Listing Thumbnail

    Illumio Breach Containment Platform

     Info
    Sold by: Illumio 
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    Illumio Zero Trust Segmentation (ZTS) Platform is the only solution that handles it all: Endpoint-Endpoint, Endpoint-Server, Server-Server, as well as extensive support for cloud workloads, containers, IoT, and OT devices. Empowering organizations to be more resilient for whatever may come their way. ZTS contains the spread of breaches and ransomware across the hybrid attack surface by continually visualizing how workloads and devices are communicating, creating granular policies that only allow wanted and necessary communication, and automatically isolating breaches by restricting lateral movement proactively or during an active attack. In addition, Illumio ZTS includes the Illumio Virtual Advisor (IVA) which provides actionable, AI driven guidance for even the most complex tasks. With IVA, teams can streamline their workflows with instant, expert-level answers to their questions. Quickly access critical information and achieve complex tasks simply by asking the virtual advisor.
    4.4

    Overview

    Play video

    Illumio Breach Containment Platform provides comprehensive mapping of traffic telemetry across hybrid multi-cloud environments and endpoints for applications, data, and cloud workloads. This visualization allows security teams to uncover unnecessary connectivity that increases risk. With the Illumio Breach Containment Platform, you can easily know if you are at risk of an attack or currently under attack. Detailed context-based label descriptions of objects guides teams as they create policies, based on applications' components and relationships. With Illumio, teams can make faster, more informed decisions about what traffic to segment to proactively maintain a strong security posture or reactively isolate a breach.

    Illumio Breach Containment Platform is made up of these solutions:

    Illumio Insights for visibility and incident response. Quickly identify risk, detect attacks, and contain threats with a single click. Empower security teams to protect critical assets and respond instantly.

    Illumio Segmentation for cloud and on-premises data center workloads. Limit an attacker's ability to travel across lateral traffic with proactive policy controls that limit the exposure of valuable assets

    Highlights

    • See risk Visualize all communication and traffic between workloads and devices across the entire hybrid attack surface. Gain visibility with real-time telemetry and data, understand application communications, security policy, usage, access and security exposure with a comprehensive map of traffic flows.
    • Set policy Comprehensive monitoring and simplified labeling that helps eliminate blind spots by automatically setting granular and flexible segmentation policies that control communication between workloads and devices to only allow what is necessary and wanted.
    • Stop the spread Proactively isolate high-value assets or reactively isolate compromised systems during an active attack to stop the spread of a breach by programming dynamic workload policies for hybrid multi-cloud networks and endpoints, and applying automated policy recommendations.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Illumio Breach Containment Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (2)

     Info
    Dimension
    Description
    Cost/12 months
    Illumio Breach Containment Platform
    Price per 250 secured workloads + Breach Containment Platform
    $109,000.00
    100 CloudSecure Workloads
    Price per 100 public cloud workloads
    $38,400.00

    AI Insights

     Info

    Dimensions summary

    You buy this platform in two unit types that you can combine based on what you protect. The first unit covers 250 secured workloads and includes the Breach Containment Platform. The second unit covers 100 public cloud workloads. Both scale by adding more units as your workload count grows. A workload is a countable resource such as a virtual machine, database, or server operating system. Different resource types convert to workloads at different ratios, so you size your quantity from your actual environment. The two units are independent, so you select the mix that matches your infrastructure.

    Top-of-mind questions for buyers

    Different resources count at different ratios. A cloud virtual machine, database, or standard server operating system each counts as one workload. A container cluster host counts as two. Legacy operating systems count as two, and five user endpoints count as one workload. You size your quantity from your actual environment.
    The two units bill independently and appear together on the same invoice. The 250 secured workloads unit covers your servers, endpoints, and data center resources plus the platform. The 100 CloudSecure Workloads unit covers public cloud resources. Your infrastructure mix decides which unit contributes more.
    Each cloud workload includes 50MB per day of data processing. Each data center and endpoint workload includes 50MB of data traffic retention. Container cluster counting here does not include Kubernetes-specific visibility or enforcement, which requires a separate deployment. Contact the vendor to discuss that option.
    www.illumio.com
    Helpful?

