Gartner® Research

gartner_logo_light

Microsegmentation,
From Plan to Enforcement in Six Steps

Gartner® discusses six steps and success measures to reduce exposure caused by open lateral network access and advanced threats. 

Small_Logo
Mainline-customer-spotlight-image

Customer Spotlight

“Elisity has changed how we look at microsegmentation solutions overall and we have now experienced how Elisity is the easiest to implement and easiest to manage.”

— Aaron Weismann, CISO, Main Line Health

Network Segmentation Without Compromise

Transform network security with identity-based microsegmentation that enables Zero Trust in weeks, not years.

The Numbers

Main Line Health deploys Elisity microsegmentation enterprise-wide across their Cisco infrastructure with Armis integration, providing comprehensive protection at every facility with network presence.

6,000+

Actively Enforced Policies

+100k

IoT, OT, and IoMT Devices Protected

150

Hospitals, Health centers and physicians' practices

3

Days to Deploy

Challenge

Expanded Attack Surface

The proliferation of connected medical and IoT devices has expanded the attack surface across clinical environments, creating new attack vectors that cybercriminals exploit to gain unauthorized access to critical patient care systems and protected health information (PHI). With thousands of devices spanning multiple facilities, healthcare organizations struggle to maintain visibility and control.​

Down_arrow
challenge-solution_icon

Elisity Solution

Comprehensive Healthcare Visibility

Elisity IdentityGraph™ transforms your switches into data sensors that automatically discover and classify all connected devices—including medical equipment, IoMT devices, clinical workstations, and building management systems—providing complete visibility across your entire healthcare environment without disrupting patient care. This visibility extends across all facilities in your healthcare system.​

Challenge

Legacy Medical Device Vulnerabilities

Clinical devices and IoMT systems often run legacy software, proprietary operating systems, or have long replacement cycles, making them impossible to patch regularly or secure with traditional endpoint solutions. These devices represent a significant portion of a healthcare organization's infrastructure but remain largely unprotected by conventional security tools.​

Down_arrow
challenge-solution_icon

Elisity Solution

HIPAA-Compliant Segmentation

Easily implement the network segmentation controls required by the 2025 HIPAA Security Rule update through identity-based policy groups that logically segment your clinical environment without complex VLAN configurations or network architecture changes. Our solution aligns with HHS 405(d) guidelines to help you achieve favorable regulatory treatment.​

Challenge

HIPAA Compliance Complexity

Meeting stringent HIPAA Security Rule requirements, especially the new 2025 mandated network segmentation controls, becomes increasingly difficult with traditional approaches that require complex VLAN configurations and static firewall rules. HHS 405(d) Health Industry Cybersecurity Practices (HICP) further emphasizes the need for robust network protection through segmentation.​

Down_arrow
challenge-solution_icon

Elisity Solution

Zero-Disruption Deployment

Deploy medical microsegmentation using your existing network infrastructure without requiring new hardware, device agents, or clinical downtime—maintaining continuous patient care operations critical to healthcare environments with multiple facilities and thousands of caregivers.​

Frame 427319008

Clinical Continuity

Healthcare organizations cannot tolerate disruptions to patient care that traditional security implementations often require, creating resistance to implementing proper security controls while maintaining 24/7 clinical operations across multiple hospitals and specialty clinics.​

Down_arrow
challenge-solution_icon

Elisity Solution

Phased Security Implementation

Roll out your fine-tuned policies in waves using Elisity's Simulation Mode to analyze policy impact, identify potential issues, and refine policies before full-scale deployment, safeguarding your clinical operations while strengthening security posture across your entire healthcare organization.​

Resources

Download the 2025 HIPAA Security Rule Update: Network Segmentation Implementation Guide

Discover how Elisity's identity-based microsegmentation helps healthcare organizations meet the 2025 HIPAA Security Rule's mandatory network segmentation requirements without disrupting critical operations

Download Here
HIPAA-Whitepaper-Download-image-Big

The Gartner® Insights

gartner_logo_dark

What Are the Gartner® Six Steps for Microsegmentation?

The Gartner® six-step measures for implementing microsegmentation are Plan, Discover, Automate, Document, Simulate, and Enforce. Here's a quick look at what each one involves. You'll find the full detail, and the success measures Gartner recommends for every step, inside the report.
gartner_logo_dark

Step 1

Plan

Define the use case, who owns it, and the cross-functional team, before you scope anything.

Step 2

Discover

Build a complete, accurate view of assets, workloads, and how they communicate.

Step 3

Automate

Use AI-driven mapping and labeling to keep that view current as the environment changes.

Step 4

Document

Turn discovery into consistent labels, validated policies, and an auditable record.

Step 5

Simulate

Validate policies in observe-only mode with application owners before you enforce.

Step 6

Enforce

Move to active enforcement gradually, with monitoring and clear escalation paths.

Framework and step definitions from Gartner, Implement Microsegmentation to Mitigate Advanced Threats, Rajpreet Kaur, Charanpal Bhogal, 26 June 2026. Descriptions above are Elisity's summaries. See the report for the full guidance. For the practitioner's view, see our guide to implementing microsegmentation.

Why Now?
Lateral Movement
is the Exposure

Advanced threats move sideways once they're inside, and that's exactly what microsegmentation closes off.

We believe the harder part is scope.

 

OT, IoT, and legacy systems sit squarely inside this framework, and those are the environments agent-based tools reach last, if at all. Any team weighing a segmentation initiative gets a clear picture here of what each phase demands and how to measure progress along the way.

