Security

Segmentation is where most of our security work sits. We take organisations from no visibility of internal traffic through to enforced, least-privilege policy on their most critical applications — on estates spanning on-premises infrastructure, Azure, AWS, GCP and mainframe.

Abstract diagram of a segmented network estate

Our core practice

Microsegmentation and Zero Trust

We specialise in Cisco Secure Workload, and work alongside Cisco ACI and Nexus, Algosec BusinessFlow and FireFlow, and VMware NSX and vRNI.

How we deliver it

Seven stages, in this order

The order matters. Enforcement without dependency mapping breaks applications, and that is the failure mode organisations are right to be afraid of.

01

Discover

Confirm the business applications in scope, their technical owners, their dependencies and what success looks like.

02

Design

Define scopes, workspaces, labels and annotations, and the approach to policy governance.

03

Onboard

Deploy and validate agents, establish visibility, resolve inventory and deployment issues.

04

Analyse

Review observed flows, map application dependencies, identify shared services and exceptions.

05

Implement

Develop, test and refine least-privilege policy alongside application owners.

06

Enforce

Move validated workloads into enforcement in controlled phases, with change approval, monitoring and rollback planning.

07

Transition

Documentation, training, troubleshooting support and handover into operations.

Track record

Delivered at scale

  • A UK critical national infrastructure operator: 20 crown-jewel workspaces enforced across 5,000+ servers and 2,000 applications
  • A multinational European bank: 2,000+ agents, 10 billion+ monthly flows analysed, 25 workspaces assessed
  • An international insurer: 10 crown-jewel applications enforced, supporting remediation of FCA audit findings
  • A US multi-campus university: 17 applications enforced across 407 agents in six months

Also

The rest of the security practice

Firewall and policy management

Firewall upgrades, rule consolidation and rationalisation, and policy management through Algosec. Where segmentation has been attempted before and left an unmanageable rule base, we untangle it.

Identity and access

Multi-factor authentication, role-based access controls, Cisco ISE, Duo, and Software Defined Perimeter design. Cloud identity across Microsoft Entra.

Cloud security

Security architecture across Microsoft Azure, AWS and Google Cloud, including hybrid estates where the majority of the difficulty usually lies.

Assessments and health checks

Vulnerability assessment, penetration testing, privileged access review and security posture assessment, with remediation support rather than a report handed over at the door.

Frameworks we design to

NIST · ISO 27001 · PCI DSS · NIS2 · DORA · MITRE ATT&CK · Cyber Essentials Plus

How it works

What a segmented estate looks like

Policyengine Endpoints and remote accessSegmented zone Application tierSegmented zone Management planeSegmented zone Data tierSegmented zone

A segmented estate

Hover over any part of the diagram — or tap it on a phone — to see what it does and why it is kept separate.

Why it matters

The scale of the problem

43%

of UK businesses identified a cyber security breach or attack in the last 12 months

£3.13m

average cost of a data breach for UK organisations

$1.93m

saved per incident by organisations using AI and automation in their defences

Sources: Cyber Security Breaches Survey 2025/26, Department for Science, Innovation and Technology. IBM Cost of a Data Breach Report 2026 — figures cover the organisations studied and are not an average across all businesses.

Further reading

Where to look next

Standards and guidance we design to, and the places we point clients when they want to read further.

Get in touch

Talk to us about your segmentation programme.

enquiries@aphsltd.com · 0845 519 8497