Smarter Boundaries, Stronger Networks
Network Infrastructure

Smarter Boundaries, Stronger Networks

Elvis Chong, Vice President IT Networking, Bursa Malaysia

Elvis Chong, Vice President IT Networking, Bursa Malaysia

With decades in enterprise networking, I specialize in system integration, financial services, and cloud architecture. An active CCIE and award-winning professional, I’ve led PDIOO initiatives, authored industry content, and earned titles like Cisco Learning Network Ambassador and Cisco Designated VIP, showcasing deep expertise and leadership in the field.

In an exclusive interview with Network Infrastructure Magazine APAC he shared invaluable insights on network micro-segmentation is essential for modern Cybersecurity, its successful implementation requires overcoming legacy system complexity, limited visibility, and tight timelines making a phased, appby-app approach with smart tools the most practical path forward.

1. “Hi Elvis, can you talk a little bit about the importance of network micro-segmentation?”

So, let’s rewind a bit and ask ourselves why micro-segmentation even matters. Yes, we need it to address the lateral movement problem. Imagine an attacker gets into just one machine, if the network isn’t segmented, they can start poking around, trying to brute-force other systems in the same zone.

Worse case, they can pretend to be a legit host and launch attacks on systems in other parts of the network. That’s where micro-segmentation comes in, it’s like putting locks on every door and only giving keys to the right people. Even if someone breaks in, they’re stuck in that one room. It really helps contain threats and protect sensitive systems.

2. “Can’t we do network micro segmentation the same way using legacy method? What are the challenges?”

I think most engineers would agree, the old-school way of doing segmentation using IP subnets and VLANs is no longer effective for modern networks. Sure, it worked when networks were simpler, but now we’re dealing with all kinds of servers, applications, hosting in on-premises or in cloud.

“Micro-segmentation isn't just a security upgrade it's a mindset shift. You need time, visibility, and precision to protect what matters most in a dynamic network world”

Trying to micro-segment using tons of small IP subnets and VLANs quickly becomes a nightmare. Imagine doing that in a global enterprise, the operational overhead is massive. You’d need to constantly update configurations, manage IP ranges, and keep everything in sync across regions. It’s just not scalable or flexible enough for today’s dynamic workloads.”

3. “So, what are the challenges in implementing micro segmentation?”

It really depends on the solution you choose. Whether it’s hostbased or network-based, each has its fans and critics. If you go with agent-based, where you install software directly on the host, application owners usually aren’t too happy about it. No one likes extra stuff running on their servers. And when something goes wrong? Yep, your “lightweight agent” is often the first to blame. On the flip side, with network-based solutions, you’ll need to make sure all your network devices are properly licensed to support the required features, which can be a challenge. But honestly, those aren’t even the hardest parts yet.

4. “Can you elaborate more about the toughest parts?”

The real challenge usually comes during a brownfield migration, when you're moving from a legacy setup to a micro-segmented network. And here’s the thing: you’ll often find that a lot of critical information is missing.

IT moves fast. People come and go. Systems evolve. Documentation gets outdated, or worse, it was never written down. The network was flat for years, and even when you talk to system owners, they might not know who or what should be accessing their systems.

To tackle this, you’ve got to figure it out the hard way, analyse existing firewall rules, dig through logs, trace traffic, and piece things together like a detective. One helpful approach is to run the micro-segmentation solution in monitoring mode. That way, we’re not blocking anything yet, we’re just observing. It lets us see what connections are active and being used. From there, we can build a baseline of legitimate traffic, which becomes the foundation for designing the right policies later.

5. “The monitoring mode sound promising, isn’t that enough?”

I wish it were! But the toughest part still isn’t over. The reality is, project timelines. No project gives you unlimited time to analyse everything in detail. So the question becomes, how much time do you really have to study all the traffic, build a fine-grained microsegmentation policy, and then enforce it?

Monitoring mode does helps, it gives us the visibility into active connections. But it’s not foolproof. You might still miss things, especially secondary systems or disaster recovery systems. These passive systems only activated when the active nodes goes wrong, it often don’t show up during normal hours or regular operations, so they can easily slip through the cracks if you're not careful.”

6. “You mentioned fine-grained policy, is that really necessary? Can’t we start with something more generic?”

And yes, fine-grained policy is absolutely necessary. Otherwise, why even bother with micro-segmentation, right?

Let’s talk security for a moment. The principle of least privilege is key, we allowing what’s permitted and blocking everything else. To do that effectively, your policies need to be detailed. The more precise your rules, the better you can control access and reduce risk. Now, designing those detailed policies isn’t easy. It’s complex, time-consuming, and sometimes frustrating. But that’s the trade-off, security vs. simplicity. You can start with something generic, sure, but eventually, you’ll need to tighten things up to truly benefit from micro-segmentation.

7. “Final question, do you have any advice for our reader, for implementing micro-segmentation?”

“If I may share from my humble experience, yes, I do have a few thoughts. First off, I truly believe micro-segmentation is essential in today’s modern networks. Sure, it’s challenging, and you can’t expect to flip the switch overnight. It’s best to approach it app-byapp, gradually rolling out segmentation across your environment. Extending the project timeline helps avoid a “massive blocking day” where too much gets restricted all at once. Take it step by step, and give yourself room to analyze and refine.

The good news? Things are getting better. With the rise of Software-Defined Networking (SDN), automation, and AIdriven tools, implementing micro-segmentation is becoming more manageable.

Finally, I’m optimistic. I believe the future holds smarter, more innovation that will make micro-segmentation easier and more effective for everyone.

That’s my final word thanks for the great questions!”

Weekly Brief

-->

Read Also

When Buildings Become Networks: The Next Managed Services Opportunity

When Buildings Become Networks: The Next Managed Services Opportunity

Joseph Weyel, RCDD, RTPM, Director of Technology Services, Big State Electric, Ltd
Why AI Strategy Fails Without Data Strategy

Why AI Strategy Fails Without Data Strategy

Greg Sharma, Director – IT Infrastructure, Maple Lodge Farms