Talk to us
by AkamaiTechBag Intel Page

Akamai Guardicore Segmentation

One stolen login can wander a flat network for weeks. Segmentation stops it at the first server — Akamai Guardicore Segmentation maps every flow between servers, containers, cloud services and OT devices and enforces allow-only policy — an agent where one fits, agentless where it cannot, with AI proposing the rules for you to approve.

Every workload gets its own allow-listAgent or agentless, cloud or on-premQuote only; Forrester Leader Q3 2026

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Akamai publishes no price and no licensing unit for Guardicore Segmentation; ask for a quote
Quote
Analysts
Forrester Wave Microsegmentation Solutions, Q3 2026, among 10 vendors evaluated
Leader (Forrester)
Deployment
The management plane runs in Akamai’s cloud or in your own data centre
Cloud or on-prem
India
Godrej’s customer story names Guardicore Segmentation across 600+ servers
Godrej

Quick answer

Akamai Guardicore Segmentation maps how servers, VMs, containers, cloud services and OT devices talk to each other, then enforces allow-only policy through an agent or, where none can run, agentlessly. AI proposes rules with confidence scores and a phased rollout. It runs from Akamai’s cloud or on-premises and is quote-only. Forrester named it a Leader in Microsegmentation (Q3 2026), and Godrej uses it in India. Read more ↓ Show less ↑
Part 01 · Orient

The Akamai platform family

This page covers Akamai Guardicore Segmentation — agent and agentless microsegmentation, cloud or on-premises. The rest:

Quick facts

30-second orientation
Product
Microsegmentation platform that maps east-west traffic and enforces allow-only policy
Maker
Akamai Technologies, Cambridge, Massachusetts; NASDAQ: AKAM; CEO Dr. Tom Leighton
Scale of maker
FY2025: $4.208B total revenue and $2.243B from security, as Akamai reported
Price
Not published; quote-only, and the licensing unit is not stated by Akamai
Enforcement
Agent on servers and endpoints; agentless mode for cloud PaaS, IoT and OT
Deployment
Management runs in Akamai’s cloud or on-premises in your own data centre
Coverage
Data centres, VMs, containers, Kubernetes, PaaS, legacy, OT, IoT and IoMT
Analysts
Forrester Wave Microsegmentation Q3 2026 Leader; GigaOm Radar 2026 Leader
India
Godrej runs it on 600+ servers; Akamai’s Bengaluru site (2018) houses a SOC
In India via
TechBag — flow mapping scope, quote in INR with GST, first ring-fence pilot
Part 02 · Learn

Understand microsegmentation before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is microsegmentation?

Each workload gets its own allow-list, so a compromised server can reach only what it needs, not the whole network.

Flat VLANs and firewall tickets vs Akamai Guardicore Segmentation — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionFlat VLANs, firewall ticketsAkamai Guardicore Segmentation
Who can talk to whatAny server inside the VLAN, on any portOnly the flows the allow-list approves
How rules are madeFirewall tickets, one change at a timeAI proposals with a score, approved in phases
Devices with no agentLeft flat, or on a VLAN of their ownMapped and covered in agentless mode
Seeing a lateral moveAfter the fact, from scattered logsOn the live map, down to the process
Containing ransomwarePull cables and rebuild whole subnetsRing-fence the affected hosts by label
What it is NOT—EDR, a perimeter firewall, or a published price

The cheapest test is a map-only pilot: put agents on twenty servers, watch the flows for two weeks, and count the paths nobody can justify.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where every flow becomes visible

Map

Continuous discovery and one map

Discovery finds known, unknown and unmanaged assets, labels them with semantic AI, and draws one live map of which process on which host talks to what, and on which port.

02
Enforcement on servers and endpoints

Agent

Guardicore Platform Agent

Installed on servers and endpoints, the agent ties each packet to the process that sent it and applies the allow-list; Akamai’s 10 September 2026 advisory says run 7.4 or later.

03
Reach where no agent can run

Agentless

Agentless visibility and control

Cloud PaaS services, IoT and OT devices, and unpatchable systems are covered without software on the device, so a PLC or an old appliance still sits inside a policy.

04
Where rules are proposed and approved

Console

Policy engine, cloud or on-prem

The management plane, hosted by Akamai or run in your own data centre, scores AI-suggested rules for confidence, phases them in, and hosts threat hunting and osquery checks.

