Skip to content

Home Expertise / Network security

NET / NET-02

Network segmentation and microsegmentation

Separate environments and restrict communication to what is necessary so that a compromised device or service does not gain broad access to information systems. Separation must be tested, not merely diagrammed.

WHEN IT HELPS

A focused response
to a defined need.

Infrastructure manager with a flat network, excessive supplier access, mixed test and production environments or sensitive data reachable from user devices.

AT A GLANCE

Family
Network security

Engagement
Implementation

Reference
NET-02

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Dependency mapping
  • user, server, administration and guest zones
  • east-west traffic
  • network or host filtering
  • pilot
  • exceptions
  • blocked-traffic monitoring

Deliverables

  • Target architecture
  • business-approved traffic matrix
  • deployed rules
  • exception register
  • positive and negative test cases
  • change procedures

Acceptance evidence

Agreed business workflows remain operational; prohibited communication fails; exceptions have an owner and expiry; new traffic requires approval.

DELIVERY

How the work is structured.

Approach

Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.

Prerequisites & responsibilities

Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.

Scope factors

Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.

Questions to clarify

Which systems must never communicate? Who knows application dependencies? Can traffic be observed before blocking?

IMPORTANT BOUNDARIES

A VLAN alone does not prove isolation. An overly aggressive policy can disrupt applications; observation, business testing and rollback are part of the project.

Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A services company shares one network between users and backups. Project: create a backup zone and restrict its management access. Target outcome: a standard workstation can no longer directly reach management interfaces.

Scenario 02

A software vendor wants to isolate customer environments. Project: map communication and apply service-level microsegmentation. Target outcome: cross-customer access tests are blocked; shared dependencies that cannot be isolated remain explicitly recorded.

Technology and reference context

Examples: Palo Alto Networks filtering, host firewalls, cloud security policies and Kubernetes NetworkPolicy, depending on the environment.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.