  • Once attackers get in, ransomware moves laterally across open east-west access.

  • At St. Luke's, 30 to 50 percent of connected devices couldn't run agents. IoT, OT, IoMT, and legacy are exactly what this framework tells you to protect.

  • Success measures at each step keep progress tangible and board-ready.

  • A phased rollout delivers risk reduction early, not after a multi-year project.

Get the Gartner® Report

Implement Microsegmentation to Mitigate Advanced Threats

Get the complete six-step insights, the success measures for each step, and the guidance on scope and enforcement models, all in one place.

Read the Report
Gartner, Implement Microsegmentation to Mitigate Advanced Threats, Rajpreet Kaur, Charanpal Bhogal, 26 June 2026.

Why Elisity

We Believe We're Built to Finish All Six Steps

Limit lateral movement with zero trust policies for every user, workload, and device. Identity-based microsegmentation, activated in weeks, on the network infrastructure you already own. One graph discovers your assets and enforces the policy. No translation layer.

Discover_Icon

Know who and what's on your network

Document policies as identity-based, least-privilege rules for every user, workload, and device across IT, IoT, OT, and IoMT. Simulate them first, see the impact, then activate with confidence.

DCM - Discover-Devices - Card Reveal
Control_Icon

Activate zero trust policies

Gain full visibility and context of all users, workloads and devices with Elisity IdentityGraph™ intelligence.​​

DCM - Control-Policies 3
Manage_Icon

Deploy and scale without downtime

Enforce on the network infrastructure you already own. No new hardware, no new VLANs, no new hires. Most teams reach their first enforced policy in weeks.

DCM - Manage-Integrations
  • Know who and what's on your network

    Plan around the use case that matters, then discover every user, workload, and device, including the large share that can't take agents. Elisity IdentityGraph automates the classification, correlating identity, behavior, traffic, and risk from 25+ native integrations.

    Frame 427319148
  • Activate zero trust policies

    Document policies as identity-based, least-privilege rules for every user, workload, and device across IT, IoT, OT, and IoMT. Simulate them first, see the impact, then activate with confidence.

    features__item_img2 (1)-1
  • Deploy and scale without downtime

    Enforce on the network infrastructure you already own. No new hardware, no new VLANs, no new hires. Most teams reach their first enforced policy in weeks.

    features__item_img3 (1)-1

Proven Across 15 Hospitals
at St. Luke’s University
Health Network

St._Lukes_University_Health_Network_logo.svg

14 days

From deployment to first active segmentation policy

15 hospitals

Network-wide, surgical robots online throughout, acquisitions onboarded in weeks

2-3 sites / wk

Site rollout pace across the network

83%

Of critical policies enforced within 90 days

See it on Your Own Network

Walk through discovery, simulation, and enforcement with our team, on the infrastructure you already own.

Schedule a Demo

Microsegmentation Implementation FAQs

What are the Gartner® six steps for implementing microsegmentation?

The Gartner® report sequences the work through Plan, Discover, Automate, Document, Simulate, and Enforce — from defining the use case and owner through validating policies in observe-only mode before active enforcement. The report on this page covers each step with success measures.

How do I secure devices I can't put an agent on?

Identity-based microsegmentation enforces policy at the network layer, on the switches you already own, so IoT, OT, IoMT, and legacy systems are covered without installing anything on the device.

How long does it realistically take to deploy microsegmentation?

With an agentless, identity-based approach, most teams reach their first enforced policy in weeks: discovery and simulation run on existing infrastructure, so there is no hardware rollout or re-IP project in the critical path. St. Luke's went from deployment to first active policy in 14 days across a 15-hospital network.

How do I prove segmentation works before enforcing policy in production?

Run policies in simulation or observe-only mode first: validate that required business traffic is allowed, review any denied flows with application owners, and only then transition to active enforcement. That's the Simulate step in the Gartner® report, and it's how teams enforce without breaking production.

Back to top
 

Recognized Across Gartner Research

 

GARTNER®  is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's Business and Technology Insights Organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

HYPE CYCLE is a registered trademark, and COOL VENDORS is a trademark and service mark, of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.

Healthcare Networks & Medical Device Security FAQ

See how Elisity helps healthcare organizations secure legacy and connected medical devices while maintaining compliance and clinical operations. These FAQs answer the most common questions from security and clinical engineering teams.

Many medical devices run outdated systems and can’t have agents installed. How can we protect these vulnerable devices?

Elisity’s identity-based microsegmentation secures each device at the network level without requiring any software on the device. By limiting communications to only what’s necessary for care, it shields legacy and unpatchable medical equipment from threats.

We have thousands of IoMT devices and strict regulations (HIPAA, HHS 405(d)) to meet. Can Elisity help us stay compliant?

Yes, Elisity automatically discovers and classifies all connected medical devices, then enforces healthcare-specific segmentation policies that protect patient data. It also provides the documentation and visibility needed to demonstrate compliance with industry security requirements.

Will deploying microsegmentation disrupt patient care or critical medical services?

No, Elisity’s solution is non-disruptive and uses your existing network, so you can roll out security policies without any downtime. You can even simulate and verify policies before enforcement to ensure there’s no impact on essential healthcare operations.

Our hospital security team is stretched thin managing multiple tools. How does Elisity simplify medical device security?

Elisity consolidates network access control into one platform that’s aware of clinical context. This unified, automated approach means fewer consoles to manage and consistent enforcement across all devices, freeing up your team from manual device-by-device configurations.

Back to top