Networking / capability
Network Access Control and Segmentation
Policy runs in monitor-only mode first, so you see exactly what would have been blocked for a month before anything is. Segmentation fails on assumptions.
The camera on your perimeter and the laptop in your finance team are on the same network until somebody decides they are not.
That decision usually gets deferred, because segmentation looks like a project and the flat network works. It keeps working right up until one compromised device can reach everything the network can reach.
Extreme builds its switching software around the same policy controls this kind of segmentation project runs on, and SECCOM designs against whatever an estate already holds.
Get SECCOM to map your real traffic before any rule is written. Segmentation fails when it is designed on assumptions.
What you get. A policy matrix: every device class against every destination it is permitted, reviewed with you before enforcement.