Definition · Open Ports & Services

What is Network Segmentation?

Network segmentation splits a network into separate zones and controls what may pass between them. It is implemented with VLANs, subnets, firewall and access-control policy, cloud security groups, or — in more granular microsegmentation approaches — per-workload policy that does not depend on network location. The goal is containment: an attacker who lands in one zone should not automatically be able to reach the rest.

What good segmentation separates

Common boundaries are a public-facing tier from internal systems, production from development and test, corporate IT from operational technology, and any cardholder or sensitive data environment from everything else. Management interfaces belong in their own restricted zone rather than alongside the systems they administer.

Segmentation is only real if it is enforced and tested. A firewall rule set that permits any-to-any between zones, or a flat network with VLANs that route freely, provides the diagram without the control — which is why PCI DSS requires segmentation to be validated when it is relied on to reduce scope.

Why it shows up in external scanning

Segmentation failures are visible from the outside. A service intended for internal use that answers from the internet — SMB, RDP, a database port, a hypervisor or switch management interface — is usually a segmentation or firewall gap rather than a deliberate decision. So is a development environment on a public subdomain sharing infrastructure with production.

The other direction matters too: segmentation limits what an exploited public-facing application can reach next, which is why it is the control that turns a single web compromise into a contained incident rather than an estate-wide one.

Segmentation contains movement; attack surface reduction removes exposure; least privilege limits what credentials reach. Together they are the containment layers of defence in depth. A VPN gateway is often the controlled crossing point between zones, and therefore a segmentation boundary worth hardening.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.