Network Segmentation

« Back to Glossary Index

Theme: A boundary exists only when flows and failure paths are controlled

Quick definition

Network segmentation divides an environment into zones and controls communication between them through defined conduits or traffic paths. It aims to limit attacks, faults and unnecessary dependencies. A VLAN configuration separates logical broadcast domains, but is not by itself a verified security boundary.

In context: from drawn zone to real boundary

A zone groups assets with comparable function and risk. The boundary becomes effective when a firewall, gateway or other control enforces documented flows. Identities, administration paths and wireless or temporary connections must be included; otherwise the drawn boundary can be bypassed.

A concrete building scenario

Ventilation, access control and the office network occupy separate zones. Energy data may move from ventilation to an integration zone, while only a management server may initiate approved administration sessions back. If the firewall or integration zone fails, local ventilation follows tested fallback behaviour.

Allowlists and identity

Rules should identify source, destination, direction, protocol, port, purpose and owner. Where equipment supports it, allowlists can restrict communication to known needs. A network address is not authentication: users, services and devices need suitable identities and least privilege.

Monitoring and change

Logs and passive network monitoring can reveal rejected flows, new devices and unexpected protocols. The baseline must connect to change management so approved maintenance is not mistaken for an unknown intrusion, and so temporary exceptions are actually removed.

Opportunities and costs

Segmentation can limit propagation, clarify accountability and protect time-sensitive traffic. More boundaries also mean rules, testing, documentation and troubleshooting. Excessively fine segmentation without support capability produces unofficial openings; excessively broad zones provide weak protection.

HubMind’s view

Specify segmentation as permitted information flows and tested failure paths, not a VLAN count. Start with physical consequence and ownership, group assets, and document minimum necessary flows. Verify both blocked traffic and critical operation when a conduit is unavailable.

A practical next step

Choose two zones and export their actual firewall and switch rules. Match every opening to a documented need and owner. Remove one unused rule in a controlled setting, simulate communications loss, and check alarms, local autonomy and return to normal operation.

Related concepts

VLAN, Cybersecurity (OT), IEC 62443, OT.

Sources and further reading

Scope and freshness

General OT segmentation under final NIST SP 800-82 Rev. 3, September 2023. Zones and conduits are architectural concepts; no universal topology is prescribed. Reviewed 31 August 2026.

« Back to Glossary Index
Contact us