Avatar

Microsegmentation has been central to my work throughout my career, including my work as cofounder of Isovalent, now a Cisco company. The challenge has remained the same: make east west application traffic visible and enforce policy close to the workload, so a compromise in one place does not become a breach everywhere.

That challenge is more urgent now. AI is changing the capability, speed, and economics of cyberattacks, allowing attackers to find and traverse vulnerable paths faster. Microsegmentation has moved from a security best practice to an essential control for limiting lateral movement and reducing blast radius.

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026. We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind Spots

Applications increasingly span private clouds, on-premises data centers, and public clouds. The same business service may depend on physical servers, virtual machines, containers, managed cloud services, and Kubernetes clusters operated by different teams. Security cannot be fragmented for each new infrastructure silo that emerges.

Cisco Secure Workload combines application dependency visibility with policy and distributed enforcement, helping organizations limit lateral movement, reduce blast radius, protect critical applications, and enforce least privilege without redesigning the physical network around every security requirement. This gives organizations a consistent approach to application visibility, policy, and distributed enforcement across these multi-cloud environments. Its mature agent-based and agentless approaches help teams understand application dependencies, administer policy centrally, and place enforcement close to workloads and infrastructure.

Forrester described Cisco Secure Workload as a “hybrid agent-based and agentless solution” that delivers “superior enforcement in on-premises and cloud-native network environments.” Cisco received the highest score possible in the policy administration, on-premises network-based enforcement, and cloud-native networking enforcement criteria. Together, these capabilities give network security teams consistent visibility and security across hybrid environments, reducing lateral movement risk while allowing cloud and application owners to preserve the deployment models that fit their workloads.

Cisco’s Vision for Multi-Cloud Distributed Network Security

Cisco also received the highest score possible in the vision criterion. That vision is centered on distributing enforcement across the places applications run. Because east west segmentation is now essential, Cisco is making major investments in microsegmentation to advance this vision. Extending Secure Workload’s existing agentless microsegmentation support for Cisco ACI and Secure Firewall, we are adding support for Cisco N9300 Series Smart Switches, making it easier to segment the network without installing software on workload devices. At the same time, we are advancing the Secure Workload agent with eBPF technology to provide deeper visibility into network and runtime activity with minimal performance overhead.

Cisco’s overall vision, available through Security in Cisco Cloud Control, brings network zone controls, workload microsegmentation, and runtime enforcement together under consistent security intent. Policy remains consistent even as workloads shift from on premises environments to the cloud, or from traditional VMs to containers running in Kubernetes.

Start Your Journey Today with Cisco Secure Workload

Achieving meaningful microsegmentation outcomes requires more than product capabilities. Teams must understand application dependencies, translate business intent into policy, establish the right administrative boundaries, and introduce enforcement without disrupting critical services.

We believe the customer feedback in the Forrester report reinforces these human requirements. Forrester reports that “Customers appreciate the ability to diagnose differences between existing traffic flows and policies.” That aligns with our experience: successful deployments depend on planning administrative scopes early and working with experienced partners. Cisco’s partner ecosystem and community help bridge the gap from architectural planning to security outcomes through expertise and proven deployment practices.

Cisco Secure Workload turns east/west visibility into precise containment across private and public clouds. In an era of AI-powered attackers, this is now a mission-critical capability for your enterprise. Cisco and its partners are ready to help you move from blind spots to insight, and from insight to enforcement, with confidence.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026

Learn more about Cisco Secure Workload.

Ready to see it in action? Request a Cisco Secure Workload demo to learn more.

Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. The Forrester report referenced above is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here.

Authors

Dan Wendlandt

VP of Product Management

Cisco Security