Back to glossary

Network segmentation

2 min read

In network security, network segmentation is the practice of dividing a network into separate zones so that a compromise in one does not spread freely to the rest. It is the control that decides how far an intruder moves after the first foothold, turning a single breached host into a contained event rather than a whole-estate one.

July 24, 2026
Compartir:

How it works

Segmentation splits a flat network into zones and controls the traffic between them. The classic form uses VLANs and firewall rules to separate, say, the user network from servers, and servers from the most sensitive systems, so that reaching one zone does not grant access to the next. Well-designed segmentation follows the value of what it protects: the more damage a system could cause, the fewer places should be able to reach it. Done at a coarse level it uses network zones; done at the workload level it becomes microsegmentation, which enforces policy per workload rather than per subnet. Both aim to make the network a series of controlled boundaries instead of one open space.

What goes wrong

The failure is a network that is segmented on the diagram and flat in practice. Rules are permissive, exceptions accumulated over years, and a management network reaches everything for convenience. On an internal test this is usually the difference between a contained finding and a full compromise: once we have one host, the question is how far we can move, and where segmentation is weak the answer is everywhere. Lateral movement is not clever when the network permits it. Industrial estates are a special case, where poor segmentation between corporate and OT and ICS networks is a recurring and high-consequence finding.

Where this shows up in an audit

We measure segmentation from the inside by attempting to move: from a starting position we map which zones we can actually reach and demonstrate the paths that should have been blocked. The finding is the reachable route, not the diagram, and it is written against the specific rule or missing boundary that allowed it. Segmentation is also the practical foundation of a zero trust architecture. This is part of how we measure lateral movement inside your network.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.