Summary: A flat network makes it easy for systems to communicate – but also for a problem or an attack to spread. Network segmentation means dividing the environment into zones and controlling the communication between them. Done properly, segmentation can reduce risk and limit the consequences of both cyberattacks and technical failures.
A typical business network can contain far more than the users’ computers:
- servers
- printers
- Wi-Fi
- cameras
- IoT
- backup
- administration interfaces
- guest networks
- building management systems
- cloud connections
- supplier access
The question is: does all of this really need to talk freely to everything else? The answer is usually no.
What is network segmentation?
The basic idea is simple. The network is divided into different areas and the traffic between them is controlled.
The Swedish National Cyber Security Centre (NCSC) explicitly recommends that organisations segment their networks and create controlled traffic flows between the segments. The purpose is, among other things, to reduce the risk of intrusion, the spread of malware and unauthorised access. Segmentation should take into account the function of the information systems and the value of the information they handle.
Why is a flat network a problem?
Imagine an attacker manages to compromise an ordinary user workstation. That does not have to mean the organisation’s most important systems are lost. But if the client has network access to servers, backup, administration interfaces and other clients, it becomes considerably easier for the attacker to try to move further.
The same principle applies to technical failures. A misconfigured system, an infected IoT device or another disruption can spread more widely if the environment lacks clear boundaries. Segmentation is therefore largely about limiting consequences.
VLANs are a tool – not the whole security model
VLANs are often used for logical separation. They are a good tool. But if all traffic is allowed to flow freely between the VLANs, the organisation has mainly achieved an administrative separation.
The real security effect comes when the traffic between zones is controlled and filtered. The NCSC describes precisely this combination of physical or logical separation and controlled traffic flows with filtering functions. Depending on the architecture, that may mean firewall rules, access control lists (ACLs) or other controls.
Which segments are needed?
There is no universal model. But the organisation can start by asking which types of systems have different functions and risks. Examples of segments:
- user clients
- servers
- administration environment
- backup
- guest Wi-Fi
- IoT and building technology
- printers
- OT or production environment
- DMZ and published services
- network equipment and management
Not every organisation needs all of these segments. The point is to think about which resources do not need direct communication with each other.
The guest network is the easy example
Most people would react if a visitor’s private laptop on the office Wi-Fi had free access to internal servers. There, the separation is obvious. The same way of thinking can be applied internally:
- Does the printer need to initiate traffic to the domain controller?
- Does a camera need to reach the finance system?
- Does an ordinary user workstation need to connect to the backup server’s administration interface?
The network design often becomes clearer when the question is framed that way.
Segmentation and identity complement each other
Modern security relies less and less on the idea that everything on the inside is trusted. Identity, device health and application controls play a major role. But that does not mean the network has become irrelevant.
Identity governance can control who is allowed to log in. Segmentation can at the same time limit where systems are able to communicate at all. That gives several layers of security.
Supplier access needs particular thought
External suppliers sometimes need access to systems for support, maintenance, operations and troubleshooting. The problem arises when the supplier is given a general VPN connection into the entire environment.
A better model can be to restrict access to the right system, the right port, the right time and the right identity. That reduces the consequences if the supplier’s account or environment is compromised.
How do you start segmenting an existing network?
The dangerous approach is to start creating VLANs without first understanding the traffic. A more controlled approach is:
- Map the environment. Which devices, systems and networks exist?
- Identify dependencies. Which systems must communicate with each other?
- Assess criticality. Which systems and information assets need the strongest protection?
- Design zones. Group systems with similar function and protection needs.
- Define permitted flows. Which communication is actually needed?
- Implement in stages. Start with clear and relatively simple boundaries.
- Monitor. Capture blocked traffic and verify that legitimate flows work.
Segmentation in an existing environment often needs to be done carefully. Otherwise undocumented dependencies are discovered only when something suddenly stops working.
Common mistakes
- Too many segments from the start. An extremely detailed design can become hard to maintain.
- VLANs without traffic control. The separation looks good on the diagram but has little security effect.
- No documentation. After a few years nobody knows why a firewall rule exists.
- Any-any as a temporary fix. Temporary exceptions have a tendency to become permanent.
- Backup in the same security zone. If the attacker who takes the production environment can also easily reach the backup, an important layer of protection disappears.
Segmentation needs to be maintained
The organisation changes. New systems are added, old ones are retired and integrations change. Network rules therefore also need to be followed up. Otherwise a new kind of technical debt builds up: hundreds of rules nobody dares to remove any more.
How Kristensson i Skåne can help
Kristensson i Skåne works with both network services and cybersecurity and technical security. We can help organisations with:
- current-state mapping
- network design
- segmentation model
- firewalls and VPN
- Wi-Fi
- supplier access
- documentation
- monitoring
- migration and implementation
That allows segmentation to be based on both the technical reality and the business’s actual risks. An example of how we work with networks in practice can be found among our reference cases, where we deliver managed IT services to a municipal infrastructure provider.
Frequently asked questions
Are VLANs the same as network segmentation?
VLANs are a common tool for logical segmentation, but the traffic between segments also needs to be controlled and filtered to deliver a real security effect.
Do small businesses need segmentation?
The need is driven more by environment and risk than by headcount. Even a smaller business may have guests, IoT, servers and critical systems that should be separated.
Can segmentation be introduced without rebuilding the whole network?
Often yes. A staged introduction, starting with clear and relatively simple boundaries, is usually more practical than a complete rebuild.
Is segmentation only relevant against cyberattacks?
No. It can also limit the consequences of failures, misconfigurations and other disruptions in the environment.
Want to know how your network would hold up against a problem that spreads? Read more about our network services for businesses or contact us for an informal conversation.
Sources: Swedish National Cyber Security Centre (NCSC), 10 recommended security measures, measure 7 – Segment and control access in the network.
This text is general information. The right segmentation model always depends on the individual environment and the business’s risks.

