Skip to main content

Segmentation and isolation are network design strategies that limit lateral movement by attackers. Segmentation involves dividing a network into smaller zones, such as placing public-facing web servers in a separate subnet (often so-called DMZ) from internal databases. Isolation goes a step further, ensuring that systems—especially critical or high-value assets—operate in completely separate environments. For example, industrial control systems might be air-gapped from the corporate network to prevent cross-contamination. The term air-gapped is commonly used to state that there is no logical connection with them.