Network Segmentation & Microsegmentation, made enforceable.
Segmentation strategies are easy to draw and hard to ship. ModernCyber plans, designs, and implements macrosegmentation and microsegmentation on the network you already own — Cisco ISE, TrustSec Security Group Tags, SD-Access, Catalyst, Meraki, and your firewalls — without breaking production.
Macrosegmentation + microsegmentation, one architecture.
Macrosegmentation
Coarse-grained isolation between business zones — users, IoT/OT, medical devices, servers, guests — using Virtual Networks (VNs), VRFs, and VLANs, with stateful enforcement at the firewall between segments. Traffic between zones is denied unless explicitly permitted, supporting compliance and containing east-west malware propagation.
Real project shape: twelve macrosegments in dedicated VRFs enforced at a next-generation firewall; eight Virtual Networks with a fusion firewall cluster between them.
Microsegmentation
Least-privilege control inside each segment using Cisco ISE and TrustSec: identity- and context-based Security Group Tags (SGTs) assigned to users, devices, and workloads, with SGT-to-SGT policy (SGACLs) enforced by your switches, wireless, and SGT-aware firewalls — no re-IP, no forklift.
Real project shape: a versioned TrustSec matrix; SGACL enforcement wired-to-wired, wired-to-wireless, and industrial-Ethernet use cases; replacing over-permissive 10.0.0.0/8 firewall rules with source-SGT matches.
One of many shapes segmentation can take.
A methodology built to never break production.
1 · Discover & requirements
Stakeholder interviews across architecture, engineering, and operations; review of existing designs, configurations, flows, and constraints. Business, technical, and operational requirements documented — not assumed.
2 · Design workshop & SDD
A collaborative workshop with built-in knowledge transfer, then a full Solution Design Document: segmentation architecture, SGT classification model, TrustSec matrix, per-site reference designs, device configuration standards, and a test & acceptance plan you formally accept before anything changes.
3 · Phased, fail-open rollout
Policies deploy in monitor mode first — unknown traffic permitted and logged so legitimate flows surface before enforcement. Pilots at representative sites produce a validated playbook; rollout proceeds site-by-site in your change windows. Enforcement turns on deliberately, not hopefully.
4 · Operationalize & support
As-built documentation, runbooks and configuration procedures, knowledge transfer, and ongoing implementation support — additional cutovers, policy tuning, optimization, and troubleshooting with our engineers on call.
Healthcare, industrial, and critical-infrastructure segmentation programs.
Customer names withheld; references available under NDA.
Multi-site healthcare system
Segmentation for a healthcare network where medical devices and IoT made flat networking a clinical risk — aligned with HHS 405(d) guidance. Built on an SD-Access foundation with a fusion firewall cluster:
- Inter-VN macrosegmentation policies on Firewall Management Center
- Intra-VN microsegmentation with SGT-to-SGT SGACLs across the SDA fabric and remote sites
- Campus-to-data-center policy: SDA/ISE SGTs mapped to ACI Endpoint Groups
- Posture & compliance via ISE partner integrations (MDM, vulnerability, SIEM), plus a QUARANTINE SGT and Adaptive Network Control for rapid threat containment
- Remote sites migrated site-by-site with next-day hypercare per site
Industrial & critical-infrastructure operator
An enterprise-wide TrustSec segmentation program in delivery across corporate, industrial (IE switch), and energy-sector environments:
- Twelve macrosegments as dedicated VRFs enforced at next-generation firewalls, with SGT-based rules replacing broad static-IP policies
- Versioned TrustSec matrix and SGT classification model covering users, IoT, cameras, printers, phones, and servers
- Cloud and virtualization context tagging (Azure, vCenter) and CMDB-integrated profiling for endpoint classification
- Wired, wireless, industrial-Ethernet, and site-to-site SXP propagation & enforcement use cases
- Micro-site and large-site pilots producing a validated site-by-site enablement playbook
The stack we segment with.
Classification
Cisco ISE, 802.1X, profiling, posture, pxGrid partner integrations (MDM/UEM, vulnerability management, SIEM, medical-device security), CMDB, Azure & vCenter context tagging.
Propagation
TrustSec inline tagging, SGT Exchange Protocol (SXP), SD-Access fabric, site-to-site propagation designs, NetFlow enablement for flow auditing.
Enforcement
SGACLs on Catalyst, Meraki, and Industrial Ethernet switches; Cisco Secure Firewall / FMC; SGT-aware third-party NGFWs; Cisco ACI (SGT-to-EPG); Adaptive Network Control.
Network segmentation questions we hear most.
What's the difference between network segmentation and microsegmentation?
Network segmentation (macrosegmentation) divides the network into coarse zones — users, servers, IoT, guests — using VLANs, VRFs, and firewalls, denying traffic between zones by default. Microsegmentation applies least-privilege policy within those zones, typically with Cisco TrustSec Security Group Tags and SGACLs, so a compromised device can't move laterally even to its neighbors. A defensible architecture layers both.
Do we need Cisco SD-Access to use TrustSec?
No. SD-Access automates TrustSec inside a fabric, but TrustSec works on traditional Catalyst, Meraki, and Industrial Ethernet networks using ISE for classification and SXP for propagation where inline tagging isn't available. We design for the network you have — including mixed estates and platforms that can't enforce, which we document and route to firewall enforcement points instead.
Will turning on segmentation enforcement break production?
Not the way we deliver it. Every policy is implemented fail-open first — unknown traffic is permitted and logged during a validation window so real flows surface before enforcement. Pilots at representative sites produce a tested playbook, rollouts follow your change process, and Day-0/Day-1 hypercare covers each cutover. Removing the fail-open rules is a deliberate, evidence-based step.
What deliverables do we get?
A Solution Design Document covering requirements, the segmentation architecture, the SGT model and TrustSec matrix, device configuration standards, and a test & acceptance plan — updated to as-built at project end — plus site enablement playbooks, knowledge transfer, and ongoing implementation support for tuning, additional cutovers, and troubleshooting.
Can you work alongside our existing partner or integrator?
Yes — we regularly deliver segmentation as the specialist subcontractor within larger programs, and our mentored (MINT) delivery style means your engineers and your partner's engineers learn the solution as it's built.
How do we buy?
Directly from ModernCyber, or worldwide through your Cisco account team and preferred partner on the Cisco Global Price List — SKU MINT-SECURITY-MCY. Engagements start with a scoping session.
Make your segmentation strategy enforceable.
Bring us your architecture, your compliance driver, or just your flat network — we'll bring the methodology, the TrustSec depth, and the engineers who've shipped it.
Not sure where to start? Begin with a Zero Trust assessment. Pair delivery with our implementation services — and when it ships, ModernISE Platform keeps the Cisco ISE underneath patched, healthy, and continuously assessed.