Illumio launches AI-powered Insights to boost cyber resilience
Illumio has announced the general availability of Illumio Insights, a product designed to help organisations contain lateral movement threats across hybrid and multi-cloud environments.
Illumio Insights is part of the broader Illumio Platform and provides AI-powered detection, real-time risk insights, and one-click containment features.
The product is described as being built on an AI security graph, which is intended to enhance how security teams detect, prioritise and contain threats. Key functionality includes strategic segmentation and the ability to act on threats before they escalate, a need that has grown with the increasing complexity of organisational networks.
Private preview findings
During its private preview phase, early adopters using Illumio Insights identified a range of risks that had previously gone undetected with conventional tools. These included widespread east-west traffic emerging from unsanctioned geographies, misconfigured services that exposed sensitive ports, and unexpected use of public large language models (LLMs) that could introduce security concerns.
The product's suite now includes several new capabilities. Country Insights provides a geographical breakdown of network traffic and highlights threats by region, supporting rapid detection of unusual activity and the application of geography-specific security policies.
The Quarantine Dashboard offers one-click isolation for compromised systems, designed to enable prompt containment of threats by users with varying levels of technical expertise. Resource View streamlines investigation by providing targeted information about resources, helping teams to reduce exposure efficiently.
Industry and partner feedback
"Enterprises often struggle to maintain an accurate inventory of all devices, applications, and data flows across increasingly complex networks - especially with the rise of cloud services and hybrid environments," said Dr. Chase Cunningham, DrZeroTrust.
"Security graphs address this challenge by automatically ingesting data from diverse sources such as asset databases, cloud APIs, and network scans to build a dynamic, real-time map of infrastructure and dependencies. This living model not only enhances visibility but also strengthens security posture by revealing hidden risks and attack paths."
Chris Konrad, Vice President Global Cyber at World Wide Technology, commented on how clients were using the new capabilities: "Illumio Insights makes a strong impression right out of the gate; it helps security teams manage complexity and emerging AI technologies to focus on what matters."
"Our clients gain actionable insights that build trust and drive better decisions because we are able to identify risks, swiftly."
Delisa Stone, Partner, Cyber Security, Cloud and Resilience at Deloitte Technology and Transformation, stated, "Illumio Insights offers unparalleled visibility and granular segmentation capabilities that empower organisations to strengthen their cyber resilience."
"We recommend Illumio Insights to our clients seeking to enhance their security posture with a scalable, adaptive solution that aligns with evolving regulatory and operational demands."
Andrew Rubin, Chief Executive Officer and Founder of Illumio, said, "The biggest gap in cybersecurity today isn't tools, it's visibility. And that's exactly what Illumio Insights delivers. Illumio Insights changes the game. It gives security teams the visibility they've been missing, like what's talking to what, where the risk is, and how to contain it fast. This isn't about more alerts, it's about actionable intelligence that helps organisations stay ahead of real threats."
Breach containment focus
Illumio Insights is designed to work in tandem with Illumio Segmentation as part of the Illumio Platform.
While Insights enables rapid threat identification and detection, Segmentation focuses on breach containment, protection of critical assets, and enabling instant incident response.
The company states that together, these products aim to support organisations in identifying and mitigating security risks, containing threats before they proliferate, and ultimately improving organisational cyber resilience in a regulatory and operational climate that demands continuous adaptation.