Back to Blog
Network Security
9 min read

Microsegmentation in Hospitals: Start Small, Reduce Lateral Movement

Most microsegmentation projects fail by starting too big. How to map real flows, pick a first segment that proves the model, and enforce without taking a ward offline.

GuardsArm Team

Security Experts

December 4, 2025

Network microsegmentation

Ransomware in a hospital is rarely a story about the initial intrusion. It is a story about what the attacker reached afterwards. One compromised workstation in a flat network can talk to the file servers, the imaging archive, the domain controllers and the infusion pumps. Microsegmentation is the control that makes that untrue.

It is also the project most likely to stall, because teams attempt it estate- wide and drown in the flow analysis.

Flat by default
Most hospital networks permit any-to-any within the internal zone
Lateral movement
The step between one compromised endpoint and an enterprise-wide outage
Monitor first
Every successful programme runs in observe mode before it blocks anything

Why the big-bang approach fails

The instinct is to map every flow in the hospital, design a complete policy, and enforce it. This fails predictably: the mapping takes a year, the estate changes underneath it, nobody will sign off blocking traffic they do not fully understand, and the project quietly becomes a monitoring deployment.

The alternative is to treat it as a series of small, complete wins.


Choosing the first segment

A good first segment has four properties: the asset is valuable, the traffic is predictable, the owner is cooperative, and the blast radius of getting it wrong is small.

CandidateValueFlow predictabilityGood first choice?
Domain controllersVery highHigh — well-known protocolsYes
Imaging modalitiesHighVery high — worklist and PACS onlyYes
Backup infrastructureVery highHighYes
Clinical workstationsHighVery low — they talk to everythingNo
Guest networkLowHighAlready done, usually

Backup infrastructure is the highest-value first segment in a hospital. If ransomware cannot reach the backups, the entire incident changes character. The flows are few and well understood, and the backup team is usually a willing partner.


Map flows from data, not from memory

Asking teams which systems talk to which produces an incomplete and optimistic answer. Use observed traffic:

Segmentation rollout per segmentTraffic is observed, a policy is modelled from it, run in monitor mode to surface what it would have blocked, then enforced and reviewed.Observecollect real flowsModelpropose policyMonitorlog would-be blocksEnforceswitch to denyReviewexceptions and drift
The monitor stage is what makes enforcement uncontroversial — you can show what breaks before it breaks.

Observe for long enough to catch the periodic: month-end reporting, quarterly vendor maintenance, the annual accreditation export. Two weeks misses all of them. Aim for a full month minimum on anything with a business cycle.

Monitor mode is not optional in a hospital
The difference between "this policy would have blocked 340 flows" and finding out at 3am which of them was the blood gas analyser is the entire risk of the project. Run every policy in monitor mode and review the would-block log with the clinical owner before enforcing.

Policy that survives change

Rules written against IP addresses break the first time DHCP or a hardware refresh moves something. Write policy against identity wherever the platform allows:

  • Tags or labels applied to workloads, not addresses
  • Device groups from the inventory or NAC system
  • Service accounts rather than source hosts, for application traffic
  • Named services rather than raw port numbers, so intent stays readable

The test of a good rule is whether someone can read it in a year and understand why it exists. allow imaging-modality -> pacs-archive : DICOM survives. allow 10.4.22.0/24 -> 10.9.1.14 : 104 does not.


What to measure

  • Segments enforced versus planned — the actual progress number
  • East-west flows denied per week, trending down as policy matures
  • Exception count and age — rising age means the policy is drifting from reality
  • Time to add a new workload to an existing segment; if this is slow, teams will route around the control

Where to start this quarter

Pick backups. Observe the traffic for a month, model the policy, run it in monitor mode for two weeks, then enforce. It is a contained piece of work with a clear security outcome, and it gives you a repeatable pattern plus an internal reference the next segment owner will believe.

For the device side of the same problem, see IoMT security, which covers segmenting equipment you cannot patch or instrument.

GuardsArm designs and validates hospital segmentation, including flow mapping and monitor-mode policy review with clinical owners. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.