Micro-segmentation has strengthened zero trust security and reduces lateral movement risks
What is our primary use case?
My main use case for Akamai Guardicore Segmentation is for micro-segmentation and east-west traffic control across data center and cloud workloads, which helps ensure zero trust policies, isolate critical applications, and prevent lateral movement, improving security posture in multi-customer environments.
For example, using Akamai Guardicore Segmentation, we segmented a three-tier application by allowing only required ports between tiers and blocking all other east-west traffic, which prevented lateral movement from compromised web servers to databases, significantly reducing attack surface and improving security compliance.
How has it helped my organization?
Akamai Guardicore Segmentation has significantly improved our security posture by preventing lateral movement through effective micro-segmentation, and it also enhanced operational efficiency with better visibility and faster policy deployment, reducing risk and improving compliance across customer environments.
With Akamai Guardicore Segmentation, we have observed a 60 to 70 percent reduction in lateral movement risk due to strict micro-segmentation policies, along with 40 to 50 percent faster incident containment and troubleshooting, improved compliance visibility, and fewer security exceptions.
What is most valuable?
Some of the best features of Akamai Guardicore Segmentation are its granular micro-segmentation and deep visibility, allowing control to process, service level, and full east-west traffic mapping, while it also stands out for AI-assisted policy creation, real-time threat detection, and software-based enforcement.
The feature I rely on most in Akamai Guardicore Segmentation is application dependency mapping and visibility, which gives real-time insight into east-west traffic flows, helping us design accurate policies quickly and troubleshoot issues without impacting production environments.
Additionally, Akamai Guardicore Segmentation offers a policy simulation test mode, which is very useful to validate rules before enforcement and avoid outages.
What needs improvement?
Akamai Guardicore Segmentation could improve in policy management at scale, as large environments can become complex to manage and tune, and enhanced cloud-native integrations and more intuitive reporting would help improve visibility and simplify operations for service delivery teams.
It can be improved with integration with SIEM or SOAR tools, and more granular role-based access control would enhance operational efficiency and governance.
For how long have I used the solution?
I have been using Akamai Guardicore Segmentation for three and a half years.
What do I think about the stability of the solution?
Akamai Guardicore Segmentation is stable.
What do I think about the scalability of the solution?
Akamai Guardicore Segmentation is highly scalable, designed to support large distributed environments across data, cloud, and hybrid setups.
How are customer service and support?
The customer support is good, but the documentation is not up to the mark.
I would rate the customer support a nine on a scale of 1 to 10.
Which solution did I use previously and why did I switch?
I previously used traditional network firewalls and VLAN-based segmentations before switching.
We switched to Akamai Guardicore Segmentation for granular micro-segmentations, better east-west visibility, and zero-trust enforcement, which were not achievable with legacy network-based approaches.
How was the initial setup?
Overall, it is expensive but high value, especially for large-scale, security-critical environments, with pricing on the premium side, a moderate setup cost, and a subscription-based licensing per agent.
What was our ROI?
We have seen a strong ROI both in cost savings and operational efficiency, having reduced 70 percent in incident handling effort and a 30 to 40 percent reduction in security resources, which delivers measurable value through reduced risk, lower operational cost, and faster breach containment.
Which other solutions did I evaluate?
Before choosing Akamai Guardicore Segmentation, I evaluated other options.
We evaluated VMware NSX and Cisco Secure Workload; while those offered segmentation capabilities, Akamai Guardicore Segmentation stood out for its deep visibility, process-level control, and easier deployment without changing the network.
What other advice do I have?
For Akamai Guardicore Segmentation, I would suggest fellow buyers to start with application dependency mapping first to clearly understand traffic flows before enforcing policies, and to implement it in a phase-wise manner, such as monitor, simulate, and enforce. I would rate this product a nine on a scale of 1 to 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Network visibility has transformed segmentation in our kubernetes environments and improves security
What is our primary use case?
Our main use case for Akamai Guardicore Segmentation is the implementation in Kubernetes AWS.
How has it helped my organization?
Akamai Guardicore Segmentation has positively impacted our organization. We implemented Akamai Guardicore Segmentation and shared all our directory with the team, who are very happy about the security environment we implemented.
What is most valuable?
Akamai Guardicore Segmentation offers us large visibility in all our environments and helps us to understand network segmentation and traffic.
The visibility from Akamai Guardicore Segmentation has helped our team by addressing the challenge of a shadow network in traffic across all environments, providing us with more insight into this network traffic.
In my experience with Akamai Guardicore Segmentation, the best feature is visibility. The segmentation is excellent, but the visibility of all network traffic is extremely helpful.
The segmentation feature of Akamai Guardicore Segmentation is very easy to set up across all environments. The Akamai team supports all our questions, and the tool is very easy to use, making it extremely helpful.
Regarding the features of Akamai Guardicore Segmentation, the integration with Active Directory is excellent and very positive.
One specific outcome from using Akamai Guardicore Segmentation is that we noticed addressing network threats, which are a very significant problem in any company. This feature, along with visibility, has brought us more peace of mind.
What needs improvement?
I believe Akamai Guardicore Segmentation could be improved with a feature to filter, and I believe implementing MFA would be very useful and helpful to us.
For how long have I used the solution?
I have been using Akamai Guardicore Segmentation for more than three years, and I had the opportunity to get certified. I liked the tool so much that I had the opportunity to earn the GCSA and GCSE certifications.
What other advice do I have?
My advice for others looking into using Akamai Guardicore Segmentation is that visibility is crucial. If you are not seeing your network clearly, your job is challenging. Visibility is the main word in Akamai Guardicore Segmentation. Our company has a business relationship with Akamai as we are a partner or reseller. I rate this product a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
One of the best Segmentation Tool that using Labelling
What do you like best about the product?
Guardicore is Labelling base segmentation tool which provide huge flexbility to perform the segmentation using verious different attributes.
What do you dislike about the product?
Frequent releases of major version is very time consuming task and disturb the whole operation flow.
What problems is the product solving and how is that benefiting you?
Guardicore segmentation is helping us to restrict or control the east west traffic which is usually not intercepted by the gateway level firewall like north south traffic.