Offer · IT Services & Advisory

Network and segmentation review

Get a clear picture of how the network is actually built — and whether a fault or an intrusion can spread further than it should.

ReviewSegmentationFirewall and VPNTarget architectureAction plan

Who it is for and when

Many networks have grown over a long time. A new switch. An extra VLAN. A firewall rule for a supplier. New access points. Cameras. IoT. VPN. Eventually the environment works — but nobody is quite sure why certain traffic flows are open or which systems can actually reach one another.

The network and segmentation review gives a technical picture of the current state and a concrete plan for making the network simpler, safer and more controlled.

NCSC recommends that networks are divided according to the function and sensitivity of the systems, and that traffic between segments is limited to what is actually needed. Administration should moreover be carried out from specially protected segments.

The offer suits situations such as when:

  • the network has grown over several years,
  • the documentation no longer matches reality,
  • users, servers and IoT sit too close together,
  • firewall rules have been added without regular review,
  • the organisation has new security or customer requirements,
  • NIS2 or other risk management is driving technical improvements,
  • suppliers have VPN or remote access,
  • new production, OT or IoT environments are being introduced,
  • network equipment is to be replaced,
  • an intrusion or incident has exposed weaknesses.

What we do

  1. Source material and interviews. We go through the network design, the equipment and the existing documentation.
  2. Technical verification. Configuration and the relevant technical conditions are reviewed under the agreed access.
  3. Analysis and target design. We identify the risks and produce a sensible segmentation model.
  4. Walkthrough and roadmap. The result is presented and the activities are prioritised.

What is included

Mapping the current state

We go through the existing environment and the relevant documentation. That can cover:

  • WAN and internet connections,
  • the firewall,
  • switches,
  • the wireless network,
  • VLANs,
  • routing,
  • VPN,
  • remote access,
  • network management,
  • central servers and services.

The segmentation model

We analyse whether the network has appropriate security zones. For example user clients, servers, administration, backup, guest network, IoT, cameras and building systems, production and OT, DMZ, and network management.

Not every organisation needs every segment. The goal is not the most VLANs. The goal is the right boundaries between systems with different functions and different risk.

Traffic flows and the firewall

We review how traffic is permitted between areas. The questions can be, for example:

  • do clients need to talk directly to each other?
  • can ordinary user machines reach administration interfaces?
  • does IoT need to reach internal servers?
  • which ports actually need to be open?
  • are there broad any-any rules?
  • are there old rules with no clear owner?
  • are inbound and outbound traffic sufficiently controlled?

NCSC recommends that only necessary traffic is permitted and that firewall rules and traffic flows are documented and reviewed regularly.

Administrative access

Administration interfaces should not be as reachable as ordinary user services. We therefore look at:

  • the management network,
  • privileged access,
  • VPN,
  • remote administration,
  • supplier access,
  • authentication.

Guests, BYOD and IoT

Private or less trusted devices normally need keeping apart from sensitive internal environments. NCSC recommends that private devices are only permitted in separate parts of the network and that unauthorised equipment is identified and blocked.

Equipment and lifecycle

We also identify obvious risks tied to, for example:

  • end-of-life,
  • older firmware,
  • unknown network devices,
  • insufficient redundancy,
  • single points of failure.

Monitoring and logging

We assess at a high level whether the network yields enough information for troubleshooting, capacity follow-up, security monitoring and incident handling.

What you get

After the engagement you normally have:

  • a documented picture of the current state,
  • a network and zone diagram at the agreed level,
  • identified security risks,
  • an assessment of the segmentation,
  • identified redundant or risky traffic flows,
  • a recommended target design,
  • a prioritised action plan,
  • proposals for quick improvements and for longer-term changes.

The report distinguishes between critical risks, important improvements, and what can be planned for later.

Scope and price

This is an architecture and configuration review. It is not automatically a penetration test or an active attack against the environment. If the organisation also wants vulnerabilities verified through active testing, it can be combined with our separate offer for vulnerability assessment and penetration testing.

The price varies with the size of the environment and the number of sites included. You get an estimated cost proposal and, where possible, a fixed price.

Can Kristensson also carry out the changes?

Yes. Kristensson i Skåne AB already works with the design, implementation and management of corporate networks, including firewall, VPN, segmentation, Wi-Fi and monitoring.

The review can therefore be followed by a separate implementation project if you want.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

Does the network have to be rebuilt after a review?

Not necessarily. There are usually both smaller improvements and larger architectural questions. The measures are prioritised so that you can decide what is done and when.

Is a VLAN the same thing as secure segmentation?

Not in itself. A VLAN gives logical separation, but the security effect depends among other things on how the traffic between segments is actually controlled.

Can you review several offices?

Yes. The scope is adapted to the environment.

Can you review Wi-Fi and VPN too?

Yes, if they are included in the scope.

Reviewed by Kristensson i Skåne AB. .

Sources: NCSC: segment and control access in the network · CIS Controls

Do you know which systems can actually talk to each other?

Contact us