Emre Sel, Country Manager for Akamai Technologies Turkey, explained Akamai’s micro-segmentation solution and its benefits.
Sel stated the following:
Firewalls—which we regard as the standard perimeter defense for internal networks—can prove insufficient in protecting against external attacks. This is because the attempt to halt attacks occurs at that perimeter. However, once attacks breach that line, these standard firewalls often fail to detect or block malicious activity taking place behind the perimeter. Consequently, the infrastructure located behind the perimeter also requires protection; standard firewalls fall short in this regard. Micro-segmentation is essential for protecting the entire attack surface situated behind the perimeter. Akamai supports the transition from perimeter-based defense to attack-surface protection. It can transform every machine within the internal network—whether deployed on-premises, in the cloud, or within container structures like Kubernetes—into an individual firewall, independent of its specific environment or operating system. Thus, each machine functions as an isolated firewall. Akamai enables this shift from perimeter defense to attack-surface protection. Naturally, machines within the network communicate with one another. Through the micro-segmentation solution, we can map out the topology of these communications, identifying exactly which machines are interacting and at what level. We make each machine visible at both the network and process levels—a concept we call “visibility.” We map the topology of every machine within your network, allowing us to see exactly how and at what level the machines communicate with each other. We are also able to intervene regarding visible activities. When a communication attempt between two machines violates security rules, it can be blocked using these mitigation methods. Consequently, in the event of a breach, the compromised machine cannot send requests to other machines, nor can it execute any unauthorized actions internally. This can be summarized as follows: if a breach occurs, the intrusion remains confined to the compromised machine. No unauthorized operations can be performed, and the threat cannot spread to other machines via lateral movement; the entire network remains isolated. Since the system is agent-based, only operations explicitly permitted by the agent—configurations determined by network administrators—can be executed; no other actions are possible. Our approach here is therefore one of “Zero Trust.” Communication between machines is restricted solely to clean, authorized operations. This is how a Zero Trust Network Access architecture is established. Regardless of the machine’s operating system or environment—or even considering the human element—we operate without relying on trust in the users themselves; instead, by strictly limiting activity to what the agent permits, we ensure infrastructure security within a Zero Trust environment where only authorized operations take place.
About the Wise
Similar Videos from this Wise
Why Is Micro-segmentation Necessary?
Emre Sel, Country Manager for Akamai Technologies in Turkey, explained why micro-segmentation is necessary. Sel stated the fo...











