Segmentation is where most of our security work sits. We take organisations from no visibility of internal traffic through to enforced, least-privilege policy on their most critical applications — on estates spanning on-premises infrastructure, Azure, AWS, GCP and mainframe.
Our core practice
Microsegmentation and Zero Trust
We specialise in Cisco Secure Workload, and work alongside Cisco ACI and Nexus, Algosec BusinessFlow and FireFlow, and VMware NSX and vRNI.
How we deliver it
Seven stages, in this order
The order matters. Enforcement without dependency mapping breaks applications, and that is the failure mode organisations are right to be afraid of.
01
Discover
Confirm the business applications in scope, their technical owners, their dependencies and what success looks like.
02
Design
Define scopes, workspaces, labels and annotations, and the approach to policy governance.
03
Onboard
Deploy and validate agents, establish visibility, resolve inventory and deployment issues.
04
Analyse
Review observed flows, map application dependencies, identify shared services and exceptions.
05
Implement
Develop, test and refine least-privilege policy alongside application owners.
06
Enforce
Move validated workloads into enforcement in controlled phases, with change approval, monitoring and rollback planning.
07
Transition
Documentation, training, troubleshooting support and handover into operations.
Track record
Delivered at scale
- A UK critical national infrastructure operator: 20 crown-jewel workspaces enforced across 5,000+ servers and 2,000 applications
- A multinational European bank: 2,000+ agents, 10 billion+ monthly flows analysed, 25 workspaces assessed
- An international insurer: 10 crown-jewel applications enforced, supporting remediation of FCA audit findings
- A US multi-campus university: 17 applications enforced across 407 agents in six months
Also
The rest of the security practice
Firewall and policy management
Firewall upgrades, rule consolidation and rationalisation, and policy management through Algosec. Where segmentation has been attempted before and left an unmanageable rule base, we untangle it.
Identity and access
Multi-factor authentication, role-based access controls, Cisco ISE, Duo, and Software Defined Perimeter design. Cloud identity across Microsoft Entra.
Cloud security
Security architecture across Microsoft Azure, AWS and Google Cloud, including hybrid estates where the majority of the difficulty usually lies.
Assessments and health checks
Vulnerability assessment, penetration testing, privileged access review and security posture assessment, with remediation support rather than a report handed over at the door.
Frameworks we design to
NIST · ISO 27001 · PCI DSS · NIS2 · DORA · MITRE ATT&CK · Cyber Essentials Plus
How it works
What a segmented estate looks like
A segmented estate
Hover over any part of the diagram — or tap it on a phone — to see what it does and why it is kept separate.
Why it matters
The scale of the problem
43%
of UK businesses identified a cyber security breach or attack in the last 12 months
£3.13m
average cost of a data breach for UK organisations
$1.93m
saved per incident by organisations using AI and automation in their defences
Sources: Cyber Security Breaches Survey 2025/26, Department for Science, Innovation and Technology. IBM Cost of a Data Breach Report 2026 — figures cover the organisations studied and are not an average across all businesses.
Further reading
Where to look next
Standards and guidance we design to, and the places we point clients when they want to read further.
- ISO/IEC 27001 — the international standard for information security management systems
- NCSC advice and guidance — UK National Cyber Security Centre guidance, by topic
- Cyber Essentials — the UK government-backed scheme covering the basic technical controls
- Cyber Security Breaches Survey — the annual UK government survey of breach prevalence and impact
