// Network security · for Düsseldorf & the Rhine-Ruhr region
Network security for company networks
In many companies every device can reach every other one. We cut the network into zones, govern what crosses between them and make visible who is actually talking to whom.
// Starting point
Networks that grew are almost always flat
Company networks are rarely drawn up on paper. They grow: another floor joins, a warehouse gets connected, production gets its own outlets, and at some point everything hangs off the same switches. Day to day that works well — and it is exactly why one machine is enough to keep going from.
Because in a flat network nobody checks sideways movement. Whoever took over the office PC in accounts can see the file store from there, the line-of-business application, the printer in dispatch and often the controller that has been running untouched for years.
Segmentation turns that around. Each area gets a room of its own, and between the rooms only what is explicitly permitted applies. It costs planning once and permanently takes the reach out of any later incident.
// Side by side
One room, or several?
The difference does not show in normal operation. It shows the moment a device stops taking instructions from you.
Everything sees everything
- A compromised laptop reaches servers, tills and controllers alike
- Visitor and maintenance devices sit in the same network as accounts
- Sideways traffic is logged nowhere and therefore never stands out
- A single weak point decides how far an intruder gets
Damage stays in the room
- An infected device only reaches what its zone is cleared for
- Visitors, contractors and production each have their own area
- Traffic between zones passes one point that keeps a record
- Odd behavior is recognizable because a baseline exists
// Where to cut
The zones nearly every company needs
-
Workplaces
Desktops and laptops used by staff. They may reach the applications they work with — not the management interface of the switches.
-
Servers and business applications
The area where the data lives. Access only through the services genuinely in use, and not by a share opened on request.
-
Visitors and contractors
Guests, service engineers and devices people bring with them get a route to the internet and no view inwards.
-
Plant and production
Controllers, building services, cameras and printers. Kit that cannot be patched needs narrow rules rather than optimism.
// Rebuild
Segmenting without stopping the business
The most common mistake is writing rules before anyone knows the real traffic. We reverse that order.
Who talks to whom?
Before anything is blocked we record the traffic as it actually is. Almost every time a connection turns up that nobody remembered existed.
Design the zones
From that real picture comes a zone plan with defined crossings. It follows how you work, not how many switch ports happen to be free.
Let the rules bite
Crossings move into blocking mode area by area, in an announced window and with a way back if an application objects.
Report the outliers
After that the baseline is known. Anything that does not fit it — new destinations, unusual volumes, access at odd hours — triggers an alert.
// Questions about network security
What technical leads settle first
01 What does segmentation add when we already run a firewall?
The firewall sits at the edge, facing outwards. Segmentation works on the inside: it decides whether a compromised office machine can also reach your line-of-business application, the till system or the machine controller. Without zones everything shares one room, just behind a better front door.
02 What is east-west traffic?
Traffic between devices within the same network — sideways rather than out to the internet. Classic setups barely inspect it, and that is precisely where an intruder moves on after the first foothold. Zones, and rules between them, make that movement visible and keep it short.
03 Will our staff notice the rebuild?
If we do it properly, barely. Zones exist as a design first and are wired up while traffic still passes freely. Only once we can see who really talks to whom do the rules start blocking — otherwise you shut down dispatch on a Friday afternoon.
04 Do we need a separate network for visitors and contractors?
Yes, for both. A visitor laptop, a maintenance engineer and a service provider’s till system have no business sitting in the company network. They get an area of their own with a route to the internet and no view of internal servers.
05 How do you spot unusual activity in the network?
Switches, access points and gateways report who is talking to whom. From the usual picture we build a baseline, and departures from it raise an alert — an office PC suddenly probing server services, say, or volumes of data moving at hours when nobody is in.
06 Does this apply to production and building services too?
Especially there. Controllers, lifts, access systems and climate technology often run unchanged for years because an update would mean a shutdown. Devices like that are hard to harden, so instead they get their own zone with very narrow rules around it.
Related
Cybersecurity overview
Can a visitor laptop reach your file server?
Plenty of networks answer that with yes, without anybody having decided it. We look at how yours is built and show where a separation buys you the most.