One live map of every flow — enforced by an agent on hosts, agentlessly on OT, IoT and PaaS, from a cloud or on-prem console.

Part 03 · Evaluate

Nine capabilities. Map, segment, respond.

Akamai Guardicore Segmentation gives every workload its own allow-list, so one breached server cannot reach the rest.

Map
Discovery

Finds the assets nobody listed

Continuous discovery across IT, cloud, OT and AI workloads surfaces known, unknown and unmanaged assets on one live map.

Map
Labelling

Labels written for you

Assets are auto-labelled, with semantic AI adding role and application context, so rules target “payments DB” rather than IPs.

Map
Process-to-packet

Which process opened the port

Each connection is tied to the process behind it, so you can allow sqlservr.exe on port 1433 and still block a script on it.

Segment
AI policy

Rules proposed, with a score

Policy recommendations come with confidence scoring, evidence and a phased workflow, so you approve rules instead of writing them.

Segment
Agentless

OT and IoT without software

Devices that cannot take an agent — PLCs, medical kit, cloud PaaS — are still mapped and placed inside segmentation policy.

Segment
Containers

Short-lived workloads too

Kubernetes clusters, PaaS and ephemeral workloads are covered, so policy follows a pod by its labels rather than a fixed address.

Respond
Risk scoring

Tighten where exposure is high

Contextual risk scores drive exposure-aware guidance, so the riskiest, most reachable assets are ring-fenced before the rest.

Respond
Threat hunting

Investigate from the same map

AI-driven threat hunting lets an analyst trace an incident across the flows already recorded, then block the path in one policy.

Respond
osquery

Spot the high-risk hosts

osquery-powered insights query hosts for risky platforms and configurations, feeding which machines to isolate first.

See it, don’t just read it

Watch Akamai Guardicore Segmentation in action

Four official Akamai videos: a 2026 explainer, a 2025 demo of lateral-movement control, a 2025 ransomware containment walkthrough and a 2024 overview.

Akamai (official)·Explainer, September 2026

When a Breach Hits a Brick Wall | Zero Trust & Microsegmentation

Why a segmented network stops an intruder at the first host instead of letting them roam.

Akamai (official)·Demo, August 2025

Demo: Visualize and control lateral movement | Akamai Guardicore Segmentation

The map, a policy built from observed flows, and lateral movement blocked in the console.

Akamai (official)·Walkthrough, August 2025

Ransomware: From Click to Containment with Akamai Guardicore Segmentation

A ransomware chain followed from the first click to the point where segmentation contains it.

Akamai (official)·Overview, May 2024

Akamai Guardicore Segmentation: Overview by Christian Samuel

A 2024 walk through the product; features added since then may not appear in it.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Akamai Guardicore Segmentation

Attackers rarely stop at the first machine. Guardicore Segmentation makes the next hop the hard part.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Agent where it fits, agentless where it cannot

Most estates mix servers that can take software with devices that never will: PLCs, medical kit, appliances, cloud PaaS. Guardicore Segmentation runs an agent on the first group and covers the second agentlessly, so one policy and one map span the data centre, the cloud and the plant floor rather than two tools.

02

Rules you approve rather than write

Writing an allow-list by hand for thousands of flows is where segmentation projects stall. Here the platform watches real traffic, proposes rules with a confidence score and the evidence behind it, and suggests a phased order, so the team reviews and approves policy in stages instead of drafting it.

03

Third-party proof at scale

Forrester named Akamai a Leader in its Microsegmentation Wave for Q3 2026, with top scores in 11 criteria including asset discovery and policy administration; GigaOm’s 2026 Radar made it a Leader and Fast Mover. Akamai cites a consulting firm that secured 300,000 endpoints in two weeks.

04

Where it stops

There is no public price or licensing unit, so budgets wait for a quote. Akamai documents no Indian hosting region for the cloud console; choose on-premises if policy data must stay in-house. The agent needs patching: the September 2026 advisory fixed a CVSS 8.5 flaw. It is not EDR or a perimeter firewall.

