Illumio updated its segmentation platform with new automation features and integrations that its founders say can speed up and simplify organizations’ zero-trust security adoption.

“Zero trust is a journey, it is something you have to implement,” said Illumio CTO and co-founder PJ Kirner, adding that a zero-trust security strategy requires multiple products and technologies. “And people need small, incremental wins on that journey of building zero trust into their environment.” The platform updates, which use automation to make companies’ zero-trust journey easier, help enable these small wins, he explained.

Zero trust ensures that only continuously verified users and devices are allowed access to corporate resources and restrict data on a least-privilege basis. A handful of technologies enable zero trust, and segmentation, which enables fine-grained security policies to be assigned to applications, is one of them.

Illumio Core, a software-as-a-service segmentation platform, can scale to more than 100,000 workloads across multi-cloud, container, hybrid, and on-premises environments. Platform updates include new automated security policy constructs that allow organizations to choose the right level of granularity when applying segmentation.

Automated Security Enforcement

“You might not be able to microsegment everything, everywhere — you might not even need to microsegment everything from a risk point of view — but you need to choose the level of granularity,” Illumio CTO and co-founder PJ Kirner said.

With this new feature, organizations can set specific segmentation boundaries to protect high-value assets like intellectual property or customer data, or they can choose selective enforcement, which allows them to  selectively and progressively enforce policy one service at a time.

Illumio also updated its App Owner View feature, which is a Core platform capability that lets application teams build software-defined perimeters around individual application instances, with improved real-time application insights. Kirner said these make it even easier to create, enforce, and test security policy. Companies can also integrate App Owner View with Quays, Rapid7, and Tenable software to score and flag vulnerabilities and exposed data.

And finally, while Illumio Core already offered SuperClusters — this is the feature that allows companies to scale segmentation and enforce policies across more than 100,000 workloads in their hybrid IT environments — new integrations now orchestrate extended enforcement in Palo Alto Networks and F5 devices and can also support IBM Cloud and Oracle Exadata. This is in addition to pre-existing integrations with Amazon Web Services, Google Cloud Platform, and Microsoft Azure.

While there’s still no easy button to get from implicit trust to continually validated, explicit trust, the platform updates are a step in that direction, Kirner said. “What we did find is: Can I press something, get some risk reduction, press it again, get some more risk reduction — so we allow people to do is incrementally work toward zero-trust goals, and with demonstrable risk reduction to show your boss, your CISO, your executives, your board.”

Illumio Scores $225M on $2.75B Valuation

The product update comes less than a month after the cybersecurity unicorn closed a $225 million Series F funding round that pushed its valuation to $2.75 billion. And in a subsequent interview with SDxCentral, Illumio CEO Andrew Rubin discussed why a zero-trust framework is critical to helping organizations protect themselves from increasingly destructive and expensive cyberattacks.

“In the last 180 days, we’ve watched SolarWinds, we’ve watched Microsoft Exchange, we’ve seen JBS and Colonial,” he said. “We’ve watched breaches for the first time go beyond data or a cyber incident and have a physical-world impact. Something’s got to change. We can’t just spend all that money on detection and assume we’re gonna catch everything, because the math no longer works.”