惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
WordPress大学
WordPress大学
D
DataBreaches.Net
腾讯CDC
小众软件
小众软件
B
Blog RSS Feed
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
U
Unit 42
Y
Y Combinator Blog
V
V2EX
I
InfoQ
D
Docker
量子位
N
Netflix TechBlog - Medium
Recent Announcements
Recent Announcements
A
About on SuperTechFans
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
阮一峰的网络日志
阮一峰的网络日志
MyScale Blog
MyScale Blog

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026
Why Network Segmentation Projects Fail: Four Patterns
Aamer Akhter · 2026-05-26 · via Security @ Cisco Blogs

In previous blogs, I’ve discussed why segmentation matters, the challenges of getting it right, and the benefits that organizations see when they fully commit to both macro- and micro-segmentation. Today, I want to flip the question around. Instead of asking what happens when segmentation succeeds, let’s ask: why do so many segmentation projects fail.

That question is the focus of the newly released Cisco 2026 Segmentation Report, which draws on a survey of 400 failed segmentation projects at U.S.-based organizations with 500 or more employees. The findings are illuminating—and occasionally surprising.

Four Patterns of Failure

When we evaluated each failed project against twelve factors spanning general IT project management and segmentation-specific challenges, four distinct failure patterns emerged:

  1. Perfect Storm (50%). Projects that failed on nearly every front at once. General IT project management issues and segmentation-specific technical challenges hit simultaneously.
  2. Diffuse Friction (33%). Projects that didn’t fail on any single front, but accumulated enough moderate friction across many dimensions that progress stalled.
  3. Operational Drag (9%). Projects where goals and sponsorship were sound, but the burden of creating and maintaining segmentation policies became unsustainable.
  4. Scope & Visibility Trap (8%). Projects defeated by expanding scope, unrealistic timelines, and inadequate visibility into a complex environment.
Four patterns of failure chart

The headline: more than 80% of failed projects stumble on multiple fronts at once, not on a single issue. Segmentation, it turns out, is rarely undone by one bad decision.

Where the Failures Concentrate

Not all segmentation projects are equally risky. Projects that include campus networks or use Layer 2 approaches (like VLANs) are especially prone to Perfect Storm or Scope & Visibility Trap failures. Projects involving IoT environments tend to fall into Diffuse Friction or Operational Drag. Interestingly, workload type (bare metal, virtualized, containerized, serverless) had no significant effect on failure patterns.

A Surprising Disconnect

Perhaps the most striking finding: when practitioners were asked what single change would have made the biggest difference, about 70% pointed to general IT project management fixes—even when the project had failed for segmentation-specific reasons. That ratio held across all four failure patterns.

The takeaway? Strong project management is a necessary foundation, but it’s not sufficient. When a segmentation-specific problem derails a project—a visibility gap, a policy maintenance burden, or tooling limitations—that problem needs a segmentation-specific fix. You can’t meet your way out of a missing asset inventory.

Read the Full Report

The full 2026 Cisco Segmentation Report goes deeper into each failure pattern, the environmental factors that shape them, and practical recommendations for teams planning segmentation projects. Download it here.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram

Authors