Enterprise networks are becoming harder to secure at the same time that attackers are moving faster. Tufin is addressing that gap with Segmentation Intelligence, an AI-powered capability designed to continuously check whether network segmentation policies are still working as intended across hybrid environments.
For years, network segmentation has been one of the foundational controls behind Zero Trust security. The idea is straightforward: separate sensitive workloads, restrict unnecessary communication and limit how far an attacker can move if an environment is compromised.
Keeping those controls aligned with reality is considerably harder.
Cloud workloads move. Firewalls are reconfigured. Subnets change. SASE architectures expand. New applications and infrastructure appear faster than security teams can manually validate every policy protecting them.
Tufin’s new Segmentation Intelligence is designed for that problem. The company says the AI-powered solution continuously analyzes segmentation policies, zones, subnets and network objects to determine whether an organization’s intended security model remains intact.
The shift is important because segmentation validation has traditionally been a periodic exercise. Security teams may review controls ahead of an audit, after a major infrastructure change or following an incident. In a highly dynamic hybrid environment, that approach can leave gaps between what security leaders believe their controls are doing and what the network is actually enforcing.
Tufin’s proposition is to turn that validation into an ongoing process.
Rather than examining one firewall or network domain at a time, Segmentation Intelligence is intended to identify policy gaps, segmentation drift and potentially exploitable coverage weaknesses across the broader environment. It can then help teams prioritize remediation according to business risk.
That puts Tufin into a growing enterprise security category around continuous security assurance.
The timing is significant. Organizations are increasingly adopting Continuous Threat Exposure Management (CTEM) practices as they attempt to identify and reduce exploitable exposure continuously rather than relying exclusively on annual assessments and vulnerability scans.
The same principle applies to segmentation.
A policy can be technically present but operationally ineffective. A rule may cover the wrong subnet. A new cloud workload may not inherit the intended controls. A network change may unintentionally create a path between environments that were supposed to remain isolated.
For security teams, the question is therefore no longer simply whether a segmentation policy exists. It is whether the policy still reflects the organization’s security intent.
Tufin says Segmentation Intelligence is built to answer that question continuously.
From security policy to security assurance
The distinction between policy management and security assurance is becoming increasingly important.
Traditional network security tools are generally optimized around configuring and enforcing controls. Tufin’s new capability adds an analytical layer that examines whether those controls continue to correspond with the organization’s intended segmentation strategy.
That could be particularly relevant for enterprises operating across data centers, public clouds, firewalls, SASE infrastructure and distributed networks.
Tufin says its system can analyze the relationships between policies, zones, subnets and objects to identify where segmentation does not match the desired security posture. Instead of producing another generic security dashboard, the objective is to give teams a prioritized view of where exposure requires attention.
That approach also aligns with the industry’s growing interest in using AI for security operations—not simply to generate summaries, but to continuously analyze complex environments and identify relationships that would be difficult to monitor manually.
Microsoft, Google and other major technology providers are pursuing similar AI-driven approaches across security operations, although their focus is generally broader than network segmentation. Microsoft’s Security Copilot, for example, uses AI agents across areas including threat detection, investigation and response.
Tufin’s opportunity is more specialized: use AI to understand the relationship between segmentation intent and the controls deployed across enterprise networks.
Why continuous validation matters
Tufin cites research indicating that 54% of enterprise cybersecurity leaders do not have a clear understanding of whether their security controls are in place and working at any given time. That statistic comes from research referenced by the company, so it should be viewed in that context.
The broader problem is well established.
Security teams are responsible for increasingly complicated control environments while simultaneously being asked to demonstrate compliance with regulations and frameworks. NIS2 and DORA, for example, have increased the emphasis on operational resilience and effective security controls for organizations covered by those regimes.
Meanwhile, the threat environment is changing.
Verizon’s 2026 Data Breach Investigations Report has highlighted vulnerability exploitation as a major initial access vector, while AI is accelerating the speed at which attackers can identify and exploit weaknesses. That creates a shorter window for defenders to discover that a security control has drifted from its intended configuration.
In that environment, periodic validation can become a dangerous lagging indicator.
Continuous segmentation analysis does not eliminate the need for security architecture, network engineering or human review. Instead, its potential value is reducing the amount of manual work required to establish whether segmentation remains effective.
The enterprise adoption question
For enterprise security leaders, the most important consideration will be how Segmentation Intelligence fits into existing infrastructure.
Large organizations rarely operate a single network technology. Their environments can include multiple firewall vendors, cloud platforms, SASE services, data centers and legacy systems. A segmentation product that only understands one technology domain can therefore provide an incomplete picture.
Tufin is positioning its broader platform as the aggregation layer for that complexity.
The company says Segmentation Intelligence can continuously identify gaps across policies and network infrastructure, detect unintended exposure, prioritize remediation based on business risk and provide evidence that supports compliance and Zero Trust initiatives.
The potential payoff is straightforward: fewer blind spots and less dependence on manually assembled audits.
But AI-driven security assurance also creates its own requirement for transparency. Enterprises will need to understand why a platform has identified a segmentation gap, which controls it examined and how it arrived at a remediation recommendation. Explainability and auditability will matter as much as detection.
Tufin’s launch reflects a larger transition in enterprise cybersecurity. Security teams are moving from asking whether a control was configured correctly to asking whether it continues to work correctly as the environment changes.
That is a much harder problem—and one increasingly suited to continuous machine analysis.
Market Landscape
Network segmentation sits at the intersection of Zero Trust, network security policy management, CTEM and enterprise security automation.
Traditional segmentation tools tend to focus on enforcing or managing network policies. Meanwhile, broader security platforms from Microsoft, Google, Palo Alto Networks and others increasingly use AI to analyze alerts, vulnerabilities and security telemetry.
Tufin is taking a narrower approach by applying AI to the relationship between security intent and segmentation enforcement.
For enterprises, the key competitive question will be coverage. A useful continuous assurance platform needs visibility across cloud, on-premises networks, firewalls and distributed infrastructure rather than producing another isolated view.
The broader market direction is clear: as infrastructure becomes more dynamic, security controls are increasingly being evaluated as continuously changing systems rather than static configurations.
That creates an opening for technologies that can continuously verify whether controls remain effective without requiring security teams to manually audit every change.
Top Insights
- Tufin Segmentation Intelligence uses AI to continuously identify network segmentation gaps and drift, helping enterprise security teams validate Zero Trust controls across hybrid environments.
- The technology shifts segmentation validation from periodic audits toward continuous assurance, potentially reducing manual checks as cloud infrastructure and attack surfaces change faster.
- Security leaders gain a way to prioritize segmentation remediation according to business risk, rather than treating every policy discrepancy as equally important.
- The launch reflects broader enterprise adoption of AI security automation, alongside platforms from Microsoft, Google and other cybersecurity vendors.
- For regulated enterprises, continuous evidence about segmentation controls could support compliance, resilience and security governance while reducing dependence on point-in-time assessments.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI




