Network segmentation divides a network into separated zones between which only explicitly permitted traffic flows. An infection then stays confined to one zone instead of spreading across the whole network.
At a glance
Segmentation limits the damage, not the access.
Cut zones by protection need, not by department.
Without logging at the crossings, half the benefit is missing.
Segmentation does not change whether someone gets in – it changes how far they get.
Zones and crossings
Zones are cut by protection need, not by the org chart. Between them sits a control point that passes only permitted connections and logs them. The craft is in the cut: too coarse achieves nothing, too fine becomes unworkable.
Real-world examples
- An infection in the office zone never reaches the production plant, because only two protocols are permitted between them.
- Administrative access runs exclusively through a zone of its own with its own sign-in.
Common misconception
Myth “We have a VLAN, so the network is segmented.”
Reality A VLAN separates broadcast domains. Without enforced rules between zones it is not a security boundary.
Frequently asked questions
How finely should you segment?
Finely enough that an infection stays contained, coarsely enough that operations can live with it. NIST SP 800-125B sets out an approach.
Does segmentation replace zero trust?
No, it is a building block of it. NIST SP 800-207 places both in context.