    Vendor refund policy

    All fees are non-cancellable and non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Illumio provides customers with 24/7 support by phone, email, and through our support portal. +1 888 631 6354, support@illumio.com ,

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Security Observability, Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    3 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Real-time Traffic Visualization
    Comprehensive mapping and visualization of all communication and traffic flows between workloads and devices across hybrid multi-cloud environments and endpoints with real-time telemetry data.
    Granular Segmentation Policy Engine
    Automated creation and enforcement of granular, context-based segmentation policies that control communication between workloads and devices to allow only necessary and wanted traffic.
    Multi-environment Workload Support
    Support for diverse workload types including endpoint-to-endpoint, endpoint-to-server, server-to-server communications, cloud workloads, containers, IoT, and OT devices across hybrid architectures.
    Dynamic Breach Isolation
    Proactive and reactive isolation capabilities that restrict lateral movement by programming dynamic workload policies and applying automated policy recommendations during active attacks or for high-value asset protection.
    AI-driven Policy Guidance
    Artificial intelligence-powered virtual advisor that provides actionable recommendations for policy creation and complex segmentation tasks through natural language interaction.
    Network Policy Enforcement
    Fine-grained network policies that limit egress traffic by IPs, domains, and IP CIDRs with automatic namespace boundary identification and policy recommendations for namespace isolation.
    Egress Traffic Management
    Egress Gateway functionality that assigns static IP addresses to egress traffic from Kubernetes pods for integration with firewalls and tools requiring static IP identification.
    Ingress Traffic Management
    Ingress Gateway using Gateway API standard with integrated Envoy Gateway for comprehensive security and observability of ingress traffic.
    Multi-Cluster Network Security
    Centralized network security management across multiple Kubernetes distributions supporting individual and multi-cluster deployments in cloud and on-premises environments.
    Network Observability and Risk Mitigation
    Observability and risk mitigation capabilities for detecting and mitigating security breaches across all types of network traffic including egress, ingress, in-cluster, and cross-cluster communication.
    Zero Trust Architecture
    Cloud-native platform implementing zero trust principles to eliminate attack surface and prevent lateral movement across distributed workforce access.
    AI-Powered Threat Detection
    Advanced cyberthreat and data loss prevention services utilizing artificial intelligence to identify and halt threats in real-time.
    Data Loss Prevention
    Protection against data loss from users, SaaS applications, and public cloud infrastructure due to accidental exposure, theft, or ransomware attacks.
    Next-Generation Zero Trust Network Access
    Industry-specific zero trust network access (ZTNA) platform enabling seamless and secure connectivity to private applications, services, and operational technology devices.
    End-to-End Digital Experience Monitoring
    Visibility and performance optimization across the complete user journey from device through ISP to cloud proxy to application endpoints.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.4
    74 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    68%
    27%
    4%
    0%
    1%
    3 AWS reviews
    |
    71 external reviews
    External reviews are from G2  and PeerSpot .
    Igor M.

