Implementing enterprise wide segmentation.
Download resourcesAbout this session
Jon Brown of Forescout presents the company's approach to enterprise-wide, zero-trust segmentation and then demonstrates its eyeSegment product. He frames segmentation with two rules: devices with no reason to talk should be blocked outright, and those that must talk should be limited to the ports and protocols they need. The difficulty, he argues, is brownfield reality: networks built for uptime, a patchwork of switching, wireless, data-centre, cloud and firewall vendors, and nobody who knows what already talks to what. Forescout's answer is agentless classification of every device, collection of flow telemetry (NetFlow, IPFIX, SPAN, cloud flow logs) into a cloud service that maps communications, and a matrix view where risky flows, such as a sales user reaching a database over SSH, surface immediately. The demo builds zero-trust and targeted rules from observed traffic, runs them in simulation against ninety days of history to predict who would break, then hands enforcement to existing switches, firewalls, NSX, cloud security groups, ServiceNow or CrowdStrike. A round-table Q&A followed but is not on the recording.
Steven has over 20 years of experience in cybersecurity architecture and enterprise
technologies, working across areas such as segmentation, cloud, endpoint, regulatory compliance, application and infrastructure security. For years he has been and still is an active contributor to intelligence sharing communities and conferences.
"To address your multi-domain, multi-use case security scenarios, you are required to be agile if you want to be Cyber resilient. Your business must meet compliance obligations towards Cyber Risks. In today’s ever evolving digital world, how will you:
• Achieve a near-real time visibility over what is connected to, beyond the users
and your IAM control?
• Eliminate disparate device access policies?
• Address the Zero Trust security framework?
Join Forescout for this presentation that will cover those complex questions. Forescout helps organizations of all size in implementing a more
mature Cybersecurity model that prevents lateral threat propagation within your
environment.
Key takeaways you will get attending this presentation:
1. Identify the baseline communication and attack surface, using real-time traffic
of any “thing”.
2. Map data flows and system interdependencies.
3. Determine least privilege access leveraging user and device security context.
4. The recipe for non-disruptive segmentation at every level: EDR, Switch, WLC, VPN,
Firewalls, hypervisors and Cloud.
Key takeaways
- Start any segmentation program with two rules: block device pairs that have no business talking, and restrict the rest to the exact ports and protocols they need.
- Get a current-state map of communications before touching enforcement; most organisations do not know what already talks to what, and that ignorance is what stalls projects.
- Run new policies in simulation against months of flow telemetry so monthly or quarterly jobs surface before a change window, not after an outage.
- Enforce with what you already own (switch ACLs, security group tags, firewall tags, cloud security groups) rather than adding another enforcement layer.
- Keep monitoring after deployment: a troubleshooting change that disables a firewall rule should trigger an alert or a ServiceNow incident, not go unnoticed.
Speakers

Jon has over 20 years of experience in network technologies including as a Product Manager, Systems Engineer, Cyber Security Specialist and Network Segmentation Overlay across diverse business segments and geographic regions.
