Network segmentation for companies that think they are too small for it
Most small networks are flat. Everything plugs in, everything can see everything, and it works — until something on it is hostile.
What a flat network gives an attacker
A single compromised machine can scan the entire address range, reach every open service on every device, and move sideways until it finds something worth encrypting. The laptop that opened the wrong attachment is rarely the target. It is the doorway.
Segmentation does not prevent that first compromise. It limits what the first compromise is worth.
A segmentation plan that fits a small company
You do not need a data centre design. Four or five segments cover most businesses:
- Staff devices — laptops and workstations
- Servers — reachable only on the specific ports that are actually needed
- Guests — internet access and nothing else, fully isolated
- Devices — printers, cameras, door access, building systems
- Management — switch and firewall administration, reachable from a short list of addresses
That last one matters more than it sounds. Network equipment administration reachable from any desk is an open invitation.
Why the devices segment is not optional
Cameras, printers and building controllers are the least maintained equipment in any building. They ship with default credentials, receive firmware updates rarely, and often run software nobody has looked at in years. They belong nowhere near your file server.
Doing it without an outage
Segmentation is disruptive if done in one weekend and undramatic if done in stages:
- Document what currently talks to what
- Split off guests first — nothing depends on it
- Move devices next, one class at a time
- Separate servers last, with rules written from the documentation in step one
The hardest part is never the configuration. It is discovering the undocumented dependency in week three.
We plan and implement segmentation as part of cybersecurity work.