    The reference solution for host-based microsegmentation

    Reviewed on Aug 28, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Illumio is the real-time visibility into application dependencies and traffic flows. The Illumination map lets me understand how workloads communicate before writing any policy, which reduces the risk of breaking production. The label-based model makes policies readable and scalable instead of relying on IP addresses, and it works consistently across a mixed environment including Windows, Linux, and IBM i. The progressive path from visibility to test mode to full enforcement makes the Zero Trust journey low-risk and manageable.
    What do you dislike about the product?
    The initial learning curve can be steep, especially when building the labeling strategy. Getting the label model right from the start is critical, and it takes time to define conventions that scale well across a large and heterogeneous environment.
    What problems is the product solving and how is that benefiting you?
    Illumio solves the problem of lateral movement inside our network. In a traditional flat environment, once an attacker or a piece of malware gets in, it can spread easily between workloads. With microsegmentation, we contain that risk by allowing only the flows that are truly necessary between applications and environments. It also solved our lack of visibility: before Illumio, we didn’t have a clear picture of how workloads actually communicated, and now we can map dependencies precisely before enforcing any policy. This benefits us by reducing our attack surface, making audits and compliance easier to demonstrate, and giving us the confidence to isolate critical systems across a mixed fleet including Windows, Linux, and IBM i. Overall it strengthens our Zero Trust posture without forcing us to redesign the underlying network.
    Education Management

    Micro-Segmentation That Strengthens Defense-in-Depth

    Reviewed on Aug 28, 2026
    Review provided by G2
    What do you like best about the product?
    The micro segmentation of the network allows defense in depth of critical assets and network
    What do you dislike about the product?
    The complexity of the configuration of IP addresses and ports. Failure to properly implement may lead to unforeseen issues on the production workload.
    What problems is the product solving and how is that benefiting you?
    Illumio solves the problem of providing more granular network connectivity of critical assets.
    Information Technology and Services

    Easy Admin Setup, Lightweight Agent, Solid L4 Access Controls

    Reviewed on Aug 28, 2026
    Review provided by G2
    What do you like best about the product?
    • Easy configuration of the admin dashboard
    • Ability to configure Layer 4 (L4) access lists
    • Lightweight agent performance
    • Equipped with essential and sufficient features
    What do you dislike about the product?
    • Multi-session performance on Azure Virtual Desktop feels unstable.
    • Logs are aggregated, making them difficult to read.
    What problems is the product solving and how is that benefiting you?
    • Granular network restrictions for virtual hosts on Azure Virtual Desktop.
    Transportation/Trucking/Railroad

    Illumio Makes Segmentation Simple and Security Stronger

    Reviewed on Aug 27, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Illumio is the combination of strong visibility, intuitive policy management, and effective microsegmentation. The UI makes it easy to understand application and workload communication and manage security policies across environments. It integrates well with our existing security and infrastructure ecosystem and performs reliably as the environment scales. The onboarding experience and available support also make adoption easier for the team. Its intelligent insights and recommendations help us better understand our environment and make more informed security decisions. Overall, Illumio reduces complexity while strengthening our security posture.
    What do you dislike about the product?
    The main area for improvement is that some of the more advanced policy configurations can have a learning curve, particularly for new administrators. A simpler guided onboarding experience and more streamlined workflows would make the platform even easier to adopt. There is also an opportunity to expand integrations and provide additional intelligent recommendations that could further reduce manual analysis and policy administration. Despite these areas for improvement, the platform remains highly capable and delivers strong value for security teams.
    What problems is the product solving and how is that benefiting you?
    Illumio helps us solve the challenges of gaining visibility across workloads, controlling lateral movement, and consistently enforcing zero-trust security policies. Its integrations help bring security controls into our existing environment, while reliable performance allows us to manage protection at scale. The platform reduces manual effort through centralized policy management and intelligent visibility into application dependencies and communication patterns. Strong onboarding and support help the team adopt the platform effectively, while the reduced operational complexity and improved risk visibility provide meaningful value and ROI. Overall, Illumio helps us strengthen security while making day-to-day operations more efficient.
    Retail

    Full Network Visibility and Control in One Place

    Reviewed on Aug 27, 2026
    Review provided by G2
    What do you like best about the product?
    We like the idea that we have full view of what is going on in our network and then can write the appropriate rules to enforce.
    What do you dislike about the product?
    It is an expensive product and the licensing is a bit confusing too.
    What problems is the product solving and how is that benefiting you?
    It is allowing us to keep our environments separate, without cross contamination between production, dev, qa, etc.
    View all reviews