The problem with flat networks
In a flat network, every device can reach every other device. Once an attacker compromises one laptop, through phishing for example, they can move laterally to servers, backups and administrator workstations. Most serious ransomware incidents depend on this freedom of movement.
How it is done
Common zones separate user devices, servers, management interfaces, backups, guest WiFi, printers and IoT devices, and production from development. Traffic between zones passes through a firewall with rules that allow only what is needed. VLANs are the usual building block. Microsegmentation goes further, controlling traffic between individual workloads, especially in data centres and the cloud.
Where to start
Map which systems need to talk to each other, isolate the most critical assets and the backup infrastructure first, block administration protocols such as RDP and SMB between user devices, and keep industrial or operational technology separate from the office network. Segmentation is also one of the pillars of Zero Trust.
Where it shows up in compliance
ISO 27001 requires segregation of networks (Annex A 8.22). The ENS includes network segregation measures, and in PCI DSS segmentation is the main way to reduce the scope of an assessment.




