Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Forescout: Why Visibility Must Come First in Network Segmentation

Forescout
08/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I want a segmentation project so I can immediately go to enforcement. But if you have a, I'll call it a dirty network, or if you have devices that you don't know if they're deployed in the right location, the right network zone, then if you try to apply enforcement policies before having an understanding of what's in that environment, it's going to fail. It's going to erroneously block the wrong device. So being able to see what's in the environment, have them accurately classified based on their identity and then layer those segmentation policies on top of that becomes more important. I think one place where it's ripe for adopting segmentation is in healthcare. And an example of healthcare is that, you know, it's a very dynamic environment, right? You now have smart devices, blood pressure monitoring devices, blood infusion pumps. They're on hospital beds and cracks that are roaming around on the hospital floor. Maybe they go to a different ward in a different building. That's where traditional segmentation fails. You can't say in this particular zone, I'm going to go ahead and segment this and A can't talk to B. The identity-based approach allows you to classify that as a device type, as a blood pump type, and then you have a different policy that you can apply for allowing that dynamic motion inside the hospital or campus, but you're still protecting those devices from unauthorized access.

TL;DR

  • Rushing to enforcement on an uncharacterized network causes segmentation projects to fail by erroneously blocking legitimate devices.
  • Accurate device visibility and identity-based classification must be established before any segmentation policies are applied.
  • Healthcare environments highlight why static zone-based segmentation breaks down when medical devices roam dynamically across facilities.

Summary

In this short interview, Paul Kao, Chief Product Officer at Forescout, explains why network segmentation projects so often fail — and what organizations must do differently. The core argument is straightforward but frequently overlooked: jumping straight to policy enforcement on an uncharacterized network is a recipe for disruption. Without first achieving full device visibility and accurate identity-based classification, enforcement policies will inevitably block the wrong devices, creating operational problems rather than solving security ones. Kao introduces the concept of a 'dirty network' — an environment where devices may not be deployed in their intended zones — and argues that layering segmentation policies on top of unverified device inventories compounds risk rather than reducing it. The healthcare sector serves as a compelling use case: smart medical devices like blood pressure monitors and infusion pumps roam dynamically across wards and buildings, making static, zone-based segmentation unworkable. Identity-based segmentation addresses this by classifying devices by type rather than location, enabling policies that follow the device wherever it moves while still protecting it from unauthorized access. This approach represents a meaningful shift from traditional perimeter-based thinking toward dynamic, context-aware network security.

Chapters

0:00 - The Segmentation Enforcement Trap
0:30 - Visibility and Identity Classification First
0:39 - Healthcare as a Segmentation Use Case
1:10 - Identity-Based Dynamic Policy

Key Quotes

0:20 "If you try to apply enforcement policies before having an understanding of what's in that environment, it's going to fail."
0:28 "It's going to erroneously block the wrong device."
1:03 "That's where traditional segmentation fails."

FAQ

Why do network segmentation projects fail?

According to Forescout's CPO Paul Kao, the most common failure is enforcing segmentation policies before achieving accurate device visibility. On a 'dirty network' where devices may not be in their intended zones, premature enforcement will block the wrong devices and disrupt operations.

How does identity-based segmentation differ from traditional approaches?

Traditional segmentation assigns policies based on network zone or location. Identity-based segmentation classifies devices by their type or identity, so policies follow the device as it moves — critical in environments like hospitals where devices roam across wards and buildings.


Categories:
  • » Webinar Library » Forescout
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • OT
  • IoT Security
  • Zero Trust
  • Best Practices
  • Demo
  • Network Segmentation
  • Device Visibility
  • Identity-Based Security
  • Healthcare IoT Security
  • Medical Device Security
  • Dynamic Segmentation
  • Policy Enforcement
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Forescout: Why Visibility Must Come First in Network Segmentation

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Oct
                        08

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        10/08/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 10/08/2026
                          12:00 PM
                          10/08/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version