Network segmentation divides a network into smaller pieces. Each piece has its own access rules. A compromised laptop in the marketing VLAN cannot reach the payroll database directly. It has to cross a boundary, and that boundary has controls. Segmentation limits how far an attacker can move once inside. Without it, one compromised machine often means access to everything.
The 2013 Target breach is a textbook example. Attackers stole credentials from an HVAC vendor and used them to enter Target's network. From there, they moved laterally to point-of-sale systems and stole 40 million card numbers. Segmentation would not have stopped the initial entry, but it could have contained it. The vendor's access should have been limited to the HVAC management network. The POS systems should have been isolated from everything else. The attackers crossed boundaries that should not have existed.
Segmentation approaches
- VLANs — logical separation within a physical network
- Firewalls — enforce rules between segments
- Microsegmentation — fine-grained controls around individual workloads
- Air gaps — physical separation for the most sensitive systems
Segmentation is not a one-time project. Networks grow. New applications and devices create new paths. Review the rules regularly. A segmentation plan that nobody maintains becomes a diagram of what the network looked like three years ago.
Comments
No comments yet. Be the first to share a thought.
Leave a comment