Skip to main content
Networking and Infrastructure

Network Segmentation

Dividing a network into smaller, isolated segments to limit lateral movement by attackers and contain breaches to a single segment.

Network segmentation divides a larger network into smaller, isolated sub-networks (segments or zones). Each segment has its own access controls, so even if an attacker breaches one segment, they cannot freely move to others.

Segmentation is a core principle of defense-in-depth. Critical systems (databases, admin panels) are placed in restricted segments accessible only from specific source networks. This limits the blast radius of a breach.

For teams, network segmentation complements credential security. Even if an attacker steals a password for one service, network restrictions may prevent them from reaching the service. Combining segmentation with unique, per-service passwords from a password manager creates layered defense.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide