.
  • Observation mode before enforcement mode is what makes the cutover reversible.
  • Zero Trust does not require replacing everything: it requires knowing who reaches what, and verifying it.

Why most Zero Trust projects stall after the audit

Because the analysis phase is comfortable and the cutover is not. The mapping is produced, the report is delivered, and nobody wants to be the person who cuts a flow on Monday morning. The project then stays at the documentary stage, with cost incurred and no risk reduced.

The blockage is not technical, it is organizational. Cutting a flow requires knowing what it serves, who will complain, and how quickly you can roll back. Without those three answers in writing, no reasonable operations manager authorizes the cutover.

That is why we treat segmentation as an operations project rather than a security project. Decisions are taken with the application teams, not against them, and every step has its rollback window.

The consequence is a longer schedule than most proposals advertise. It is also why our cutovers get completed.

How do you segment without interrupting service?

In four stages, three of them reversible. Passive discovery of real traffic, zone definition with the business teams, rules applied in observation mode, then enforcement zone by zone. At each step, a written success criterion and a rollback window that has actually been exercised.

  • Passive discovery. You observe what genuinely flows, over a period covering the business cycles: month end, close, overnight backups. A rare flow is a flow you cut by mistake.
  • Zone definition. Decided with the application owners, because only they know what must talk to what. A zone drawn from a network diagram produces permanent exceptions.
  • Observation mode. Rules are written and evaluated but block nothing. Discrepancies surface with no consequence for users, and are corrected in calm conditions.
  • Zone-by-zone enforcement. One zone at a time, with a success criterion and a rollback window that has actually been tried, not merely documented.

What does Zero Trust actually require?

That no user or device is granted implicit trust merely for being inside the network. In practice this means verifiable identity, explicit authorization per resource, and usable logging. It does not require replacing existing infrastructure.

The most widespread misreading treats Zero Trust as a product. No vendor sells Zero Trust: it is an architectural principle applied with the components you have, filling the gaps that remain.

The second misreading treats it as a state to reach. It is a trajectory: you progressively reduce implicit trust, starting where it costs the most: payment systems, sensitive data, administrative access.

The right opening question is therefore not "how do we become Zero Trust" but "where does implicit trust expose us most today".

SASE or VPN: what actually changes?

A VPN pulls traffic back to the data centre before letting it out again, which penalizes cloud applications and often grants broad access to the internal network. SASE moves security closer to the user and authorizes per application rather than per tunnel. The gain is as much operational as it is security.

The difference shows on two points. Hybrid work performance first: a user reaching a cloud application has no reason to transit through head office. Then the access perimeter: a VPN tunnel generally opens far more than the user needs.

SASE is not a universal answer for all that. It presumes mature identity management, because authorization shifts onto identity. An organization whose accounts are poorly kept will relocate its problem rather than solve it.

We check that point before recommending the architecture, and it sometimes leads to treating identity management first.

Frequently asked questions

Rarely in full. Segmentation builds first on what exists: switches, firewalls, access controllers, directory. The work consists of using their real capabilities, often underexploited, and identifying the few points where a component is genuinely missing. We establish that gap before recommending any purchase, and since we resell no licences, that conclusion earns us nothing.

It depends on the number of zones, the quality of existing documentation and the availability of application teams: we do not announce it in advance. What is constant is the sequencing: discovery must cover a full business cycle, and each zone cutover is followed by an observation period before the next.

Through the traceability of inter-zone access, which becomes usable once zones are defined. This is in fact one of the least anticipated benefits of the work: a flat network demonstrates very little, whereas a segmented network naturally produces the evidence auditors and regulators ask for.

Yes, but the sequence differs: you start with an inventory of connected assets, because industrial environments almost always contain equipment unknown to the IT department. Observation mode runs longer, and some cutovers are scheduled during planned shutdown windows. Reversibility matters even more there than elsewhere.

With them, by default. Segmentation produces rules somebody will maintain for years: if your teams did not take part in the trade-offs, they will inherit a setup they dare not modify. Knowledge transfer is part of the work, not an option at the end of the project.

Sources

Is your infrastructure ready for the next threat?

An initial assessment, free and without commitment, to evaluate your security posture.

Home Expertise RISS 360 PME Assess