Validated Containment Architectures are here. →Explore

Microsegmentation is having its moment. Forrester just mapped the market with its Q3 2026 Wave, and the category is maturing fast. Deployment is getting easier, and more enterprises are segmenting east-west traffic than ever. That's real progress. 

It's worth asking what microsegmentation is for. Teams deploy it because they've accepted the modern premise: breaches happen, and the job is to limit what a compromised workload can reach. That is the containment question: reduce what an attacker can get to once they are already inside. Microsegmentation is the market's answer to it on one plane: reachability between workloads, east-west. So a Wave on microsegmentation is a progress report on one answer to the containment question. The useful thing a security leader can do with it is ask whether that answer is the whole answer. 

It isn't, and not because any product falls short. “What a compromised workload can reach” runs well past east-west: it reaches out through egress, it rides valid credentials, it lands on managed services and serverless where no segmentation agent sits. Microsegmentation and containment are the same instinct, limit the reach, at different scope. Knowing where one ends and the other begins is what tells you where your exposure still lives. 

All Containment is Not Equal 

Every serious vendor now says “containment.” The word has converged faster than the architecture behind it has. Now, the useful question is what their architecture actually leaves reachable. 

Containment, stated precisely, is the architectural enforcement of explicit communication policy at every workload — governing what it can reach and what can reach it, at the granularity of workload identity and protocol, on every path available to it, independent of whether a compromise has been detected. 

Both microsegmentation and containment start from one idea: a compromised workload should not be able to reach whatever it likes. Microsegmentation acts on that instinct where most breaches move first — east-west, between workloads inside the estate — and shrinks that reachability. Containment carries the same instinct to its conclusion: applied not only east-west but to egress and north-south, not only where an agent can run but to every compute model, not only after a signal fires but before it, and propagated as one policy across every cloud. 

That is what the five testable properties measure: the full version of what microsegmentation begins. An architecture either demonstrates each one or it doesn't: 

Property 

The Test 

Path-complete 

Does enforcement govern every communication path, or only the paths that traverse the enforcement point? 

Identity-aware at Layer 7 

Is policy expressed at workload identity and protocol, or at addresses and ports? 

Detection-independent 

Does enforcement hold before anything is detected, or does it wait on a signal? 

Compute-model agnostic 

Does it reach every compute model, or only where its mechanism can be installed? 

Universally propagated 

Does one policy change reach every provider, region, and cluster in subseconds, or does intent get re-expressed per environment and drift? 

 A microsegmentation project is the right first move, and it maps cleanly onto that rubric. At its best it contributes to identity-aware, east-west enforcement, the reachability between workloads that attackers exploit first. Where it stops is the edge of the technique. It reaches only as far as its mechanism installs: an agent, an appliance, a switch, a hypervisor. Serverless functions, managed services, managed model runtimes, and partner networks fall outside it. And it governs traffic between workloads, not the egress path out or the policy drift across clouds. 

Those are precisely the planes the five properties test in full: and the ones a segmentation project, by its nature, reaches last or not at all. So instead of microsegmentation versus containment, it's the same line continued. Containment is where the east-west segmentation you have already deployed keeps going: onto every path, every compute model, and every cloud, and held there whether or not anything has been detected. 

The Exposure a Segmentation-Only Architecture Leaves 

Each property a segmentation-only architecture leaves ungoverned is a property a real, public breach walked straight through: 

  1. Path-complete. SolarWinds / SUNBURST, 2020The trojanized Orion update beaconed out over DNS to an attacker-controlled domain, then opened a command channel over ordinary outbound web traffic. Its command-and-control ran on a north-south egress path that a workload-to-workload segmentation policy never sees. 

  2. Identity-aware at Layer 7. Shai-Hulud, 2025The npm worm used each victim's own token to push stolen secrets to a public GitHub repository, riding allowlisted github.com. A policy that allows github.com cannot tell your repo from an attacker's dump. 

  3. Detection-independent. Snowflake / UNC5537, 2024165 organizations breached with valid stolen credentials, no exploit and no malware on the platform. Legitimate authentication produces no signal to detect.  

  4. Compute-model agnostic. Capital One, 2019An SSRF reached the EC2 metadata service, yielded IAM credentials, and read 106M records from S3, a managed service where no host agent runs. 

  5. Universally propagated. Cloudflare, 2023 After the Okta breach, thousands of credentials rotated but four missed: one service token and three service accounts wrongly believed unused. The policy in force lagged the policy intended, and the attacker used the gap. 

 None of these is a segmentation failure between workloads. They are egress, credential, managed-service, and propagation failures: different properties, different exposure. However well the east-west layer is deployed, it does not close them. 

Instead of Shopping for a Grade, Measure Your Exposure 

The instinct in a maturing market is to ask which vendor “has containment,” but that's the wrong question; it invites a race to the lowest passing line. The better question is the one an attacker is already answering: what can one compromised workload in your environment actually reach? 

That is your blast radius, and it is measurable. Segment your east-west traffic, then measure the exposure the segmentation layer leaves: the egress paths, the managed services and serverless functions no agent covers, the enforcement that waits on detection, the policy that drifts across clouds. 

If you run a stack of security categories today like an NGFW, security groups, a service mesh, or a CNAPP, that's worth testing too. Each governs one slice, and none understands the others; stacking them does not, on its own, shrink what a compromised workload can reach. 

Use the free Aviatrix Workload Attack Path Assessment to find the exploitable paths and containment gaps in your environment before an attacker does: measured not from an architecture diagram, but from your real runtime flows. 

Forrester and Forrester Wave are trademarks of Forrester Research, Inc. Aviatrix is not a Forrester client and was not evaluated in the report. 

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
How Zero Trust Was Born | In Progress episode with John Kindervag

How Zero Trust Was Born | In Progress, Episode 5

Sep 02, 20265 min read
Bedrock Guardrails Won-t Stop an Exfiltrating Agent, But Here's What Will

Bedrock Guardrails Won't Stop an Exfiltrating Agent, But Here's What Will

Sep 01, 20265 min read
Messages that Waited 30 Years: Preparing for Quantum Computing

Messages that Waited 30 Years: Preparing for Quantum Computing

Aug 27, 20268 min read
Frontier AI Critical Defense Program Virtual Patching Buys You Time, Not Reach

Frontier AI Critical Defense Program: Virtual Patching Buys You Time, Not Reach

Aug 26, 202610 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image