HomeLatest NewsOpinionWhy micro-segmentation is the datacentre security model that perimeter defences cannot match

Why micro-segmentation is the datacentre security model that perimeter defences cannot match

Traditional perimeter security leaves datacentres vulnerable once threats breach the outer wall. Network virtualisation enables micro-segmentation, isolating threats at the virtual interface level and preventing lateral movement across workloads.

Preferred Source of Google

Protecting a corporate network is not as simple as building a wall around it. Threats can still sneak through the network firewall or circumvent security infrastructure altogether. Once they are inside, they can move around and attack at will since there are few, if any, controls inside the datacentre to prevent malicious traffic.

For a lot of security practitioners, nirvana is the ability to do micro-segmentation within the datacentre, or build a honeycomb, in effect, so that any threat that gets into the datacentre is actually captured within the honeycomb and cannot move very much. [Micro-segmentation divides a network into small isolated zones, each with its own security controls, preventing lateral movement by attackers who breach the perimeter.] What we can do with network virtualisation is bring that firewalling all the way down to the virtual interface.

VMware NSX has been around for more than two years now, and in that time software-defined networking and network virtualisation have become integrated into modern datacentre architecture. It seems like an inconceivable amount of progress has been made. But the reality is that we are only at the beginning of this journey.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

The transformation of networking from a hardware industry into a software industry is having a profound impact on services, security and IT organisations around the world. As more datacentres adopt the power of network virtualisation and a software-defined datacentre architecture, we will see a broad range of traditional security solutions that leverage the unique position of the network virtualisation platform in the hypervisor.

Detailed knowledge of VMs and application process owners, combined with automated provisioning speed and operational efficiency, is the foundation for an exciting new approach to some very old challenges.

The VMware NSX business, the network virtualisation and security platform for the software-defined datacentre, grew over 100 per cent year-over-year, bringing the total annual bookings run rate to well over $600 million in 2015. The past year also saw hundreds of production deployments of network virtualisation. Over 200 customers are running VMware NSX in production datacentres, with more being added every week.

Advertisement

We saw customers sign up for our NSX offering, signalling that CIOs in India are also convinced this transformative architecture will help them deploy workloads faster, as well as giving them greater agility in the face of increasingly dynamic datacentres.

Two observations stand out as we look at customer adoption of NSX in 2015. The first is the diversity of customers, in terms of both size and industry. This is an indication of the maturing of the market for this technology. In contrast to the early days, customers do not need to be especially large or sophisticated to see the benefits of network virtualisation, or to put the technology into production.

While we still see lots of interest from our traditional large, technology-focused customers, adoption is clearly spreading across industry segments such as healthcare, retail, the public sector and many others. Additionally, there are plenty of smaller customers in the mix with large enterprises and service providers.

Advertisement

The second observation is that no single use case is dominating adoption of network virtualisation; in fact, the breadth of use cases continues to increase. While the emergence of micro-segmentation as a use case definitely increased customer interest in NSX and continues to be important, customer deployments are spread across many different use cases such as agility and automation, service insertion and multi-datacentre applications such as . Increasingly we are seeing customers tackling multiple use cases in a single deployment.

Overall this breadth of usage points to the general-purpose nature of network virtualisation technology.

Aside from confidently predicting more customers, deployments and use cases, there is actually one other notable trend that should emerge in 2016. That is an increase in the range of endpoints that can be managed by NSX. This is a natural extension to the development of NSX over the past three years.

From the early days we have had support for workloads running on a range of hypervisors (ESX, KVM, Xen), and we have been able to extend virtual networks to physical workloads as well. By integrating NSX with AirWatch, we have been able to extend the security capabilities of micro-segmentation to applications running on . We have started to use micro-segmentation to improve the security of virtual desktops.

In 2016 we will see this ability to provide networking and security services to a range of endpoints move to another level. The set of endpoints that NSX can manage will extend to containers and public cloud workloads. We will also see NSX extending out to branch offices as Software Defined WAN (SD-WAN) solutions take root.

Recognising that for at least some of their end users, public clouds will be the chosen venue for a workload to run, IT managers want to have a consistent view of networking and security policy. They also want to maintain that consistency even if a workload at some point moves from one public cloud to another, or moves back to on-premise deployment. Meeting this requirement will be the objective as we expand NSX into public cloud environments.

A similar desire for consistency in networking and security policies will drive the extensions to support containers as first-class endpoints for NSX.

By the numbers

$600 million
VMware NSX annual bookings run rate in 2015
100%
Year-over-year growth of NSX business
200+
Customers running NSX in production datacentres

So, it continues to be an exciting time for network virtualisation. Adoption of the technology will increase, and we will see still more breadth of customer types and use cases. Perhaps most exciting is that we are moving well beyond our traditional sweet spot of delivering networking services to on-premise virtualised workloads, as we expand the reach of NSX to everything from to public clouds to the software-defined WAN.

The writer is senior director, systems engineering, India and , VMware

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

B S Nagarajan
B S Nagarajan
B S Nagarajan is senior director and chief technologiest at VMware India & SAARC
Advertisement
- Advertisement -
- Advertisement -

AI is speeding up existing cyberattacks, not creating ‘magic AI malware’, says Thoughtworks’ Lilly Ryan

Thoughtworks Principal Cybersecurity Engineer Lilly Ryan says that AI is amplifying existing cyberattacks rather than creating entirely new threats, forcing enterprises to rethink whether their security operations can respond at the speed of increasingly automated attacks.

RELATED ARTICLES