Glossary
Network Segmentation
Instead of one big network, you have many small ones. If attackers get into accounting, they can't reach engineering. Like having locked doors between departments instead of one open floor plan.
What is Network Segmentation?
Dividing a network into smaller, isolated segments to limit lateral movement and contain breaches.
Why Should You Care?
Network segmentation directly reduces breach severity by preventing attackers from freely pivoting to critical assets once they gain initial access. Organizations with segmented networks contain incidents faster and at lower cost because lateral movement is blocked by design rather than detected after the fact. Security teams can enforce granular access controls per segment and detect unauthorized movement attempts immediately, transforming breach response from reactive damage control to automated containment.
Is your business exposed?
Real-World Example
The 2013 Target breach exploited the absence of strong network segmentation—attackers entered through a third-party HVAC vendor's connection and were able to move toward the payment card environment because internal systems were insufficiently isolated. Had the payment processing segment been strictly separated with tight firewall rules, the intrusion could have been contained to the vendor access zone, preventing the theft of roughly 40 million card numbers.
How to Protect Against Network Segmentation
- 1.
Segment critical systems from general network
- 2.
Implement micro-segmentation for sensitive data
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required