Case study insurance: Microsegmentation under DORA
Servers, terminal servers and Kubernetes in one segmentation model: KAEMI introduced Zero Trust microsegmentation at a German insurance company, a professional services project from the first dependency map to the handover to the internal team, co-managed ever since. The EU regulation DORA set the pace.
The starting point
Insurance companies fall under DORA, EU Regulation 2022/2554 on digital operational resilience in the financial sector, applicable since 17 January 2025. The company's perimeter was well built. Inside, it looked the way most grown infrastructures do: once you are in, you get far. Nobody had a complete view of the east-west traffic between the systems.
On top of that came three very different workload worlds: classic servers in the data center, terminal server farms for the business applications and a growing Kubernetes platform. Network-centric firewalls only inspect this traffic at zone boundaries. What happens inside a zone or inside the cluster remained invisible and unregulated.
The assignment for KAEMI: establish visibility, design a segmentation model for all three worlds, introduce it without downtime and hand it over in a way that lets the internal team carry the segmentation forward on its own. And document all of it so that it stands up in front of internal auditors and the supervisor. As usual for references from regulated industries, we do not name the customer.
The project at a glance
- Industry
- Insurance
- Location
- Germany
- Environment
- Servers in the data center, terminal server farms, Kubernetes
- Driver
- DORA (Regulation (EU) 2022/2554)
- Scope
- Professional services: analysis & design, rollout, handover to the internal team, co-managed support
Anonymised at the customer's request.
The regulatory frame
What DORA demands of network security
DORA prescribes no vendor and no product. But the regulation and its regulatory technical standard formulate requirements to which segmentation can make a substantial contribution. Four of them shaped the project.
Identify (Art. 8)
DORA requires financial entities to know their ICT landscape and its dependencies. The dependency map shows continuously which systems talk to which: a living inventory instead of an outdated network sketch.
Protect and prevent (Art. 9)
The regulatory technical standard accompanying DORA (Delegated Regulation (EU) 2024/1774, Art. 13) explicitly calls for the segmentation of networks, graded by the criticality of the functions they support. Microsegmentation addresses exactly this requirement, enforced at the individual workload.
Contain and keep working (Art. 11)
Response and recovery presuppose that an incident stays local. Compromised workloads can be isolated while critical processes keep running. The blast radius of an attack becomes a quantity you can plan for.
Provide evidence (Art. 5 and 6)
Supervisors (in Germany, BaFin) expect risk management you can prove. Communication map, policies and change history are available as audit artefacts; nobody has to gather them from scratch for every audit.
The environment
Three workload worlds, one segmentation model
Each of the three worlds brings its own difficulty. The decisive point was not to answer them with three separate solutions, but with one model that speaks the same language everywhere.
Servers in the data center
The insurer's core systems, from policy administration to claims handling, first received ringfencing: a protective ring around each critical application. The rules are enforced directly at the workload, not at a zone boundary. Even neighbours in the same network segment only reach the application if a rule allows it.
Terminal servers
Many users share one system, and classic IP rules cannot tell who opens a connection. So user- and group-based rules apply here: each session only reaches the applications that belong to its role. A compromised session stays contained and no longer serves as a stepping stone into the data center.
Kubernetes
Pods come and go, IP addresses are ephemeral. The rules therefore follow workload identity (labels and namespaces) instead of address lists. East-west traffic inside the cluster becomes visible, and connections between cluster, VMs and databases follow the same policy model as the rest of the environment.
The approach
Four phases to enforced segmentation
Segmentation rarely fails because of the technology, often because of the approach. So no rule goes live whose effect was not visible in the simulation first.
-
Visibility first
Sensors rolled out on servers, terminal servers and in the cluster, then several weeks of observing real traffic. The result is a dependency map across all three worlds: a reliable picture that also shows the connections nobody had thought about any more.
-
Model and simulation
A tag model of environment, application and role instead of IP lists. Ringfencing of the critical applications first, then finer rules down to the microsegmentation of individual workloads. Everything in simulation mode at first: the platform shows what a rule would block before it does.
-
Step-by-step enforcement
Enforcement went live application by application, in each case only once the simulation no longer reported legitimate connections, coordinated with the business units. That way the rollout needed no downtime.
-
Handover to the internal team
Documentation, runbooks and training to finish: the internal team took over the lead on the platform with clear processes for new rules, new workloads and exceptions. Since then, KAEMI has continued to support the environment co-managed through its professional services.
The result
What the insurer has today
- An up-to-date communication map across servers, terminal servers and Kubernetes that is maintained continuously and does not age into a project document.
- Critical applications inside a ringfence; lateral movement between workloads reduced to the defined minimum.
- User-based rules on the terminal servers: sessions only reach what belongs to their role.
- One policy model for all three worlds, enforced at the workload rather than at zone boundaries.
- Solid evidence for DORA audits: map, policies and change history are available at any time.
- An internal team that leads the segmentation itself after handover and training, co-managed by KAEMI professional services.
Answer the DORA requirements with segmentation
In a joint analysis workshop we make visible where an attacker would spread in your environment, and show how segmentation can support the requirements from DORA. No obligation, and specific to your infrastructure.