GlossaryAttack surface and pentesting

Network segmentation

Short answer

Network segmentation divides a network into separate zones with controlled traffic between them, so that a compromise in one area cannot spread freely to the rest. It limits the damage of an attack and protects critical systems and data.

The problem with flat networks

In a flat network, every device can reach every other device. Once an attacker compromises one laptop, through phishing for example, they can move laterally to servers, backups and administrator workstations. Most serious ransomware incidents depend on this freedom of movement.

How it is done

Common zones separate user devices, servers, management interfaces, backups, guest WiFi, printers and IoT devices, and production from development. Traffic between zones passes through a firewall with rules that allow only what is needed. VLANs are the usual building block. Microsegmentation goes further, controlling traffic between individual workloads, especially in data centres and the cloud.

Where to start

Map which systems need to talk to each other, isolate the most critical assets and the backup infrastructure first, block administration protocols such as RDP and SMB between user devices, and keep industrial or operational technology separate from the office network. Segmentation is also one of the pillars of Zero Trust.

Where it shows up in compliance

ISO 27001 requires segregation of networks (Annex A 8.22). The ENS includes network segregation measures, and in PCI DSS segmentation is the main way to reduce the scope of an assessment.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub