Network Segmentation Defense
Compare flat, VLAN-only, firewall, and microsegmented IoT designs to see how lateral movement is contained
Network Segmentation Defense
Compare flat, VLAN-only, policy-enforced, and microsegmented designs. Watch where a compromised IoT device can move, which boundary stops it, and why VLAN labels alone are not a security policy.
Network Segmentation Workbench
One weak IoT node can see the whole flat network
Start with a smart-building deployment where a camera shares reachability with workstations, a gateway, and a building management server.
Attack path, trust zones, and boundary decision
The active stage highlights whether the next move is allowed, routed by default, or blocked by policy.
Segmentation score
Current finding
A flat network gives the attacker direct paths to every device that accepts traffic from the compromised node.
risk = exposure + weak policy + blast radius - detectionArchitecture behavior
Flat reachability makes the VLAN or zone boundary invisible because there is no enforced boundary.
Accuracy warning
Segmentation is not just drawing boxes. The security benefit comes from enforced routing, firewall, ACL, identity, and monitoring decisions.
Segmentation Controls
Select a deployment, compare architectures, and choose a view. The diagram, metrics, boundary decision, and teaching note update together.
Network Segmentation Quick Reference
A VLAN separates layer-2 broadcast domains. It helps organize traffic, but routed paths still need security policy.
The boundary becomes protective when rules explicitly allow required flows and deny unnecessary cross-zone access.
Measure how far a compromise can spread from the first weak device before a rule, identity check, or alert stops it.
Logs and detection prove whether the intended boundary is actually being used, bypassed, or misconfigured.
Technical Accuracy Notes
NIST SP 800-82 Rev. 3 discusses OT security architectures, common threats, vulnerabilities, and countermeasures for systems that interact with the physical environment.
NIST SP 800-41 Rev. 1 frames firewalls and firewall policy as rule-based control points between networks, not merely labels on diagrams.
NIST SP 800-207 describes zero trust as continuous, policy-driven access decisions that can complement segmentation.
The score is a teaching heuristic. Real designs also need asset inventory, routing review, rule review, traffic capture, change control, and testing.
Common Misreads
A VLAN can be useful structure, but security depends on what traffic is allowed between VLANs.
Rules drift, exceptions accumulate, and device roles change. Review, logging, and ownership matter.
Industrial and clinical systems may have safety and availability constraints. Segment around required safe operation.
Detection helps response, but it does not reduce reachability unless paired with control decisions and action.
Practice Prompts
Switch from Flat network to Policy firewall. Which route disappears first, and what business flow remains allowed?
Select VLANs only. Why does the PLC still become reachable if inter-VLAN routing is broadly allowed?
Use Microsegment + monitor. Which asset stays protected, and what residual risk still needs process controls?
Use the Policy matrix lens. Write one allow rule and one deny rule that explain the outcome.