Back to blog
NetworkIT InfrastructureSME

Network segmentation: why a flat network is a risk

NDVDL Team7 min read
Network cables organised into separate segments at a switch

A flat network becomes a risk because a single compromised computer, or a single insecure device, can move around the entire network unhindered – from the camera at the entrance to the server holding your customer data. Network segmentation splits a network into several logically isolated zones, so that an incident in one segment doesn't automatically become an incident across the whole business. For many SMEs it's the single most effective step for shrinking the attack surface of their own IT infrastructure – and, at the same time, one of the most commonly skipped.

What a flat network actually means

A network is flat when every device sits in the same network segment and can communicate with every other device without restriction: the office PC, the printer, the production line, the IP camera in the car park, and a guest's laptop on the Wi-Fi. This rarely happens on purpose – a network usually grows over the years, new devices get plugged into whichever switch port is free, and at no point does anyone consciously decide to run everything in a single segment. Day to day, it works fine – right up until that missing step becomes the problem.

Why a flat network becomes a risk

The core problem with a flat network isn't that it looks less secure – it's that a single weak point is enough to reach the entire network. A poorly secured IP camera with a default password, an infected USB stick plugged into a guest laptop, an outdated IoT device on the production line: these are all common entry points that, on their own, often look harmless. On a flat network, though, an attacker can move on from there unhindered towards servers, file shares or accounting, because there's no boundary in the way.

  • A compromised device on a flat network can reach every other device on the same network
  • IoT devices and cameras are often less well secured than standard IT and are a popular entry point
  • Guest Wi-Fi sharing a network with internal systems opens up an unnecessary additional attack surface
  • Production equipment is often particularly hard to patch and should therefore be particularly isolated

What VLANs actually solve

VLANs (Virtual Local Area Networks) logically split a physical network into several separate segments without needing separate cabling or switches. Traffic between segments passes through a firewall or a layer-3 device that specifically defines which communication is even allowed between which segments. A device on the camera segment can, for example, talk to the video recorder but not to the server in accounting – even if both are plugged into the same physical switch. This separation can be introduced step by step and doesn't have to happen for the entire network all at once.

What technology it takes

Clean segmentation usually doesn't require a complete overhaul of your network hardware, but it does need a few basics: managed switches that support VLANs, rather than plain unmanaged switches, plus a firewall or router that can enforce rules between segments. Many SME networks already run on equipment that could, in principle, do this but simply hasn't been configured for it – in that case segmentation is mainly a configuration and planning effort, not a pure hardware project. Only when the existing equipment doesn't support VLANs at all does replacing individual components actually become necessary.

How to segment a network sensibly

A sensible basic structure follows functional areas, not physical locations: production, office IT, guest Wi-Fi, and cameras/building systems are four areas that, for practical reasons alone, have different requirements for security and reachability in most businesses.

  • Production network: its own segment, usually with especially restrictive rules, since equipment is often hard to patch
  • Office IT: workstations, servers, printers – with differentiated rules depending on how sensitive each system is
  • Guest Wi-Fi: fully isolated, internet access only, no access to internal systems
  • Cameras and building systems: their own segment, usually reachable only by the matching recorder and a limited management interface

Practical implementation: how a segmentation project runs

Segmentation can't be done in an afternoon once a network has already grown organically – but it can be introduced in a structured, step-by-step way without putting ongoing operations at risk.

  1. 01Stocktake: which devices exist, where they're plugged in, and who talks to whom
  2. 02Define target segments based on functional areas rather than physical locations
  3. 03Define firewall rules between segments, starting from a restrictive baseline
  4. 04Move devices into their target segments step by step, testing communication at each stage
  5. 05Fine-tune the rules once it becomes clear which connections are actually needed

After segmentation: what stays part of the job

Segmentation isn't a one-off project that ends once the firewall rules are in place. Networks change – new devices get added, new applications need new connections between segments, and without a regular rhythm of upkeep, the same lack of clarity that was cleared out at the start grows right back over time.

  • Assign new devices to the correct segment from the start, rather than plugging them into whichever network is closest
  • Review firewall rules regularly and remove exceptions that are no longer needed
  • Keep the segment plan and IP assignment documented and up to date, so a new person can also find their way around
  • Spot-check communication between segments to confirm it still matches the original rule set

What it costs to skip it

The effort of segmentation is often weighed against the perceived effort of leaving things as they are. What gets overlooked is that a flat network only shows its true cost when it actually matters – when a single incident doesn't stay contained to one segment but spreads through the whole business, hitting production, office IT and the camera system all at once. That cost then doesn't arrive on a planned schedule but under time pressure – and is usually considerably higher than segmenting the network up front would have been.

Want to split your existing network into sensible segments, or set up a new infrastructure cleanly separated from the start? We plan and implement the segmentation – from the stocktake through to the finished firewall rules.

Get in touch

You'd rather not work this out yourself? The solution page explains how we plan, build and then run it.

See IT security

Questions about your IT infrastructure?

Talk directly to our team — no obligation, no detours.