Gartner® Research
Microsegmentation,
From Plan to Enforcement in Six Steps
Gartner® discusses six steps and success measures to reduce exposure caused by open lateral network access and advanced threats.
Customer Spotlight
“Elisity has changed how we look at microsegmentation solutions overall and we have now experienced how Elisity is the easiest to implement and easiest to manage.”
— Aaron Weismann, CISO, Main Line Health
Network Segmentation Without Compromise
The Numbers
Main Line Health deploys Elisity microsegmentation enterprise-wide across their Cisco infrastructure with Armis integration, providing comprehensive protection at every facility with network presence.
6,000+
Actively Enforced Policies
+100k
IoT, OT, and IoMT Devices Protected
150
Hospitals, Health centers and physicians' practices
3
Days to Deploy
Challenge
Expanded Attack Surface
The proliferation of connected medical and IoT devices has expanded the attack surface across clinical environments, creating new attack vectors that cybercriminals exploit to gain unauthorized access to critical patient care systems and protected health information (PHI). With thousands of devices spanning multiple facilities, healthcare organizations struggle to maintain visibility and control.
Elisity Solution
Comprehensive Healthcare Visibility
Elisity IdentityGraph™ transforms your switches into data sensors that automatically discover and classify all connected devices—including medical equipment, IoMT devices, clinical workstations, and building management systems—providing complete visibility across your entire healthcare environment without disrupting patient care. This visibility extends across all facilities in your healthcare system.
Challenge
Legacy Medical Device Vulnerabilities
Clinical devices and IoMT systems often run legacy software, proprietary operating systems, or have long replacement cycles, making them impossible to patch regularly or secure with traditional endpoint solutions. These devices represent a significant portion of a healthcare organization's infrastructure but remain largely unprotected by conventional security tools.
Elisity Solution
HIPAA-Compliant Segmentation
Easily implement the network segmentation controls required by the 2025 HIPAA Security Rule update through identity-based policy groups that logically segment your clinical environment without complex VLAN configurations or network architecture changes. Our solution aligns with HHS 405(d) guidelines to help you achieve favorable regulatory treatment.
Challenge
HIPAA Compliance Complexity
Meeting stringent HIPAA Security Rule requirements, especially the new 2025 mandated network segmentation controls, becomes increasingly difficult with traditional approaches that require complex VLAN configurations and static firewall rules. HHS 405(d) Health Industry Cybersecurity Practices (HICP) further emphasizes the need for robust network protection through segmentation.
Elisity Solution
Zero-Disruption Deployment
Deploy medical microsegmentation using your existing network infrastructure without requiring new hardware, device agents, or clinical downtime—maintaining continuous patient care operations critical to healthcare environments with multiple facilities and thousands of caregivers.
Clinical Continuity
Healthcare organizations cannot tolerate disruptions to patient care that traditional security implementations often require, creating resistance to implementing proper security controls while maintaining 24/7 clinical operations across multiple hospitals and specialty clinics.
Elisity Solution
Phased Security Implementation
Roll out your fine-tuned policies in waves using Elisity's Simulation Mode to analyze policy impact, identify potential issues, and refine policies before full-scale deployment, safeguarding your clinical operations while strengthening security posture across your entire healthcare organization.
Resources
Download the 2025 HIPAA Security Rule Update: Network Segmentation Implementation Guide
Discover how Elisity's identity-based microsegmentation helps healthcare organizations meet the 2025 HIPAA Security Rule's mandatory network segmentation requirements without disrupting critical operations
The Gartner® Insights
What Are the Gartner® Six Steps for Microsegmentation?
Step 1
Plan
Define the use case, who owns it, and the cross-functional team, before you scope anything.
Step 2
Discover
Build a complete, accurate view of assets, workloads, and how they communicate.
Step 3
Automate
Use AI-driven mapping and labeling to keep that view current as the environment changes.
Step 4
Document
Turn discovery into consistent labels, validated policies, and an auditable record.
Step 5
Simulate
Validate policies in observe-only mode with application owners before you enforce.
Step 6
Enforce
Move to active enforcement gradually, with monitoring and clear escalation paths.
Framework and step definitions from Gartner, Implement Microsegmentation to Mitigate Advanced Threats, Rajpreet Kaur, Charanpal Bhogal, 26 June 2026. Descriptions above are Elisity's summaries. See the report for the full guidance. For the practitioner's view, see our guide to implementing microsegmentation.
Why Now?
Lateral Movement
is the Exposure
Advanced threats move sideways once they're inside, and that's exactly what microsegmentation closes off.
We believe the harder part is scope.
