Eliminate Lateral Threats and Reduce Hybrid Cloud Complexity with Microsegmentation

Jul 23, 2026
5 minutes

Why Microsegmentation Is Now a Business Imperative

As enterprises navigate complex multi-cloud environments, the risk of threats is pervasive in lateral traffic flows and most microsegmentation solutions are simply too complex to scale. In March of 2026, Palo Alto Networks announced the general availability of Microperimeter, a solution for Prisma AIRS customers to protect their internal networks. By leveraging our microsegmentation solution, customers can redirect traffic from their critical workloads to AIRS (VM), part of Prisma AIRS AI Runtime Security, for Layer 7 protection. This launch provides C-suite leaders with a unified path to eliminate internal blind spots, reduce operational cost of implementing microsegmentation, and satisfy rigorous global compliance mandates through a single, integrated platform.

Protect High-Value Assets from Lateral Threat Movement

The modern enterprise faces a lateral movement gap where traditional security measures fail to control East-West traffic. Once an attacker gains a foothold, they can often move freely between workloads in the same segment or zone. This lack of granular control creates a massive blast radius that puts your entire operation at risk from a single point of entry.

Palo Alto Networks addresses this risk by including native microsegmentation capabilities in AIRS (VM). Instead of relying on basic port-blocking, our Microperimeter solution uses a lightweight PAN Traffic Redirector which automatically steers all traffic from a critical asset to AIRS (VM) for deep packet inspection. This ensures that even East-West traffic can get L7 inspection, without any need to re-architect the network.

Benefits include:

  • Instantly isolate infected systems to prevent them from compromising the wider business network. 
  • Deploy Layer 7 visibility to see what is actually inside your traffic rather than just monitoring connection ports.
  • Limit the blast radius of AI-driven and traditional threats that attempt to propagate laterally.

Introduction to AIRS (VM)

To safely deploy next-generation applications, organizations must defend their cloud network architecture from both conventional network threats and AI-specific exploits like prompt injections or model DoS attacks. AIRS (VM), part of Prisma AIRS AI Runtime Security, delivers real-time, AI-powered security to intercept and neutralize these risks at the network layer. By acting as an intelligent microperimeter around critical workloads, the platform keeps critical workloads secure without compromising processing speed.

Simplify Hybrid Cloud Complexity and Reduce Costs

Today, CIOs and CISOs are burdened by a stitching tax—the high operational cost and complexity of trying to integrate disconnected point products for firewalls and microsegmentation. Managing policies across fragmented tools creates immense deployment friction, leaving critical gaps in security. Organizations need a unified architecture that makes microsegmentation simpler to deploy, manage, and scale.

Microperimeter from Palo Alto Networks standardizes your security posture by providing a single, consistent solution for both virtual machines and modern containers. By bundling microsegmentation within the AIRS (VM) platform, there is no need to pay twice for separate tools. This architectural alignment allows your team to secure workloads in hours rather than weeks, regardless of whether they reside on-premise or in the public cloud.

  • Eliminate redundant point products to significantly reduce software licensing and operational overhead.
  • Achieve immediate enforcement with no monitoring or learning time required before policies can be applied.
  • Standardize hybrid infrastructure to provide consistent security across AWS, Azure, Google Cloud, and private data centers.

Satisfy Global Regulatory Mandates with Provable Isolation

Pressures are reaching an all-time high with mandates like Digital Operational Resilience Act (DORA), Payment Card Industry Data Security Standard (PCI DSS), National Institute of Standards and Technology (NIST), and Society for Worldwide Interbank Financial Telecommunication (SWIFT), requiring strict proof that sensitive data is isolated. Many leadership teams find that their current infrastructure cannot provide the granular evidence needed to satisfy auditors, which can lead to significant compliance risks and potential financial penalties.

Microperimeter from Palo Alto Networks is architected to protect your critical assets by establishing provable, granular boundaries around sensitive datasets. Through Strata Cloud Manager (SCM) or Panorama, you have a single source of truth to manage and report on your entire security posture. This level of control allows you to meet the strict isolation requirements of regulations like DORA with confidence.

  • Establish provable segmentation for high-value data to meet PCI and NIST standards.
  • Automate compliance reporting through a centralized management plane for all cloud and on-premise assets.
  • Verify zero trust principles by ensuring that policy accounts for user and process identity across the entire fabric.

Benchmark Your Microsegmentation Strategy

The first step to securing your internal landscape is recognizing where your current infrastructure may leave you exposed to lateral movement. Traditional port-level controls are no longer the 2026 benchmark for an AI-powered world. We invite you to assess your current blast radius and explore how a security-first microsegmentation solution can turn your network into a business enabler.

To see how your current infrastructure holds up and identify where your exposed internal assets and traffic patterns are today, sign up for a Cloud Network & AI Risk Assessment (CLARA). CLARA maps your cloud network risk posture and provides the actionable intelligence needed to eliminate evasion blind spots and secure your AI and multi-cloud future.