Start a project
Blog

Network segmentation for a business with no security team

Most small and mid-sized businesses run a flat network. Every device can reach every other device, because that is what happens when a network grows by addition rather than by design. It works fine until one laptop is compromised, at which point the attacker inherits the same unrestricted access.

Segmentation is the control that turns a compromised laptop into a contained incident. It does not require enterprise tooling or a dedicated security team.

Start by mapping what genuinely needs to talk

Before drawing zones, find out what actually communicates. This is almost always smaller than people assume. The accounting workstation does not need to reach the kitchen display. The guest wifi does not need to reach anything internal at all. The CCTV recorder needs the cameras and nothing else.

Segmentation designed without this map either breaks the business or is quietly bypassed by staff who need to work, and a bypassed control is worse than none because it is believed in.

Zones by blast radius

Group by what you can afford to lose together. A workable starting split for most businesses: guest wifi fully isolated, staff workstations, servers and business systems, and unmanaged devices such as cameras, printers and point-of-sale terminals.

That last group deserves particular attention. Devices that cannot be patched or monitored should be assumed compromisable, and placed where that assumption is survivable. A camera recorder running firmware from years ago should not be able to reach your file server.

Default deny, then open what the map showed

Firewall rules between zones start from deny everything, then permit exactly the flows the mapping exercise identified. The order matters: starting from allow and blocking what looks dangerous means the rules only cover the threats you thought of.

Write the rules with comments explaining why each exists. In two years someone will find a rule nobody can justify, and an undocumented rule is either deleted at random or kept forever out of fear.

Remote access is where flat networks come back

A VPN that drops a remote worker into the full internal network undoes the segmentation you just built. Remote access should land in a zone with the same restrictions as being in the office, or tighter, and it should be logged.

This is the practical core of zero-trust, without the marketing: location does not confer trust. Being on the office wifi should not grant more access than being at home, because an attacker who compromises one laptop is, technically, on the office wifi.

Test it by trying to move

Design review is not verification. Once the segmentation is in place, attempt lateral movement yourself: from a workstation, try to reach the server zone. From guest wifi, try to reach anything. From the camera network, try to reach the internet on unexpected ports.

Rules that look right frequently are not, usually because of an overlooked route, a permissive rule higher in the list, or a device with two interfaces bridging zones. Finding this yourself is much cheaper than the alternative.

Staged, not big bang

Nobody should cut over a live network in one evening. Introduce zones incrementally, starting with the easy and high-value separations: guest wifi first, since it is isolated by definition and breaks nothing, then unmanaged devices, then the split between workstations and servers.

Each stage gets a rollback point. This takes longer and it does not take the business offline, which matters more. We approach network design work this way, and the first deliverable is always the map, because everything after it depends on being right about what actually talks to what.

All articles
Start here

Tell us what you need.

One paragraph is enough. You'll get a straight answer on whether it's a fit, roughly what it takes, and what happens next.

Reply within one business day NDA on request Fixed-price quotes, no hourly billing
Company
NeedBridge LLC
Registered
United States
Studio
Morocco