The idea
Every workload gets its own allow-list
The residency
Cloud console, or on-premises in India
The price
Quote only; no licensing unit published
Proof, not promises

The numbers behind the platform

300000 endpoints
secured in two weeks by a global consulting firm, as Akamai’s product page reports
— Customer
16 lakh people
served by a water utility that Akamai cites as a Guardicore Segmentation customer
— Customer
600+ servers
covered by Guardicore Segmentation at Godrej Industries Group, per its customer story
— Customer
300+ apps
Godrej says it protected in six months, using Guardicore with two other Akamai products
— Customer
11 criteria
where Akamai earned the top possible score in Forrester’s Q3 2026 Microsegmentation Wave
— Analyst
10 vendors
evaluated in the Forrester Microsegmentation Wave (Q3 2026), which named Akamai a Leader
— Analyst

What your Akamai Guardicore Segmentation rollout looks like

Week 1Model

Map before you block

Deploy agents on a pilot group of servers, switch on agentless discovery for the rest, and let the map fill with real flows.

Week 2Decide

Pick the crown jewels

Choose the first ring-fence, such as core banking or ERP databases, and label the applications and owners around it.

Week 3Pilot

Review the AI proposals

Accept the high-confidence rules, run the doubtful ones in alert-only mode, and log which flows app owners dispute.

Month 2Prove

Enforce the first segment

Turn the ring-fence to block, watch for broken flows for a fortnight, then add OT and IoT devices in agentless mode.

Month 3Commit

Widen and hunt

Extend policy across the estate in phases, patch agents to 7.4 or later, and hand the SOC the map for threat hunting.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
58+ reviews*
86% would recommend
Traffic visibility and map4.6
Policy recommendations4.4
Agentless coverage4.2
Ease of rollout3.9
Value for money3.8
5★
52%
4★
33%
3★
10%
2★
3%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“The map showed our core banking servers accepting SMB from the whole branch range. We closed that within the first week.”
Network Security Lead
BFSI
Manufacturing
“Our plant PLCs cannot run anything. Agentless mode put them in their own segment without a single change on the floor.”
OT Security Manager
Manufacturing
Pharmaceuticals
“Confidence scores on suggested rules let us enforce the high-scoring ones first and leave the doubtful ones in alert mode.”
Infrastructure Architect
Pharmaceuticals
E-commerce
“Seeing the process behind each flow ended arguments with app owners about which service really needs that port.”
Platform Engineer
E-commerce
Healthcare
“Patch the agent like any other software. We had to push 7.4 across hundreds of hosts after the September advisory.”
Systems Administrator
Healthcare
Logistics
“Strong product, but the quote took several rounds and the licensing basis was hard to compare with Illumio’s.”
IT Procurement Head
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the microsegmentation market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Microsegmentation Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Akamai Guardicore SegmentationThis page

Forrester Leader, Q3 2026; quote-only.

Grid 02 · The architecture

Agentless Reach × Workload Depth

The grid nobody publishes — how far enforcement reaches without an agent vs how deep it sees and acts inside each workload.

Agent-deep workload toolsHybrid agent-and-agentless platformsHypervisor-bound firewallsNetwork-native segmenters
Akamai Guardicore SegmentationThis page

Agent plus agentless for PaaS, IoT and OT; process-level map and hunting.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Akamai Guardicore Segmentation vs the microsegmentation field

Against Illumio Segmentation, Zero Networks Segment, Cisco Secure Workload, Elisity and VMware vDefend — on enforcement, coverage, price, detection, India and exit.

DimensionAkamai Guardicore SegmentationIllumio SegmentationZero Networks SegmentCisco Secure WorkloadElisityVMware vDefend
What it isAI segmentation platformAgent-led segmentationAgentless, MFA-backedWorkload segmentationIdentity-based, networkHypervisor firewall
DeploymentCloud or on-premisesSaaS, or on-prem PCESaaSSaaS or on-prem clusterCloud-managedOn-prem software
Enforcement methodAgent and agentlessVEN programs host FWOS APIs, no agentWFP, iptables, cloud SGsSwitch-native policyIn the ESXi kernel
CoverageIT, cloud, OT, IoT, K8sServers to endpointsWindows, Linux, OTVMs, metal, KubernetesIT, IoT, OT, IoMTVMware estates
Visibility and mappingProcess-to-packet mapReal-time traffic map30-day learning modeFlows from many feedsIdentityGraphInside VMware only
Policy automationAI rules, scoredRecommended allow-listsAuto-generated rulesAI/ML policy lifecycleDynamic policy engineRules you author
Scale on record300,000 endpoints3,000 servers (eBay)90% in 90 daysUp to 999,999 (SaaS)10,000+ devicesBound by host cores
Pricing modelUnit not publishedPer workload, yearlyPer 500-asset bundlePer workload, 1–5 yrsNot publishedPer core, subscription
Published entry priceQuote only$109,000 / 250 / year$100,000 / 500 / yearNot on the datasheetNot publishedNot published
Included vs add-onHunting in platformInsights sold apartThree separate productsProtection vs endpointOne platformATP is an add-on
Detection and responseAI threat huntingSeparate productMFA on admin portsBehaviour anomaliesPartner signalsVia ATP and NDR
India data and presenceOn-prem, or askOn-prem PCE optionSaaS, region unstatedOn-prem clusterSaaS, region unstatedYour own hosts
Lock-in and exitNot tied to a stackNative host firewallsNothing to uninstallCisco ecosystem pullTied to your switchesVMware only
Best fitMixed IT, cloud and OTServer-heavy hybridFast, agent-free startLarge Cisco data centresCampus, IoT and OTVMware-only estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Akamai Guardicore Segmentation if…

