The same thing, workload by workload
An illustrative hybrid estate of 84 workloads. The highlighted headers and tags are the labels the current boundary is written with.
Risk against effort
Exposure left after each stage, above the rules it took to get there. The coarse deny fences are a handful of rules each. The allow-lists are where the hours go.
The approach in three rules
Fence first, coarse to fine
Environment, Regulation and Location boundaries are deny rules over a few labels. They need no application knowledge, run safely in Selective Enforcement, and remove most of the reach.
Allow-lists last, one app at a time
Application and Role rules need the dependency map from the visibility stage. Each one is real work with an app owner, so they come after the cheap wins, in order of business risk.
Get the labels right
Every rule is written against labels, never IP addresses. A workload with the wrong Environment or Location label lands on the wrong side of a fence. Source them from the CMDB and cloud tags, and treat an unlabelled workload as a finding.
Quarantine collapses the radius in one change
Add a Quarantine label to the compromised workload and force it into Full Enforcement. One Override Deny rule outranks every Allow rule already written, so it works at any stage of the rollout, even before the allow-lists exist.
Reach drops to 2: the local SIEM collector for logs out, and the jump hosts for the incident team coming in. Illumio's SIEM and NDR integrations can apply the label straight from an alert.
Notes for the room
Regulated zones
PCISWIFTSOX are a custom Regulation label type. Fencing them is stage 3, and it is the evidence assessors want: PCI-DSS 11.4.5 asks for segmentation to be pen-tested at least yearly, and SWIFT CSCF 1.1 asks for the secure zone to be isolated.
The numbers
Workload counts come from a model of an illustrative estate. Rule counts are estimates. The firewall overlay is generous: it assumes clean zone rules, and real rule bases carry broad legacy rules, so the true brownfield baseline is usually worse. The shape of the curve is the point, and it holds in real estates: rerun this against your own flow data before quoting a percentage.
Cloud caveat
AWS, Azure and GCP are visibility-only in this plan. Illumio sees those flows and maps cloud tags onto the same labels, but security groups, NSGs and firewall rules do the blocking. The Cloud columns shrink only if those match the policy.