What Is Network Segmentation?

Related problems: One infected laptop could reach every server on the network; Guest Wi-Fi and IoT devices on the same network as finance systems; Cyber insurer or auditor asking how our network is segmented; Payment or regulated systems mixed in with everything else

Network segmentation is the practice of dividing a network into separate zones, or segments, and controlling which traffic is allowed to pass between them. Instead of one flat network where every device can reach every other device, segments group systems by role or sensitivity, such as guests, employees, servers, payment systems and building equipment, with rules at the boundaries. The goal is to limit how far an attacker, a piece of malware or a fault can spread from wherever it starts.

At a glance

  • Segmentation splits one network into zones and controls the traffic between them.
  • Separation is usually built with VLANs, subnets, wireless networks or cloud network constructs; enforcement comes from firewalls or access rules.
  • Its main security value is containment: a compromised device reaches less.
  • It can help with compliance scope, for example around payment card systems, subject to your assessor’s judgment.
  • Microsegmentation applies the same idea at the level of individual workloads.

What problem it solves

Many mid-sized companies still run flat networks: laptops, servers, printers, cameras, phones and the guest Wi-Fi all share one address space with little or nothing in between. That is simple to run, but it means a single compromised device, perhaps a laptop that opened a malicious attachment or an unpatched camera, can scan and reach everything else. Ransomware operators rely on that freedom of movement.

Segmentation reduces the blast radius. If the guest network cannot reach internal systems, a visitor’s infected phone is not your problem. If user laptops can reach the file server only on the ports it needs, and cannot reach the backup system at all, an attacker on a laptop has fewer paths. Segmentation can also isolate devices that cannot be secured well, such as older equipment and connected devices with limited IoT security options, and it can keep a noisy or failing device from disrupting the whole network.

How it works

Design. Group systems by function and sensitivity, then decide which groups need to talk to which, on which ports. Typical segments include users, servers, management interfaces, guests, voice, IoT and building systems, and regulated environments such as payment systems.

Separation. On local networks, segments are usually built with virtual local area networks (VLANs) and separate IP subnets, with separate wireless networks mapped to them. In cloud environments, virtual networks, subnets and security groups do the same job. Physical separation is used where the risk justifies it.

Enforcement. Traffic between segments passes through a network firewall or routing equipment with access rules that allow only what is needed. Logging at these boundaries also gives security teams visibility into unusual movement.

Finer-grained control. Microsegmentation applies policy between individual servers or workloads, often using software on the hosts. It fits with zero trust security principles, which assume no device should be trusted just because of where it sits on the network.

Maintenance. Rules drift as applications change. Periodic reviews, and testing that the segmentation actually blocks what it should, keep it effective.

When it matters for buyers

  • When refreshing switches, Wi-Fi or firewalls. New wired and wireless LAN infrastructure is the natural time to redesign segments.
  • When cyber insurance renews. Insurers increasingly ask whether critical systems and backups are separated.
  • When handling payment cards or regulated data. Segmentation may reduce compliance scope, if your assessor agrees.
  • When adding IoT, cameras or building systems. These devices often cannot run security software and belong on their own segment.
  • After an incident. Lateral movement during an attack is a common prompt to segment.

Our network firewalls overview covers the equipment that usually enforces the rules between segments.

Questions to ask vendors

  • Can you map our current traffic flows before proposing a segmentation design?
  • Which device enforces rules between segments, and does it have the throughput to inspect that traffic?
  • How will you roll out changes without breaking applications, and can rules run in monitor-only mode first?
  • How are rules documented, reviewed and changed over time?
  • Can the design extend to our cloud environments and remote sites?
  • How will we test that segmentation works, and do you provide evidence for auditors or insurers?

How it differs from a VLAN

A VLAN is a networking technique that splits one physical switch network into separate logical networks. It is one of the most common building blocks of segmentation, but it is not segmentation by itself. If traffic can route freely between VLANs, the network is divided on paper but not in practice. Segmentation is the overall design plus the rules that control what crosses between segments, whatever technology is used to build them.

Frequently Asked Questions

Is a VLAN enough to segment a network?
Not on its own. A VLAN separates traffic logically, but if devices on different VLANs can route to each other freely, the separation adds little security. Segmentation needs rules, usually on a firewall or similar device, that decide which traffic may cross between segments.
What is microsegmentation?
Microsegmentation applies the same idea at a much finer level, controlling traffic between individual workloads or applications rather than between broad zones. It is common in data centers and cloud environments and is usually enforced by software on the hosts or in the virtualization platform.
Does segmentation help with PCI compliance?
It can. Under PCI DSS, properly isolating systems that store, process or transmit card data may reduce the number of systems in scope for assessment. Your assessor decides whether the segmentation is adequate, and it typically has to be tested, so involve them early.
How should a small company start segmenting its network?
Begin with the obvious separations: guests, IoT and building systems, user devices, servers, and anything regulated such as payment systems. Put them on separate segments, allow only the traffic each needs, and log what crosses between them. Refine from there.
Will segmentation break our applications?
It can if rules are written without knowing which traffic applications rely on. Mapping traffic flows first, rolling out in stages and starting in monitor-only mode where your equipment supports it reduce the risk of outages.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.