Continuous Segmentation is Your Best Defense Against Modern Attacks
Network segmentation has a shelf life problem. Security teams spend weeks or months building segmentation policies: baselining network traffic, defining which devices belong in which groups, what traffic those groups can exchange, and how the NAC should enforce those boundaries. The day those policies go live, they are correct. Then the network does what networks do. Devices get added. Devices and their network traffic evolve. IP addresses shift. And with every change, the gap between what the NAC is enforcing and what it should be enforcing gets a little wider.
This is not a niche worry. In the Cisco 2025 Segmentation Report, 79% of organizations called segmentation a priority, yet only 33% had fully implemented it, and 87% said their approach needs improvement. Cisco and others want microsegmentation to flourish, but follow-through stalls because keeping policy aligned with a dynamic and evolving network is relentless manual work.
Until now, closing that gap meant someone had to notice the drift, diagnose it, rebuild the affected policies, and re-apply them by hand. Carefully. With one eye on operational continuity. Most teams do not have the spare capacity to do that consistently. The result is segmentation that looks complete on paper and leaks in practice.
Visibility specialists could identify device risk but lacked the network policy expertise to translate that into safe enforcement recommendations. Network specialists understood the policy layer but lacked the device-level visibility to assess which changes were safe to make.
Asimily’s Proactive Cyber Defense Platform bridges device visibility, risk assessment, and network policy – and our latest feature release, Continuous Segmentation, as part of Segmentation Orchestration, seeks to solve this problem for organizations.
Policy Built on Intent, Not Static Facts
The root cause of policy drift is how most segmentation gets done: teams identify specific devices, assign them to groups, and write policies around those lists. The problem is the list itself. The moment any device on it changes, or a new device shows up that should have been on it, the policy is stale.
Continuous Segmentation flips the model. Instead of targeting individual devices, you define the criteria that describe a group: device type, manufacturer, function, risk profile, and dozens of other attributes relevant to that segment. Asimily captures that intent and evaluates every device against it continuously. Having a rich understanding of each device (Visibility) becomes the necessary table stakes to perform all the other important analyses that enable Continuous Segmentation.
Another key analysis that feeds Continuous Segmentation is an accurate risk assessment for each device. The risk profile Asimily assigns to each device is grounded in ATT&CK Analysis, which determines actual exploitability in the specific network topology rather than relying on generic vulnerability scores. This means the criteria driving group membership reflect real, ranked risk, not theoretical severity. Threat detection – based on real-time network activity – also can change the risk level of a device in real-time, which can change the desired segmentation policy to deploy.
Humans remain in the loop as much as organizations want, but get the simplicity of receiving and deploying desired policies broadly to reduce risk faster than attackers can find problems. The policy follows the rule without relying on a simple list that might miss a new device or changed behavior or parameters of an existing device. When the network changes, the policy responds. Asimily Continuous Segmentation works through your NAC and firewall infrastructure. Applying policies through Asimily ensures devices are continuously tracked and automatically conform to the intent defined at setup.
Three Common Scenarios, Zero Manual Intervention
A New Device Appears That Has Assigned Segmentation Rules
Asimily detects it through passive monitoring and active safe scanning where appropriate, recognizes the match, and applies the appropriate Group Policies or Dynamic ACLs automatically. The device is segmented soon after it is active on the network, not after the next quarterly policy review.
An Existing Device No Longer Meets the Criteria
A device changes state through a firmware update, a reconfiguration, or a role change. If it no longer belongs in a segment, Asimily removes the previously applied NAC policy automatically. The policy stays accurate without anyone manually auditing group membership.
A Peer Device’s IP Address Changes
Consider a group of tracked devices communicating with a central management server that have a DACL restricting communication just to a single server’s IP address. If the server IP address were to change down the road, then a network administrator needs to remember to update the new address in the DACL to avoid a communication breakdown. Asimily automatically detects such an IP address change and updates the DACL for a seamless transition.
In each of these 3 cases, every action is logged, so the audit trail is complete. The system is also configurable: security teams decide if a policy for a set of devices will be continuously evaluated or not. Further, audit logs help track changes to a device’s policy as its attributes evolve, aiding how Asimily ensures the most appropriate policy is in effect at any time.
Why This Matters Now
The argument is straightforward. Device populations are not static, and enforcement that does not track device changes is not really enforcement. It is a snapshot, and snapshots age badly.
For environments dependent on critical devices, such as factories, oil and gas facilities, and hospitals, a device that changes its network behavior carries a different risk profile than one that does not. However, DACLs without this understanding of network context would treat traffic coming and going from each device identically. Continuous Segmentation can suggest network changes based on dozens of attributes such as risk and is not solely dependent on device-blind DACLs. The same holds across the broader set of connected assets, from IoT sensors and OT systems to IoMT devices and the IT infrastructure that connects them.
The bigger trajectory here is toward networks that maintain and strengthen their own security posture, not through one-time configuration, but through continuous alignment between what users and devices are doing and how the network should be configured. Asimily Continuous Segmentation makes sure that the gap between network policies and changes in the network is covered.
Secure Every IoT Device.
Automatically.
Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.