In most offices the network looks like this: one router, and everything — from the director's laptop to a $25 IP camera — sits on the same shared network. Every device can see every other device. Convenient? Yes. Safe? Not at all.

What can actually go wrong

An attacker doesn't need to break into your best-protected computer — the weakest device is enough. An old camera, a smart TV in the meeting room, a printer running five-year-old firmware. Once inside it, the attacker is on the same network as your accounting, servers and customer database — and moves on from within.

Segmentation in plain words

Segmentation splits one big network into isolated zones: office computers in one, servers in another, cameras and smart devices in a third, guest Wi-Fi in its own. Zones cannot see each other except where you explicitly allow it. A camera can no longer "talk" to accounting — even if it gets compromised.

Guest Wi-Fi — the simplest example

When a guest or contractor joins your Wi-Fi, they should see nothing but the internet. If you still have one password "for everyone", every visitor potentially has access to internal resources. A separate guest zone closes this in a single evening of work.

Is it expensive?

No. Segmentation is first of all configuration, not new hardware: most switches and routers, even inexpensive ones, support it. For a typical office it is days of an engineer's work, not a new equipment budget. If your hardware truly can't do it, we'll say so honestly and pick gear for the task, not for a vendor.

When segmentation is not enough

Segmentation answers "who can see whom". The next level is "who can connect at all" — that's 802.1X, an access-pass system for devices we covered in a separate article. Together they close most "stranger on the network" scenarios.

Want to know how "flat" your network is and what a single camera can reach? Get in touch — we'll audit it and show the risks, no strings attached.