Security startup Illumio added container support to its segmentation platform, which means that companies can set and enforce consistent security policies across data center, cloud, and containerized workloads.

Segmentation, or microsegmenation, enables fine-grained security policies to be assigned to applications. The approach improves network security by integrating it directly into a virtualized workload without requiring a hardware-based firewall. It reduces a company’s attack surface by essentially sealing off workloads from the rest of the network, thus preventing hackers from gaining access to the wider system.

The latest release of Illumio’s Adaptive Security Platform expands segmentation across Kubernetes, Docker, and OpenShift container platforms in addition to supporting non-container environments. This allows companies to govern workloads wherever they run from a single interface with a uniform policy model, automatically and at scale — beyond 100,000 workloads, said CEO and founder Andrew Rubin.

It’s been a busy year for the security unicorn, which launched this scalability feature, raised $65 million in a Series E round that brought its total haul to $332.5 million, and hired Anup Singh as its CFO in the first two months alone. Behind the scenes, however, the team was also developing its container strategy.

Illumio’s Container Strategy

Rubin admits that his security company isn’t the first to the container party. But there’s a reason for that. “We have been incredibly deliberate and used the voice of our customers to support our container roadmap,” he said.

When it comes to containers, “it’s the second pitch of the first inning of the game, and it may still be pre-season,” Rubin said. “I believe we are incredibly early. And although there’s a lot of excitement and huge uptake, there’s still a huge number of unknowns about what the containerized world is going to look like. There is a lot of baseball left to play.”

So, Illumio is starting with Kubernetes, Docker, and OpenShift “to support how we believe the containerized world is unfolding and standardizing.”

But despite arriving late, Illumio claims its platform is more effective than a container security point product, which essentially creates another silo. And it’s more effective than other SDN or hypervisor-based segmentation like Cisco ACI with Tetration and VMware’s NSX, Rubin says.

Taking On VMware, Cisco With Superclusters

“Our big differentiator against our competition, NSX and Cisco Tetration and ACI, — No. 1 on the list would be scalability,” Rubin said. “Our ability to operationalize at scale, we believe, is many, many times larger than our competitors.”

The company’s Policy Compute Engine (PCE) Supercluster technology, which enables enterprise-scale, real-time application dependency mapping and microsegmentation, is used by “some of the largest organizations in the world,” according to Illumio. For the record, Illumio’s customers include Morgan Stanley, Salesforce, BNP Paribas, Oracle NetSuite, Quicken Loans, Plantronics, Oak Hill Advisors, and Backcountry.com.

The company launched its supercluster technology in January, and Rubin says this made it the first vendor to offer microsegmentation and visibility that scaled beyond 100,000 workloads.

The argument becomes: I don’t care how cool your features are,” Rubin said. “If it doesn’t work past 5,000 workloads, it’s worthless to me.”

Infrastructure Agnostic

Illumio’s No. 2 differentiator is that it’s infrastructure agnostic, Rubin said. Its supports switches from both Cisco and Arista, and its platform works across any data center, public cloud, or hybrid cloud deployment on bare metal, virtual machines (VMs), and containers. Plus, Illumio is built from the ground up as a segmentation company.

“We’re not an infrastructure company that built switches and then decided to become a segmentation company,” Rubin said. “We started the company with a sole purpose, which means we did not have to think about any legacy business or architectures. We are decoupled from everything: containers, VMs, AWS, Azure, GCP — we simply don’t care because none of those things affect us.”

And No. 3, “the vulnerability maps, we believe, is a key differentiator,” he added. This is a feature that overlays third-party vulnerability scanning tools like Qualys with Illumio’s real-time application dependency map to provide insights to the exposure of vulnerabilities and attack pathways within a customer’s environment.

“Both NSX and ACI through Tetration are making more progress in making the map a bigger part of their story, but they are building it afterward. Whereas when we started, we said the application dependency map is the gateway to the segmentation journey," Rubin said.

Still, Rubin acknowledges that he’s got serious ground to cover to win market share from Cisco and VMware. Additionally, VMware recently announced its own container push including a Kubernetes portfolio and a whole new security business unit at last month’s VMworld event.

Meanwhile VMware Pushes Deeper Into Security

“We have an enormous amount of respect and humility in the face of VMware. This is one of the most important, largest, and forward-leaning and innovative companies inside of the data center certainly now and probably ever. To not take them as a serious threat would be wrong,” Rubin said. “However, having said that, there is no doubt that they are getting more active in the security space. Yes, they view it as a critical piece of their future, and I love seeing that because it means we are in the right place, going after the right problem set. We believe segmentation it not going to be a point solution, it is going to be baked into the fabric of the data center.”

Of course, this also sounds similar both VMware and Cisco’s approach to segmentation and security. And considering these companies’ data center stronghold — and VMware’s emerging cloud prowess — why would a major enterprise that’s already invested heavily in Cisco and VMware infrastructure choose Illumio’s segmentation technology?

Rubin says ultimately the best technology will win, and he believes that’s Illumio. “Our bet is not how many things we can staple to segmentation,” he said. “Our bet is let’s build the absolute best segmentation platform.”

If a customer need to solve a highly visible problem (like security) that has severe consequences (hello, Equifax breach), “a customer will select the best of breed solution,” he said. “Very rarely does something meet those two thresholds at the same time. But when it does meet those two it is no longer enough to buy good enough. When we are talking about regulators, compliance, and being on the front page of The Wall Street Journal when you get it wrong, ease and convenience and one-stop shopping isn’t enough.”