Network Security & Segmentation
Segmentation as blast-radius control, egress and DNS as the exfiltration path nobody instruments, and where zero-trust network access actually beats a VPN.
Network security changed shape in the cloud but didn’t disappear. The perimeter that used to be a firewall at the edge is gone; what remains is segmentation, controlling what can reach what, and it’s still one of the strongest levers for limiting how far a compromise travels. The catch is that the most important direction of network control, outbound, is the one almost nobody instruments.
Segmentation is blast-radius control
Section titled “Segmentation is blast-radius control”Where account structure contains blast radius at the organizational layer, network segmentation contains it at the traffic layer. The design questions:
- VPC/VNet design and subnet tiering: public subnets for what must face the internet, private subnets for everything else, and database tiers reachable only from the application tier. The tiering is the control: a database in a private subnet with no route to the internet cannot be reached directly no matter what its credentials are.
- Private and service endpoints: reach a managed service (storage, database) over the provider’s private network instead of the public internet. Removes an entire class of exposure: the storage account that’s “private” but still has a public endpoint is a recurring finding.
- Not flat: a flat network where every workload can reach every other is the network equivalent of a single shared account: convenient, and it makes lateral movement free once an intruder is inside.
East-west and microsegmentation
Section titled “East-west and microsegmentation”The traditional model hardened north-south (in and out) and left east-west (workload to workload, inside the perimeter) wide open. That’s exactly the freedom a pentester or red team exploits after initial access. Get one foothold, move sideways unimpeded.
Microsegmentation closes it: each workload reaches only what it legitimately needs, so a compromise is contained to what that specific workload could talk to rather than the whole segment. It’s the network expression of least privilege, and it’s what turns “attacker has a foothold” into “attacker has a foothold and nowhere to go.”
Egress control: the path nobody instruments
Section titled “Egress control: the path nobody instruments”Here’s the point most network security misses. Organizations pour effort into inbound filtering — what can reach us — and leave outbound wide open. But exfiltration, command-and- control, and data theft are all outbound, which means egress control is the direction that actually catches an active intrusion. The reframing worth carrying: egress control is a detection and containment capability, not a firewall chore. Whether outbound traffic is even visible is a design decision that sits upstream of the detection pipeline. The full treatment (default-deny egress and why it’s the most under-deployed control in the cloud, proxy and firewall architecture, and DNS as both attack channel and cheapest telemetry) lives in Egress & DNS Security.
TLS, mTLS, and service mesh
Section titled “TLS, mTLS, and service mesh”Encryption in transit is table stakes; the interesting decisions are about identity in transit. mTLS makes the certificate the workload identity, so service-to-service auth stops relying on shared secrets, and a service mesh is what makes that practical at scale, by pushing the certificate lifecycle into infrastructure. What the mesh actually buys, what it costs to run, and where mTLS is worth having without one is Service Mesh & mTLS.
ZTNA vs. VPN: where each helps
Section titled “ZTNA vs. VPN: where each helps”Both provide remote access; the models differ, and the difference is the Zero Trust one:
- VPN puts you on the network: authenticate once, and you have network-level access to a segment. The failure mode is exactly that: a compromised VPN credential grants broad network access, and the flat internal network does the rest.
- ZTNA grants access per application, continuously verified against identity and device posture, with no network-level access at all. You reach the specific app you’re authorized for, and nothing else is even visible.
ZTNA is the better model for most remote-access needs because it doesn’t grant the network foot in the door, and it’s Zero Trust applied to connectivity: identity as the perimeter, enforced per request. VPN still fits site-to-site connectivity and legacy systems that can’t sit behind a ZTNA proxy. The common mistake is treating them as interchangeable; they grant fundamentally different things.
Where this connects
Section titled “Where this connects”Segmentation extends the blast-radius design of account structure, and its egress dimension is what makes detection possible. You can’t see what the network never routes to a sensor. It’s what cloud pentesting navigates after a foothold, and ZTNA is Zero Trust at the connectivity layer.
Graph View
Backlinks
Spotted an error on this page? Report it.