Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Illumio integrator in Switzerland

We deploy Illumio to contain lateral movement — mapping the real flows, then applying segmentation in stages, without touching the existing network.

Why this vendor

Ransomware does no damage at the moment it enters. It does damage in the hours that follow, spreading from one machine to the next. Almost every security investment addresses the entry; very few address what happens afterwards. That is precisely Illumio's bet: assume something will get in, and make sure it goes nowhere.

The architectural choice is what makes the approach workable. Policy is enforced by the firewalls already present in the operating systems, those of Windows and Linux, rather than by network equipment. So there is nothing to recable, no VLAN to redesign, no outage window to negotiate — which explains why these projects finish where traditional network redesigns get stuck.

The difficulty is elsewhere, and it is human. Segmenting requires knowing which server talks to which other, and why. That knowledge is written nowhere: it lives in the heads of a few people, some of whom have left. Mapping the real flows is therefore the true first step, and it has value in itself, independently of any policy.

Our offensive practice sheds light on the exercise. An internal penetration test shows concretely the path an attacker takes from a compromised host — and that path designates which segmentations to put in place first, far better than theoretical reasoning about server criticality.

Illumio
What we bring
  • Mapping the real flows before any rule
  • A label model that lasts
  • Prioritisation by observed attack paths
  • Gradual enforcement, always reversible
  • Verification by internal penetration test
Vendor website
Diagram

What segmentation changes

Flat network versus Illumio segmentation: spread from a compromised host Flat network one segment, no internal control Illumio segmentation only legitimate flows are allowed Compromised hostCompromised host ServersDatabasesBackupsServersDatabasesBackups Lateral movement is unrestrictedMovement stops at the first hop
The compromised host is the same on both sides. Only the distance it can travel before being stopped changes.

The products we integrate

Two products under the vendor's containment platform: one enforces segmentation, the other watches what circulates.

Segmentation

Illumio Segmentation maps communications between workloads, then enforces policy through the firewalls already present in the operating systems. On-premises servers, virtual machines, containers and endpoints fall under the same model. Every rule is first tested in simulation: you see what it would block before it blocks anything.

Illumio Segmentation

Observation and detection

Illumio Insights analyses flows to surface what has no business happening — a workstation querying a domain controller for no reason, a server suddenly talking to thirty machines. Those movements are invisible to a perimeter firewall, which only sees what enters and what leaves.

Illumio Insights
The principle

The vendor calls its platform breach containment, and the intent is exact: the aim is not to prevent intrusion but to limit its reach. Putting a rule between workstations and backup servers takes only a few hours and takes away ransomware's most valuable target. That is where we start, with Illumio Segmentation.

Illumio Segmentation
Our approach

How we proceed

No rule is enforced before it has been observed in simulation. That is what makes these projects acceptable to the operations teams.

Illumio integration approach, from mapping to operations ScopingImplementationDuration01Flowmapping02Labelmodel03Policies insimulation04Gradualenforcement05ContainmentverifiedOperationsor handover
Simulation shows what a rule would block before it blocks: without it, the first outage ends the project.
Frequently asked questions

Frequently asked questions

No, and that is what sets the approach apart. Policy is enforced by the firewalls already present in the operating systems, not by network equipment. No VLAN to redo, no addressing to revisit, no outage window to negotiate — the reason these projects finish where traditional redesigns stall at the architecture board.

Mapping delivers value within the first weeks, before any rule: it almost always reveals flows nobody knew existed. The first useful segmentation — isolating backups from workstations — takes a few days and removes ransomware's principal target.

It should never reach production without going through simulation, which shows exactly what it would block. An enforced policy also remains reversible within moments. The real risk is not technical: it is segmenting from obsolete documentation instead of the flows actually observed.

By trying to cross it. An internal penetration test, run from a workstation as an attacker would, measures the distance actually travelled — before and after. It is the only verification that does not rely on reading your own configuration, and we run it ourselves.

Intrusion will happen. Will it get far?

Describe your environment — mapping the flows is already worth it on its own.