Flat networks turn local trust into broad reachability
On a flat network, being on the network is the same as being trusted by everything on it.
That was a reasonable design when the network was a building and everything in it was owned and managed. It stopped being reasonable once laptops leave, suppliers connect, cloud services join and devices nobody chose appear. A flat network turns any single foothold into an enormous amount of reach, which is the single most common reason a contained incident is not contained.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
- Network zones should reflect trust and functionZones follow the job
