PCI Segmentation...Why is it so hard!

I've started two recent PCI DSS Audits over the last few weeks and both clients have not had an adequately segmented environment. 

The mere fact of having a firewall or two does not mean your network is segmented!

