{"id":152,"date":"2026-04-09T19:21:19","date_gmt":"2026-04-09T19:21:19","guid":{"rendered":"https:\/\/gigabrit.com\/?p=152"},"modified":"2026-04-09T19:26:53","modified_gmt":"2026-04-09T19:26:53","slug":"navigating-the-vdefend-security-journey","status":"publish","type":"post","link":"https:\/\/gigabrit.com\/?p=152","title":{"rendered":"Navigating the vDefend Security Journey"},"content":{"rendered":"\n<p><strong>Stage 1: The Security Segmentation Score<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"240\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.40.02-PM-1024x240.png\" alt=\"\" class=\"wp-image-153\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.40.02-PM-1024x240.png 1024w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.40.02-PM-300x70.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.40.02-PM-768x180.png 768w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.40.02-PM.png 1167w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>It happens every time I talk to a Security Team. Someone says something like \u201cZero Trust sounds great, but where do I even start without breaking the whole network?\u201d It\u2019s a valid fear. Most organizations are flying blind, guessing which firewall rules are actually doing work and which ones are just legacy clutter. If you want real results, you need trackable metrics. That\u2019s why the first step of the vDefend Security Journey isn&#8217;t about writing rules\u2014it&#8217;s about getting your Security Segmentation Score.<\/p>\n\n\n\n<p><strong>Not another score to track! <\/strong><\/p>\n\n\n\n<p>Stay with me here. The goal here isn&#8217;t to give your managers another metric to track how well you&#8217;re doing your job as a Security team. <\/p>\n\n\n\n<p>Instead think of this as a &#8220;credit score&#8221; for your data center\u2019s health. Instead of you manually auditing thousands of rows of spreadsheet data, the vDefend Security Services Platform (SSP) uses Security Intelligence to analyze your actual traffic flows (up to 30 days&#8217; worth) and compares them against your existing Distributed Firewall (DFW) policies.<\/p>\n\n\n\n<p>The result? A single number from 0 to 95 that tells you exactly how much of your environment is actually protected versus how much is sitting in an exposed &#8220;blast radius.&#8221;<\/p>\n\n\n\n<p>Why not a 100? Because simply put, the only way to really get a 100 score on anything related to Security is either to turn off the VM, or Unplug it from the Network. <\/p>\n\n\n\n<p><strong>Let&#8217;s walk through the process together. <\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Calculate Score : In the Security Services Platform on the &#8220;Monitor &amp; Plan&#8221; tab overview section, click &#8220;Calculate Score&#8221; <\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"721\" height=\"400\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.49.49-PM.png\" alt=\"\" class=\"wp-image-154\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.49.49-PM.png 721w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.49.49-PM-300x166.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.49.49-PM-672x372.png 672w\" sizes=\"auto, (max-width: 721px) 100vw, 721px\" \/><\/figure>\n\n\n\n<p>Noted in the UI is the following info about each mode.<\/p>\n\n\n\n<p>Strict<br>&#8220;Customers looking for a score that accurately reflects their data center security posture should use Strict mode. This mode highlights achieved security while applying stricter penalties for any allowed unidentified traffic.&#8221;<\/p>\n\n\n\n<p>Relaxed<br>&#8220;Customers creating security policies for their data center workloads may be cautious about denying traffic for fear of disrupting production applications. Relaxed mode emphasizes progress in rule creation rather than strict enforcement.&#8221;<\/p>\n\n\n\n<p>I recommend running the Strict mode, at this point there is no actual enforcement happening so there is minimal risk to causing any harm.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"582\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.53.37-PM-1024x582.png\" alt=\"\" class=\"wp-image-155\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.53.37-PM-1024x582.png 1024w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.53.37-PM-300x171.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.53.37-PM-768x437.png 768w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.53.37-PM.png 1512w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Now I&#8217;m already starting to see a picture of what I need to do in my environment to reduce my attack surface. <\/p>\n\n\n\n<p>A few details to point out in the Image above. <\/p>\n\n\n\n<p>Infrastructure Protection score is 0 because all infrastructure flows are currently unprotected. <\/p>\n\n\n\n<p>Environment Protection score is 0 because no environment is defined yet.<\/p>\n\n\n\n<p>Application Protection score is 0 because no applications are currently secured, and the datacenter is not locked down.<\/p>\n\n\n\n<p><strong>Security Segmentation Reports<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"456\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.58.23-PM-1024x456.png\" alt=\"\" class=\"wp-image-156\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.58.23-PM-1024x456.png 1024w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.58.23-PM-300x134.