OT, IoT, and legacy systems sit squarely inside this framework, and those are the environments agent-based tools reach last, if at all. Any team weighing a segmentation initiative gets a clear picture here of what each phase demands and how to measure progress along the way.
-
Once attackers get in, ransomware moves laterally across open east-west access.
-
At St. Luke's, 30 to 50 percent of connected devices couldn't run agents. IoT, OT, IoMT, and legacy are exactly what this framework tells you to protect.
-
Success measures at each step keep progress tangible and board-ready.
-
A phased rollout delivers risk reduction early, not after a multi-year project.
Get the Gartner® Report
Implement Microsegmentation to Mitigate Advanced Threats
Get the complete six-step insights, the success measures for each step, and the guidance on scope and enforcement models, all in one place.
Why Elisity
We Believe We're Built to Finish All Six Steps
Know who and what's on your network
Document policies as identity-based, least-privilege rules for every user, workload, and device across IT, IoT, OT, and IoMT. Simulate them first, see the impact, then activate with confidence.
Activate zero trust policies
Gain full visibility and context of all users, workloads and devices with Elisity IdentityGraph™ intelligence.
-
Know who and what's on your network
Plan around the use case that matters, then discover every user, workload, and device, including the large share that can't take agents. Elisity IdentityGraph automates the classification, correlating identity, behavior, traffic, and risk from 25+ native integrations.
-
Activate zero trust policies
Document policies as identity-based, least-privilege rules for every user, workload, and device across IT, IoT, OT, and IoMT. Simulate them first, see the impact, then activate with confidence.
-
Deploy and scale without downtime
Enforce on the network infrastructure you already own. No new hardware, no new VLANs, no new hires. Most teams reach their first enforced policy in weeks.
Proven Across 15 Hospitals
at St. Luke’s University
Health Network
14 days
From deployment to first active segmentation policy
15 hospitals
Network-wide, surgical robots online throughout, acquisitions onboarded in weeks
2-3 sites / wk
Site rollout pace across the network
83%
Of critical policies enforced within 90 days
See it on Your Own Network
Walk through discovery, simulation, and enforcement with our team, on the infrastructure you already own.
Microsegmentation Implementation FAQs
The Gartner® report sequences the work through Plan, Discover, Automate, Document, Simulate, and Enforce — from defining the use case and owner through validating policies in observe-only mode before active enforcement. The report on this page covers each step with success measures.
Identity-based microsegmentation enforces policy at the network layer, on the switches you already own, so IoT, OT, IoMT, and legacy systems are covered without installing anything on the device.
With an agentless, identity-based approach, most teams reach their first enforced policy in weeks: discovery and simulation run on existing infrastructure, so there is no hardware rollout or re-IP project in the critical path. St. Luke's went from deployment to first active policy in 14 days across a 15-hospital network.
Run policies in simulation or observe-only mode first: validate that required business traffic is allowed, review any denied flows with application owners, and only then transition to active enforcement. That's the Simulate step in the Gartner® report, and it's how teams enforce without breaking production.
Recognized Across Gartner Research
Elisity was named a Cool Vendor in the Gartner® Cool Vendors™ in Cyber-Physical Systems Security 2025.
Elisity was recognized as a Sample Vendor in the Gartner® Hype Cycle™ for Enterprise Networking, 2025
Elisity was recognized as a Representative Vendor in the 2025 Gartner® Market Guide for Network Security Microsegmentation.
GARTNER® is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's Business and Technology Insights Organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
HYPE CYCLE is a registered trademark, and COOL VENDORS is a trademark and service mark, of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.
Healthcare Networks & Medical Device Security FAQ
See how Elisity helps healthcare organizations secure legacy and connected medical devices while maintaining compliance and clinical operations. These FAQs answer the most common questions from security and clinical engineering teams.
Elisity’s identity-based microsegmentation secures each device at the network level without requiring any software on the device. By limiting communications to only what’s necessary for care, it shields legacy and unpatchable medical equipment from threats.
Yes, Elisity automatically discovers and classifies all connected medical devices, then enforces healthcare-specific segmentation policies that protect patient data. It also provides the documentation and visibility needed to demonstrate compliance with industry security requirements.
No, Elisity’s solution is non-disruptive and uses your existing network, so you can roll out security policies without any downtime. You can even simulate and verify policies before enforcement to ensure there’s no impact on essential healthcare operations.
Elisity consolidates network access control into one platform that’s aware of clinical context. This unified, automated approach means fewer consoles to manage and consistent enforcement across all devices, freeing up your team from manual device-by-device configurations.
