Network segmentation is a foundational enterprise security control. Despite its recognized benefits, segmentation initiatives frequently fail in practice, and the field lacks a systematic empirical explanation for why these projects do not achieve their intended outcomes. This paper presents an empirical study of failed segmentation projects based on a survey of 400 U.S.-based\ network security practitioners. The survey was grounded in a two-part failure framework that separately measures general IT project failure factors and segmentation-specific technical and operational barriers. Clustering analysis of the responses reveals four distinct failure archetypes. Surprisingly, practitioners across all four archetypes propose general IT project management fixes over segmentation-specific fixes in the same ratio.
翻译:网络分段是一种基础性的企业安全控制手段。尽管其益处已被公认,但分段项目在实践中频繁失败,而该领域尚缺乏对项目未能实现预期结果原因的系统性实证解释。本文基于对400名美国网络安全从业者的调查,对失败的分段项目开展了一项实证研究。该调查以双部分失败框架为基础,分别衡量了通用IT项目失败因素以及分段特有的技术与操作障碍。对反馈的聚类分析揭示了四种不同的失败原型。令人惊讶的是,所有四种原型的从业者提出采用通用IT项目管理修复方案与分段特有修复方案的比例是相同的。