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.58.23-PM-768x342.png 768w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.58.23-PM-1536x685.png 1536w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.58.23-PM.png 1557w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Sample Report<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"692\" height=\"901\" data-id=\"158\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.59.49-PM.png\" alt=\"\" class=\"wp-image-158\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.59.49-PM.png 692w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-2.59.49-PM-230x300.png 230w\" sizes=\"auto, (max-width: 692px) 100vw, 692px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"690\" height=\"897\" data-id=\"157\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.00.03-PM.png\" alt=\"\" class=\"wp-image-157\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.00.03-PM.png 690w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.00.03-PM-231x300.png 231w\" sizes=\"auto, (max-width: 690px) 100vw, 690px\" \/><\/figure>\n<\/figure>\n\n\n\n<p><strong>Breaking Down the Report: A Reality Check<\/strong><\/p>\n\n\n\n<p>When you pull your first Security Segmentation Report, don\u2019t expect a gold star. In my recent assessment\u2014run in Strict Mode over a 30-day period\u2014the environment pulled a score of 6. <\/p>\n\n\n\n<p>Why so low? Because in Strict Mode, the system doesn&#8217;t give you credit for &#8220;trying&#8221;; it only counts explicitly identified and secured traffic. Anything matching a &#8220;Default Allow&#8221; rule is a direct hit to your score.<\/p>\n\n\n\n<p>The report looks at five core domains to see where you&#8217;re vulnerable. Here\u2019s how my lab measured up:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Infrastructure Protection (2.5\/5): We have the Distributed Firewall and Stateful services activated, but we haven&#8217;t actually blocked the risky stuff yet.<\/li>\n\n\n\n<li>Environment Protection (0\/2.5): Zero credit here. We haven&#8217;t defined &#8220;Production&#8221; vs. &#8220;Development&#8221; environments, so cross-contamination risk is at an all-time high.<\/li>\n\n\n\n<li>Application Workload Protection (0\/25): This is the big one. We have 93 application workloads running, and 100% of that traffic is unprotected.<\/li>\n\n\n\n<li>Malicious IP Protection (0\/5): We haven&#8217;t turned on the Malicious IP feeds yet, which is basically an &#8220;easy win&#8221; for the next stage.<\/li>\n<\/ul>\n\n\n\n<p><strong>Stage 1 Complete<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"368\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.09.59-PM-1024x368.png\" alt=\"\" class=\"wp-image-159\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.09.59-PM-1024x368.png 1024w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.09.59-PM-300x108.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.09.59-PM-768x276.png 768w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.09.59-PM-1536x552.png 1536w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-at-3.09.59-PM.png 1658w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Congratulations, you&#8217;ve just completed the first step in the Security Journey. Now that we&#8217;ve assessed your environment we can move towards taking real steps to secure it. <\/p>\n\n\n\n<p>This report is your prescriptive plan to locking down your Datacenter and preventing attacks. <\/p>\n\n\n\n<p>-Britton Johnson | @vcixnv | VCIX-NV | VCP-VCF9 <\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"514\" src=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/03\/vexpert-badge_Years-10.png\" alt=\"\" class=\"wp-image-144\" style=\"aspect-ratio:1.9455844353245173;width:266px;height:auto\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/03\/vexpert-badge_Years-10.png 1000w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/03\/vexpert-badge_Years-10-300x154.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2026\/03\/vexpert-badge_Years-10-768x395.png 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p>Written by me. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Stage 1: The Security Segmentation Score It happens every time I talk to a Security Team. Someone says something like \u201cZero Trust sounds great, but where do I even start without breaking the whole network?\u201d It\u2019s a valid fear. Most organizations are flying blind, guessing which firewall rules are actually doing work and which ones &hellip; <a href=\"https:\/\/gigabrit.com\/?p=152\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Navigating the vDefend Security Journey<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-152","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts\/152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=152"}],"version-history":[{"count":4,"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts\/152\/revisions"}],"predecessor-version":[{"id":163,"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts\/152\/revisions\/163"}],"wp:attachment":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}