Segmentation is supposed to contain a breach to one part of the network. In practice, it’s one of the most commonly-failed controls we test — not because teams don’t try, but because segmentation decays quietly over time.
A VLAN gets added for a project and never cleaned up. A firewall rule meant to be temporary becomes permanent. A legacy server nobody remembers owning sits with an open path into a segment it was never supposed to reach.
The fix isn’t a one-time segmentation project — it’s testing the boundary regularly enough to catch the drift before an attacker does.