Skip to content
Cyber Risk Calculator

Network Segmentation for Business

One flat network means anything that reaches a laptop can reach a machine controller, a card terminal or a camera. Separating them is mostly configuration rather than new hardware, and it is what supplier questionnaires are actually asking about.

Request a quote

The question behind most customer security questionnaires

A great many businesses run one network. The office laptops, the guest Wi-Fi, the card terminals, the CCTV, and on a production site the machine controllers, all sit on the same flat space where anything can reach anything else. That arrangement is invisible while nothing goes wrong and is the reason an incident that starts with one phishing email ends up somewhere it should never have reached.

Segmentation separates them, so that traffic on one part cannot cross into another without passing a control. In practice this means guest Wi-Fi that cannot see your file server, production equipment that cannot be reached from the office network, and cameras and building systems on their own space rather than sharing yours. On most sites this is configuration on equipment you already have rather than a project requiring new hardware, which is why it is usually cheaper than people expect.

It has become the recurring question in supply chains. Aerospace, automotive, rail, defence, pharmaceutical and increasingly chemical customers all ask suppliers about it, and the questionnaires have moved a long way down to smaller firms. The value is being able to answer from what is actually configured rather than assembling a picture in the week before an assessment, which is where it becomes expensive and where the answers become approximate.

What gets separated from what

Guest from business

Visitors and customer Wi-Fi on their own space, unable to see anything of yours. The most common first step.

Production from office

Machine controllers and process systems unreachable from email and browsing. The one audits ask about first.

Payment from everything

Card terminals isolated, which is both sensible and frequently a condition of the arrangement you signed.

Building systems

Cameras, door entry and heating on their own segment rather than sharing the network with your accounts.

Access control

Who can reach what, reviewed rather than assumed. Shared passwords are what the questionnaire is really probing.

Documentation

A written picture of the above. Without it you cannot answer an audit from fact rather than from memory.

Who we work with

We are independent of any single network or vendor, so the recommendation follows the requirement.

Network & security

We build on the platform that fits the requirement rather than the one we happen to stock.

  • Cisco
  • FortinetFortinet
  • Palo AltoPalo Alto
  • UbiquitiUbiquiti
  • ForcepointForcepoint

Network and vendor names and logos are the trademarks of their respective owners, shown to describe the services SCG Solutions supplies.

When it stops being optional

  • A customer sends a supplier security questionnaire — increasingly the trigger, and increasingly for small firms
  • You take card payments on the same network your staff browse from
  • Production or process equipment shares a network with office traffic
  • You offer guest or contractor Wi-Fi from the same connection as the business
  • An insurer asks how your network is arranged before renewing cyber cover
  • You supply into aerospace, automotive, rail, defence, pharmaceutical or chemical, where it is now assumed

Network Segmentation for Business — Common Questions

Is segmentation expensive?

Usually far less than people expect, because on most sites it is configuration on equipment already in place rather than new hardware. Where a network has grown organically over years it can require some rework, which a survey establishes quickly. The expensive version is doing it under deadline because a customer has just asked.

Our customers have started sending security questionnaires. Is this what they mean?

It is a large part of it. The recurring questions are whether production and office networks are separated, whether there is a monitored firewall, and whether access is controlled and reviewed rather than shared. The value of having it in place is being able to answer from actual configuration rather than from what you believe is true.

We are small. Does this really apply to us?

Increasingly yes, because the questionnaires have moved a long way down supply chains and size is much less protection than it was. At a small scale it is genuinely configuration rather than significant expense. The disproportionate response is buying enterprise security tooling nobody has time to administer, and we would talk you out of that.

Does this stop us using guest Wi-Fi?

The opposite — it makes offering it sensible. Guest Wi-Fi on its own segment means visitors, contractors or customers can have a connection without being able to see anything of yours, and without a busy evening of streaming affecting your booking system or card terminals. Offering guest access from a flat network is the arrangement worth changing.

Will it disrupt production to set up?

It is planned around production rather than imposed on it, and on most sites the work happens in stages rather than as one cutover. Where equipment is genuinely fragile or a line cannot stop, that shapes the sequence — which is a reason to survey first and to be honest about what is not worth doing on a particular site.

Do we need this if we already have a firewall?

A firewall controls traffic in and out; segmentation controls traffic once it is inside. A business with a good perimeter firewall and a flat internal network is still one compromised laptop away from everything else on that network. The two do different jobs and the internal one is the half more often missing.

More IT & Cloud Services

See all services and solutions

Not sure how your network is actually arranged?

Most businesses are not, and finding out is a survey rather than a commitment. We will map what can currently reach what, tell you which separations are worth making, and be straight about the ones that are not worth the disruption on your site.

What do you need?

It's easy to talk to us