Illumio integrator in Switzerland
We deploy Illumio to contain lateral movement — mapping the real flows, then applying segmentation in stages, without touching the existing network.
Why this vendor
Ransomware does no damage at the moment it enters. It does damage in the hours that follow, spreading from one machine to the next. Almost every security investment addresses the entry; very few address what happens afterwards. That is precisely Illumio's bet: assume something will get in, and make sure it goes nowhere.
The architectural choice is what makes the approach workable. Policy is enforced by the firewalls already present in the operating systems, those of Windows and Linux, rather than by network equipment. So there is nothing to recable, no VLAN to redesign, no outage window to negotiate — which explains why these projects finish where traditional network redesigns get stuck.
The difficulty is elsewhere, and it is human. Segmenting requires knowing which server talks to which other, and why. That knowledge is written nowhere: it lives in the heads of a few people, some of whom have left. Mapping the real flows is therefore the true first step, and it has value in itself, independently of any policy.
Our offensive practice sheds light on the exercise. An internal penetration test shows concretely the path an attacker takes from a compromised host — and that path designates which segmentations to put in place first, far better than theoretical reasoning about server criticality.
- Mapping the real flows before any rule
- A label model that lasts
- Prioritisation by observed attack paths
- Gradual enforcement, always reversible
- Verification by internal penetration test
What segmentation changes
The products we integrate
Two products under the vendor's containment platform: one enforces segmentation, the other watches what circulates.
Segmentation
Illumio Segmentation maps communications between workloads, then enforces policy through the firewalls already present in the operating systems. On-premises servers, virtual machines, containers and endpoints fall under the same model. Every rule is first tested in simulation: you see what it would block before it blocks anything.
Observation and detection
Illumio Insights analyses flows to surface what has no business happening — a workstation querying a domain controller for no reason, a server suddenly talking to thirty machines. Those movements are invisible to a perimeter firewall, which only sees what enters and what leaves.
The vendor calls its platform breach containment, and the intent is exact: the aim is not to prevent intrusion but to limit its reach. Putting a rule between workstations and backup servers takes only a few hours and takes away ransomware's most valuable target. That is where we start, with Illumio Segmentation.
How we proceed
No rule is enforced before it has been observed in simulation. That is what makes these projects acceptable to the operations teams.
This service in practice
Frequently asked questions
Intrusion will happen. Will it get far?
Describe your environment — mapping the flows is already worth it on its own.