Network segmentation is a foundational enterprise security control. Despite its recognized benefits, segmentation initiatives frequently fail in practice, and the field lacks a systematic empirical explanation for why these projects do not achieve their intended outcomes. This paper presents an empirical study of failed segmentation projects based on a survey of 400 U.S.-based\ network security practitioners. The survey was grounded in a two-part failure framework that separately measures general IT project failure factors and segmentation-specific technical and operational barriers. Clustering analysis of the responses reveals four distinct failure archetypes. Surprisingly, practitioners across all four archetypes propose general IT project management fixes over segmentation-specific fixes in the same ratio.
翻译:网络分段是一种基础性的企业安全控制措施。尽管其优势已获公认,但分段计划在实践中经常失败,而该领域缺乏对为何这些项目未能达到预期成果的系统性实证解释。本文基于一项对400名美国网络安全从业者的调查,对失败的分段项目进行了实证研究。该调查基于一个由两部分组成的失败框架,该框架分别衡量了一般IT项目失败因素以及分段特有的技术性和运营性障碍。对调查反馈的聚类分析揭示了四种不同的失败原型。令人惊讶的是,所有四种原型的从业者都倾向于提出一般性IT项目管理修正方案,而非分段特定的修正方案,且比例相同。