Network segmentation — the act of dividing a network into multiple smaller, isolated networks that are not visible from the outside — has long been used to reduce cyber risk. At its core, segmentation assumes a “zero trust” approach to protecting digital environments and minimizes access to digital assets for those who don’t need it, while enabling access for those who do. Should a breach occur, that threat is contained in the segmented network so it doesn’t propagate to other assets.
Let’s take a closer look at why network segmentation can be a useful tool, particularly in light of some new threats that have become public over the past few weeks.
New cyber threats and vulnerabilities highlight the need for segmentation
Network segmentation is particularly effective at mitigating the risk posed by vulnerabilities in connected devices that have yet to be patched, and aggressive strains of virus, malware, and botnets that, left unchecked, can run rampant across networks.
For example, segmentation was recently recommended as a best practice by the Food and Drug Administration (FDA), who just issued a notice to hospitals and healthcare providers informing them of cybersecurity vulnerabilities affecting GE Healthcare Clinical Information Central Stations and Telemetry Servers. Hackers could exploit this flaw and remotely interfere with the function of patient monitors, such as silencing the alarms that alert medical staff to vital health information. GE has advised hospitals to continue using the devices and is working on a patch to close the vulnerability, writes MedTech Dive. In the meantime, it recommended that hospitals isolate the devices from other networks.
In another recent case, America’s Cybersecurity and Infrastructure Security Agency (CISA) warned of an increase in the number of targeted cyber-attacks that utilize Emotet — a form of malware that proliferates within a network by brute force to obtain sensitive information. To stop the virus in its tracks, CISA recommended segmenting and segregating networks and functions.
The challenges of network segmentation
Network segmentation is an important part of reducing cyber risk across your digital ecosystem. However, it can be costly, complex, and cumbersome to achieve and manage over time — putting pressure on already stretched IT resources. Plus, if one mistake is made and access levels or other vital controls are misconfigured, entire networks can be exposed to cyber threats.
Furthermore, as organizations increasingly connect with third, fourth, and nth parties such as cloud providers, sub-contractors, and partners, they must find ways to limit the risk of doing business with vendors that may not have the best security postures. Network segmentation can help; but many organizations work with hundreds, if not thousands, of vendors — making proper separation hard to prioritize, manage, and monitor.