All posts

Why microsegmentation matters: meeting John Kindervag

Why microsegmentation matters: meeting John Kindervag (KAEMI)

Some encounters stay with you. I recently had the opportunity to meet John Kindervag in person: the man who coined the term Zero Trust. What impressed me was not the title “creator of Zero Trust” but his clarity: no buzzwords, no product pitch, just a simple principle thought through to its logical end. And one point he stressed emphatically: without microsegmentation, Zero Trust remains theory.

How Zero Trust came about

Kindervag did not invent Zero Trust on a drawing board, but by consistently questioning an assumption everyone took for granted. For decades the rule was: trustworthy inside, dangerous outside; the firewall draws the line. Exactly this implicit trust on the inside is the design flaw. Insiders and, above all, the lateral movement of an attacker who has gotten in undermine the model. His conclusion: no network segment automatically deserves trust.

An attitude he sums up in a memorable line: “You must validate the things everyone says and see if they're true.” You have to question what everyone considers self-evident, especially in security.

The point that stuck with me: microsegmentation is not a detail

In many conversations, Zero Trust gets reduced to identity and MFA. Kindervag is clear on this point: microsegmentation is the mechanism that actually enforces Zero Trust. It divides the network not coarsely but at fine granularity, down to the workload level, and governs who may communicate with whom. That limits the blast radius of an incident: if a system is compromised, the attacker cannot keep moving laterally from one system to the next. The damage stays local instead of escalating to full access.

Shrink the attack surface instead of defending the perimeter

The shift in perspective he describes is decisive: instead of defending an ever-growing attack surface on the outside, you shrink the area to be protected on the inside, the “protect surface.” You specifically protect what is valuable (data, applications, services) and govern the traffic to it according to the least-privilege principle. Microsegmentation is the technique that implements exactly this in the running environment, independent of the traditional network layout.

It's about workloads, not distrust

One misunderstanding keeps coming up: Zero Trust supposedly sounds as if you distrust your own colleagues. Kindervag clears that up, and I found it liberating. Zero Trust is not a statement about people but about technology: controls protect packets and workloads, not “the people on the network.” Microsegmentation does not decide whom we trust, but which systems are allowed to talk to each other in the first place. This decoupling takes the emotion out of the debate and turns it into what it really is: an architecture question.

Visibility first: protect what you can see

One point that is often skipped in practice and causes projects to fail: you can only protect what you know. Before you segment, you have to make the applications and their dependencies visible: which service talks to which, over which ports, in which direction. Only this map makes meaningful rules possible; without it, you segment blindly and either break legitimate processes or leave gaps open. Visibility is therefore not a warm-up act but the first real step.

His most important practical advice: not too big, not too fast

What I particularly liked as a practitioner: Kindervag explicitly warns against starting too big and too fast. Zero Trust rarely fails on principle; it fails in big-bang projects. His path is iterative: a manageable protect surface first, gather experience, then the next one. It is this modesty that makes the concept workable in everyday practice at all.

More than lateral movement: containing ransomware

The value of microsegmentation does not end with stopping lateral movement. It also limits the impact of ransomware and data exfiltration: what is not allowed to communicate cannot spread and cannot leak anything out. That shortens attacker dwell time and reduces the scale of damage, legal risk, and reputational harm, an argument that is convincing well beyond the technology. And because clear, fine-grained rules simplify daily work, good segmentation also takes load off the security teams.

Why this confirms our approach at KAEMI

For us, this is not abstract theory. As Illumio EMEA Partner of the Year, we implement microsegmentation every day, specifically as the part of Zero Trust that actually stops lateral movement rather than merely promising to. Meeting John Kindervag reinforced a conviction that carries our work: Zero Trust is a strategy, not a product. Microsegmentation is the point where it makes the difference when it counts. Requirements-driven, in phases, and aligned with the reality of our customers.

Sven Launspach, CEO KAEMI

Want to stop lateral movement before an incident spreads?

KAEMI designs, implements and manages Zero Trust segmentation down to the workload — from the dependency map to the managed service.