  • ✓Your estate mixes servers, containers, cloud PaaS and OT or IoT devices, and you want one map and one policy across all of them
  • ✓You want AI to propose the allow-list with a confidence score, so the team approves rules in phases instead of writing them
  • ✓You want threat hunting on the same map that enforces the policy, from a Forrester Microsegmentation Leader (Q3 2026)

Compare alternatives if…

  • ✓You need a price before a sales call — Illumio and Zero Networks list theirs on AWS Marketplace
  • ✓You want no agent at all on Windows servers — Zero Networks drives the hosts’ own firewalls through OS APIs
  • ✓Your estate is entirely VMware — vDefend enforces inside the hypervisor you already own

Do not expect…

  • ✓A published price or a stated licensing unit
  • ✓A documented Indian region for the cloud-hosted console
  • ✓Endpoint detection and response, or a perimeter firewall in place of your NGFW

TechBag has no microsegmentation guide yet, so Akamai Guardicore Segmentation sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does a flat network cost you to run?

Drag the sliders (servers and workloads to segment; engineer-hour cost). Estimates model time spent raising firewall-rule tickets, tracing who talks to whom and answering segmentation audits, at an assumed 1.5 hours per workload a year, with 70% of it removed by a live map and proposed rules. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual segmentation-operations cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Akamai publishes no price and no licensing unit for Guardicore Segmentation; a demo comes first. Ask what is counted — servers, endpoints or assets — and whether agentless devices are priced apart. TechBag scopes the estate, compares cloud and on-premises hosting, then quotes in INR with GST.

Cloud-hosted console

Best when Akamai should run the management plane

  • Quote only; no public price
  • Agent plus agentless coverage
  • Ask where data is stored

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

On-premises console

Best when policy data must stay in your data centre

  • Quote only; sized by TechBag
  • Management in your own DC
  • Plan agent upgrades in-house

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Scope

How many servers, endpoints, containers and OT or IoT devices are in scope, and which of them can run an agent?

2
Hosting

Will the console run in Akamai’s cloud or on-premises? Ask Akamai in writing where cloud-hosted data is stored.

3
Crown jewels

Which applications form the first ring-fence, and who signs off when a proposed rule blocks a flow?

4
Agentless reach

Which PLCs, medical devices or PaaS services must be covered agentlessly, and what data does that mode need?

5
Agent hygiene

Can you push Guardicore Platform Agent 7.4 or later across every host, as the September 2026 advisory requires?

6
ZTNA link

Do you also use or plan Akamai Enterprise Application Access, and should Zero Trust Client handle both roles?

7
Licence

What exactly is counted — servers, endpoints, assets or cores? Ask for INR with GST, the term and renewal cap.

8
Category

TechBag does not have a microsegmentation guide yet, so weigh the five rivals in the table above directly.

FAQ

Questions buyers ask

It is Akamai’s microsegmentation platform. It discovers the assets on your network, maps which process on which host talks to what, and enforces allow-only policy so an attacker who lands on one machine cannot move to the next. It works with an agent or, for PaaS, IoT and OT, agentlessly.

Ready to evaluate Akamai Guardicore Segmentation?

Map your east-west traffic first, or let a TechBag advisor scope a pilot that ring-fences one critical application before enforcement widens.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.