What flow records cannot tell you
I had a version of this site up for about a day that claimed a segmentation assessment could tell you 'this is an ORU result feed to a system that left your estate in 2023, and here are the message headers'. Two reviewers took it apart within an hour, and they were right to.
The argument underneath it is sound. HL7 v2 is carried over MLLP, a framing protocol with no native encryption — it was specified when the network was assumed trusted, which is why organisations wrap it in stunnel or mutual TLS when they want transport security. DICOM's classic DIMSE services carry the same assumptions, and DICOM over TLS is defined but unevenly deployed. Where those protocols are in the clear, a packet capture tells you what a flow actually is rather than merely that it exists.
The problem is that none of that applies to an assessment built on firewall logs and NetFlow.
Flow records contain addresses, ports, direction, byte and packet counts, and timestamps. They do not contain HL7 message headers. They do not contain a sending facility. They do not tell you that host 10.20.4.17 is an infusion pump rather than a badge reader — you can observe that something at that address talks to something else on port 2575, and port 2575 is a convention, not a proof.
So a claim like 'we identify the device by its traffic signature' is doing enormous unearned work. What actually happens is: you nominate the address ranges, and I report what crosses the boundaries between them.
This matters beyond honesty in marketing copy. If you buy an assessment expecting protocol-level findings and receive address-level findings, the report is a disappointment regardless of how good the analysis was — and you will reasonably conclude the whole category is overstated.
There is a second limit worth stating just as plainly. Observing traffic between two segments proves a path is open. Observing none proves nothing at all. The path may exist and be unused this week. Your collection point may sit on one leg of an asymmetric route. A trunk may be missing from the mirror. A rule that matched nothing in seven days may fire at quarter-end or during a failover you have not had this month.
That asymmetry means the only findings worth writing are the positive ones. 'Your matrix says these zones do not communicate, and here are 4,812 flows between them' is hard to argue with. 'We saw nothing, so you are fine' is not a finding, and any report that presents it as one is selling reassurance rather than evidence.
The deeper analysis is a real thing and I would like to build it. It needs packet capture, which needs a business associate agreement, which needs a clinical-engineering conversation, which needs a track record I do not have. That is a later product, and putting it on the website before it exists would have been the same mistake in a different costume.