Reduce Risk Faster with Asimily & Your NAC

How Asimily complements your NAC to make segmentation a fully realized, automated control.

You have a Network Access Control platform (NAC) – Cisco ISE, Aruba ClearPass, Arista CloudVision, Extreme SiteEngine, or another – that your team bought, deployed, and integrated. But the infrastructure you bought to segment your network is still running at a fraction of its potential, not because the platform is limited, but because turning authentication into continuously enforced segmentation that doesn’t risk outages is a problem your NAC was never designed to solve on its own.

Organizations own capable NAC infrastructure, often for a decade or more, and use it almost entirely for authentication. Risk-reducing segmentation, the reason many of them bought the NAC in the first place, remains a project that never quite gets operationalized. 

Asimily changes that by operationalizing your NAC. We do this by giving NACs deep device intelligence and the policy engine to turn that intelligence into enforced, continuously maintained segmentation.

Related Reading: Segmentation Was Built for a Network that No Longer Exists

Your NAC Knows Who, but it Does Not Know What

NACs are very good at answering one question: is this device allowed on the network? It authenticates, admits or denies, and assigns access at a coarse level. What it cannot do on its own is answer the harder question that segmentation depends on: what this device is, what it needs to communicate with, and what it should never be allowed to touch.

That gap is why segmentation stalls. To write a segmentation policy, you need to know what every device is, how it behaves, what it legitimately communicates with, and what risk it carries. That’s relatively simple for IT, but much harder for diverse IoT, OT, and IoMT, which are sensitive to network traffic, hard to update, and often critical for business operations. A NAC does not understand each device’s network needs. Neither does a spreadsheet attempting to statically inventory the network, nor does a network team working from memory and tribal knowledge. This is precisely the intelligence Asimily was built to produce.

Asimily discovers and profiles every connected device across your IoT, OT, IoMT, and IT infrastructure agentlessly through passive monitoring and active safe scanning where appropriate. Asimily identifies each device down to make, model, firmware version, and behavioral pattern, and it maps what every device actually communicates with. That is the foundation segmentation requires, and it is the layer your NAC cannot see on its own.

Related Reading: Introducing Segmentation Orchestration from Asimily

From Device Intelligence to Enforced Policy

Knowing what your devices are is necessary but not sufficient for operationalizing segmentation. The reason segmentation projects fail even when teams have comprehensive device visibility is that the path from “we understand our devices” to “we have enforced a policy that holds up in production” is full of hidden risk. Write the policy wrong, and you break a clinical workflow, halt a production line, or take down a system nobody realized depended on the traffic you just blocked. On top of that, any of the vulnerabilities discovered in a day might be attackable in your network and require changes for security.

Asimily closes the gap between knowledge and enforcement with Segmentation Orchestration, and it does so through your existing NAC and firewall infrastructure rather than around it.

The Chain That Turns a NAC Into a Segmentation Engine

ATT&CK Analysis determines which devices carry genuinely exploitable risk. Policy Auto-Recommendation generates conflict-free policies from observed device behavior. Policy Simulation proves those policies safe against real traffic before they go live. Your NAC enforces them. Continuous Segmentation keeps them accurate as the environment changes. Each step feeds the next, and every step runs on the device intelligence your NAC never had.

  1. Start with vulnerability prioritization. ATT&CK Analysis, Asimily’s patented methodology, evaluates whether each vulnerability is actually exploitable on a specific device given its firmware and its place in your network topology. It draws on more than 15 threat intelligence sources including CISA KEV, the NVD, MITRE ATT&CK for ICS, vendor SIRTs, and exploit databases, and it routinely narrows millions of theoretical vulnerabilities down to roughly the 1% that carry real, exploitable risk. This tells you which devices genuinely need tighter segmentation and which communication paths represent actual exposure, so your policy decisions are precise rather than uniform guesses.
  2. Then generate the policy. Policy Auto-Recommendation drafts conflict-free segmentation rules derived from how your devices actually behave, not from templates. The recommendation reflects the real communication dependencies of each device, so you start from a working policy rather than a blank slate.
  3. Prove it safe before enforcement. Policy Simulation tests every proposed policy against real observed traffic and shows you exactly which flows it would block before anything reaches production. This is the step that eliminates the fear that stalls segmentation programs. You see the impact, confirm no critical workflow breaks, and approve with evidence in hand.
  4. Enforce through the infrastructure you own. Asimily formats policies for your specific NAC using vendor-specific methods and pushes them for enforcement, whether it’s Cisco ISE, pxGrid, Aruba ClearPass, Extreme Site Engine, or Arista MSS or CloudVision.e. Where firewall enforcement is the right control, Asimily works with Palo Alto and Fortinet. You are not buying new enforcement infrastructure. You are finally using what you already have.
  5. Keep it accurate over time. Continuous Segmentation maintains the policy as devices join, move, update firmware, or change behavior. When ATT&CK Analysis identifies a new exploitable vulnerability in your existing device population, the segmentation posture adapts. The policy follows the intent you defined, not a static device list that goes stale the day after you write it.
Why Device Context Is the Difference

Device context is crucial to segmentation, but it’s something that network-only tools cannot provide. A NAC, and the network team operating it, can see traffic. They can group by VLAN, by subnet, by port. What they cannot see is device context: that the device in question is an infusion pump running a specific firmware version with a known exploitable vulnerability, or that it’s a PLC controlling a specific process, or even a building management controller that should never be talking to a lathe.

Segmentation built on traffic patterns alone produces policies that are either too permissive, because the team could not confidently tighten them without risking an outage, or too brittle, because they were built on a snapshot that no longer reflects reality. Segmentation built on device intelligence produces policies that reflect what each device is, what it needs, and what risk it carries. That is the difference between a NAC that only authenticates and a NAC that genuinely segments.

What Changes for the CISO

You stop carrying segmentation as the initiative that never ships. The infrastructure you already paid for starts delivering the risk reduction it was supposed to. Blast radius shrinks because compromised devices are contained to what they legitimately need. And every policy decision is defensible, traceable to a specific device, a specific vulnerability, and a documented simulation of its impact, which is exactly the evidence boards, auditors, and cyber insurers increasingly ask for.

Your NAC Was a Good Investment. Make It a Great One.

The organizations getting the most value from their NAC today are not the ones who bought the most expensive platform. They are the ones who paired it with the device intelligence and policy orchestration that turn authentication into enforced, maintained segmentation. Asimily is how you get there, working with the Cisco, Aruba, Arista, Extreme, Palo Alto, and Fortinet infrastructure you already run.

For teams that already own a NAC and know segmentation should be doing more, the fastest path to value is not another purchase. It is unlocking the one you already made.

See It On Your Own Network

The most convincing version of this story is your own environment. Request a demo, and we will show you how Asimily turns your existing NAC into an enforced, continuously maintained segmentation engine, using your device estate and your infrastructure.

Secure Every IoT Device.
Automatically.

Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.