Microsegmentation in Hospitals: Start Small, Reduce Lateral Movement
Most microsegmentation projects fail by starting too big. How to map real flows, pick a first segment that proves the model, and enforce without taking a ward offline.
GuardsArm Team
Security Experts
Ransomware in a hospital is rarely a story about the initial intrusion. It is a story about what the attacker reached afterwards. One compromised workstation in a flat network can talk to the file servers, the imaging archive, the domain controllers and the infusion pumps. Microsegmentation is the control that makes that untrue.
It is also the project most likely to stall, because teams attempt it estate- wide and drown in the flow analysis.
Why the big-bang approach fails
The instinct is to map every flow in the hospital, design a complete policy, and enforce it. This fails predictably: the mapping takes a year, the estate changes underneath it, nobody will sign off blocking traffic they do not fully understand, and the project quietly becomes a monitoring deployment.
The alternative is to treat it as a series of small, complete wins.
Choosing the first segment
A good first segment has four properties: the asset is valuable, the traffic is predictable, the owner is cooperative, and the blast radius of getting it wrong is small.
| Candidate | Value | Flow predictability | Good first choice? |
|---|---|---|---|
| Domain controllers | Very high | High — well-known protocols | Yes |
| Imaging modalities | High | Very high — worklist and PACS only | Yes |
| Backup infrastructure | Very high | High | Yes |
| Clinical workstations | High | Very low — they talk to everything | No |
| Guest network | Low | High | Already done, usually |
Backup infrastructure is the highest-value first segment in a hospital. If ransomware cannot reach the backups, the entire incident changes character. The flows are few and well understood, and the backup team is usually a willing partner.
Map flows from data, not from memory
Asking teams which systems talk to which produces an incomplete and optimistic answer. Use observed traffic:
Observe for long enough to catch the periodic: month-end reporting, quarterly vendor maintenance, the annual accreditation export. Two weeks misses all of them. Aim for a full month minimum on anything with a business cycle.
Policy that survives change
Rules written against IP addresses break the first time DHCP or a hardware refresh moves something. Write policy against identity wherever the platform allows:
- Tags or labels applied to workloads, not addresses
- Device groups from the inventory or NAC system
- Service accounts rather than source hosts, for application traffic
- Named services rather than raw port numbers, so intent stays readable
The test of a good rule is whether someone can read it in a year and understand
why it exists. allow imaging-modality -> pacs-archive : DICOM survives.
allow 10.4.22.0/24 -> 10.9.1.14 : 104 does not.
What to measure
- Segments enforced versus planned — the actual progress number
- East-west flows denied per week, trending down as policy matures
- Exception count and age — rising age means the policy is drifting from reality
- Time to add a new workload to an existing segment; if this is slow, teams will route around the control
Where to start this quarter
Pick backups. Observe the traffic for a month, model the policy, run it in monitor mode for two weeks, then enforce. It is a contained piece of work with a clear security outcome, and it gives you a repeatable pattern plus an internal reference the next segment owner will believe.
For the device side of the same problem, see IoMT security, which covers segmenting equipment you cannot patch or instrument.
GuardsArm designs and validates hospital segmentation, including flow mapping and monitor-mode policy review with clinical owners. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


