Network segmentation is the practice of dividing a network into separate zones, or segments, and controlling which traffic is allowed to pass between them. Instead of one flat network where every device can reach every other device, segments group systems by role or sensitivity, such as guests, employees, servers, payment systems and building equipment, with rules at the boundaries. The goal is to limit how far an attacker, a piece of malware or a fault can spread from wherever it starts.
At a glance
- Segmentation splits one network into zones and controls the traffic between them.
- Separation is usually built with VLANs, subnets, wireless networks or cloud network constructs; enforcement comes from firewalls or access rules.
- Its main security value is containment: a compromised device reaches less.
- It can help with compliance scope, for example around payment card systems, subject to your assessor’s judgment.
- Microsegmentation applies the same idea at the level of individual workloads.
What problem it solves
Many mid-sized companies still run flat networks: laptops, servers, printers, cameras, phones and the guest Wi-Fi all share one address space with little or nothing in between. That is simple to run, but it means a single compromised device, perhaps a laptop that opened a malicious attachment or an unpatched camera, can scan and reach everything else. Ransomware operators rely on that freedom of movement.
Segmentation reduces the blast radius. If the guest network cannot reach internal systems, a visitor’s infected phone is not your problem. If user laptops can reach the file server only on the ports it needs, and cannot reach the backup system at all, an attacker on a laptop has fewer paths. Segmentation can also isolate devices that cannot be secured well, such as older equipment and connected devices with limited IoT security options, and it can keep a noisy or failing device from disrupting the whole network.
How it works
Design. Group systems by function and sensitivity, then decide which groups need to talk to which, on which ports. Typical segments include users, servers, management interfaces, guests, voice, IoT and building systems, and regulated environments such as payment systems.
Separation. On local networks, segments are usually built with virtual local area networks (VLANs) and separate IP subnets, with separate wireless networks mapped to them. In cloud environments, virtual networks, subnets and security groups do the same job. Physical separation is used where the risk justifies it.
Enforcement. Traffic between segments passes through a network firewall or routing equipment with access rules that allow only what is needed. Logging at these boundaries also gives security teams visibility into unusual movement.
Finer-grained control. Microsegmentation applies policy between individual servers or workloads, often using software on the hosts. It fits with zero trust security principles, which assume no device should be trusted just because of where it sits on the network.
Maintenance. Rules drift as applications change. Periodic reviews, and testing that the segmentation actually blocks what it should, keep it effective.
When it matters for buyers
- When refreshing switches, Wi-Fi or firewalls. New wired and wireless LAN infrastructure is the natural time to redesign segments.
- When cyber insurance renews. Insurers increasingly ask whether critical systems and backups are separated.
- When handling payment cards or regulated data. Segmentation may reduce compliance scope, if your assessor agrees.
- When adding IoT, cameras or building systems. These devices often cannot run security software and belong on their own segment.
- After an incident. Lateral movement during an attack is a common prompt to segment.
Our network firewalls overview covers the equipment that usually enforces the rules between segments.
Questions to ask vendors
- Can you map our current traffic flows before proposing a segmentation design?
- Which device enforces rules between segments, and does it have the throughput to inspect that traffic?
- How will you roll out changes without breaking applications, and can rules run in monitor-only mode first?
- How are rules documented, reviewed and changed over time?
- Can the design extend to our cloud environments and remote sites?
- How will we test that segmentation works, and do you provide evidence for auditors or insurers?
How it differs from a VLAN
A VLAN is a networking technique that splits one physical switch network into separate logical networks. It is one of the most common building blocks of segmentation, but it is not segmentation by itself. If traffic can route freely between VLANs, the network is divided on paper but not in practice. Segmentation is the overall design plus the rules that control what crosses between segments, whatever technology is used to build them.
