On Demand Webinar
99% Plan It. 9% Have It. A CISO Playbook for Closing the Microsegmentation Gap
An Omdia survey of 352 healthcare and manufacturing security leaders puts numbers on the say-do gap — and two CISOs who closed it share what actually works.
About This Webinar
Ninety-nine percent of CISOs are planning or deploying microsegmentation. Nine percent have it protecting their critical systems. Nearly one in two organizations had a lateral movement attack in the past twelve months.
A new Omdia survey of 352 healthcare and manufacturing security leaders just put numbers on what most CISOs have felt for years: the say-do gap is real, it is structural, and the architecture has finally caught up.
Hear from the two analysts who ran the survey and two CISOs who have shipped microsegmentation at scale. Thirty minutes of fireside conversation. Survey data on screen. No product pitch. A working playbook from people who have done it.
Speakers
Hollie Hennessy
Principal Analyst, OT/IoT Cybersecurity, Omdia
Rik Turner
Chief Analyst, Cybersecurity, Omdia
Edmond Mack
Senior Vice President and CISO, Cencora
Jason Elrod
CISO, MultiCare Health System
Webinar Details
What You'll Learn
- Why most microsegmentation projects fall short, and the architectural shift unblocking them now
- A practical sequence for visiting clinicians, unmanaged medical devices, OT remote engineers, ICS, and building management systems
- How peers translated cyber insurance, HIPAA, FDA, IEC 62443, and Zero Trust pressure into a board-ready plan
- Honest answers on where to start, what to cut from scope, and how to bring the network team along
- The metrics CISOs use to prove value, from device discovery to minimizing incident blast radius
- Plus audience Q&A — practical questions from real practitioners
Who Is This For?
- Healthcare CISOs and CIOs
- Security and IT Leaders in highly-regulated industries
- Anyone seeking to accelerate Zero Trust adoption without years of painful, costly projects
Featuring
Omdia research meets real-world CISO experience.
This webinar pairs Omdia analysts Hollie Hennessy and Rik Turner with practicing CISOs Edmond Mack (Cencora) and Jason Elrod (MultiCare Health System) for an unscripted conversation about what it actually takes to close the microsegmentation gap in healthcare and manufacturing.
Network Segmentation Without Compromise
The Numbers
Key findings from Omdia's 2024 microsegmentation survey of enterprise security leaders.
99%
of CISOs planning or deploying microsegmentation
9%
have operational protections in place
352
healthcare and manufacturing security leaders surveyed
1 in 2
organizations hit by lateral movement attack
Challenge
Expanded Attack Surface
The proliferation of connected medical and IoT devices has expanded the attack surface across clinical environments, creating new attack vectors that cybercriminals exploit to gain unauthorized access to critical patient care systems and protected health information (PHI). With thousands of devices spanning multiple facilities, healthcare organizations struggle to maintain visibility and control.
Elisity Solution
Comprehensive Healthcare Visibility
Elisity IdentityGraph™ transforms your switches into data sensors that automatically discover and classify all connected devices—including medical equipment, IoMT devices, clinical workstations, and building management systems—providing complete visibility across your entire healthcare environment without disrupting patient care. This visibility extends across all facilities in your healthcare system.
Challenge
Legacy Medical Device Vulnerabilities
Clinical devices and IoMT systems often run legacy software, proprietary operating systems, or have long replacement cycles, making them impossible to patch regularly or secure with traditional endpoint solutions. These devices represent a significant portion of a healthcare organization's infrastructure but remain largely unprotected by conventional security tools.
Elisity Solution
HIPAA-Compliant Segmentation
Easily implement the network segmentation controls required by the 2025 HIPAA Security Rule update through identity-based policy groups that logically segment your clinical environment without complex VLAN configurations or network architecture changes. Our solution aligns with HHS 405(d) guidelines to help you achieve favorable regulatory treatment.
Challenge
HIPAA Compliance Complexity
Meeting stringent HIPAA Security Rule requirements, especially the new 2025 mandated network segmentation controls, becomes increasingly difficult with traditional approaches that require complex VLAN configurations and static firewall rules. HHS 405(d) Health Industry Cybersecurity Practices (HICP) further emphasizes the need for robust network protection through segmentation.
Elisity Solution
Zero-Disruption Deployment
Deploy medical microsegmentation using your existing network infrastructure without requiring new hardware, device agents, or clinical downtime—maintaining continuous patient care operations critical to healthcare environments with multiple facilities and thousands of caregivers.
Clinical Continuity
Healthcare organizations cannot tolerate disruptions to patient care that traditional security implementations often require, creating resistance to implementing proper security controls while maintaining 24/7 clinical operations across multiple hospitals and specialty clinics.
Elisity Solution
Phased Security Implementation
Roll out your fine-tuned policies in waves using Elisity's Simulation Mode to analyze policy impact, identify potential issues, and refine policies before full-scale deployment, safeguarding your clinical operations while strengthening security posture across your entire healthcare organization.
Take the Next Step
Ready to close your own microsegmentation gap?
See how Elisity's identity-based microsegmentation helps healthcare and manufacturing organizations implement Zero Trust protection — without disrupting operations.
Healthcare Networks & Medical Device Security FAQ
See how Elisity helps healthcare organizations secure legacy and connected medical devices while maintaining compliance and clinical operations. These FAQs answer the most common questions from security and clinical engineering teams.
Elisity’s identity-based microsegmentation secures each device at the network level without requiring any software on the device. By limiting communications to only what’s necessary for care, it shields legacy and unpatchable medical equipment from threats.
Yes, Elisity automatically discovers and classifies all connected medical devices, then enforces healthcare-specific segmentation policies that protect patient data. It also provides the documentation and visibility needed to demonstrate compliance with industry security requirements.
No, Elisity’s solution is non-disruptive and uses your existing network, so you can roll out security policies without any downtime. You can even simulate and verify policies before enforcement to ensure there’s no impact on essential healthcare operations.
Elisity consolidates network access control into one platform that’s aware of clinical context. This unified, automated approach means fewer consoles to manage and consistent enforcement across all devices, freeing up your team from manual device-by-device configurations.
Additional Resources

Microsegmentation in Healthcare: Omdia Survey Findings

PCI DSS 4.0 Network Segmentation Requirements Explained

Field Notes from Gartner SRM 2026: Four Threads I'm Still Thinking About
Ready to Prevent Lateral Movement? Secure Your Network in Weeks, Not Years
Don't wait for attackers to exploit your east-west traffic security policy gaps. Implement Elisity's identity-based microsegmentation without agents, hardware, or network changes. Discover 99% of all users, workloads, and devices in one day, create dynamic least privilege policies, and prevent lateral movement—all while leveraging your existing infrastructure. Schedule your personalized demo today.
Schedule Time With Us
