[Submitted on 9 Apr 2026 (v1), last revised 24 Jul 2026 (this version, v3)]

View PDF HTML (experimental)

Abstract:Network segmentation is a foundational enterprise security control. Despite its recognized benefits, segmentation initiatives frequently fail in practice, and the field lacks a systematic empirical explanation for why these projects do not achieve their intended outcomes. This paper presents an empirical study of failed segmentation projects based on a survey of 400 U.S.-based\ network security practitioners. The survey was grounded in a two-part failure framework that separately measures general IT project failure factors and segmentation-specific technical and operational barriers. Clustering analysis of the responses reveals four distinct failure archetypes, ranging from projects in which every factor contributed simultaneously to projects where governance was comparatively better but specific segmentation challenges proved decisive. The archetypes correspond to real differences in how segmentation was attempted: projects that included campus networks were more likely to experience the broadest or most technically intense failures. On the other hand, the archetypes did not differ significantly by workload type.

Submission history

From: Rohit Dube [view email]
[v1] Thu, 9 Apr 2026 17:00:23 UTC (563 KB)
[v2] Thu, 30 Apr 2026 05:21:21 UTC (562 KB)
[v3] Fri, 24 Jul 2026 13:47:49 UTC (566 KB)