Wethaq ICT | وثاق
Get a Quote
Insights

Network security fundamentals: segmentation, NGFW and visibility

GovernmentPrivate sectorBanks & finance

Many enterprise networks still behave like the office LAN of twenty years ago: once a device is connected, it can reach almost everything. In a flat network, one phished laptop or one compromised contractor account gives an attacker a clear path to file servers, databases and management interfaces. Good network security assumes that a breach will eventually happen and works to limit how far it can travel and how quickly you notice it.

Why flat networks fail

Attackers rarely stop at their first foothold. They scan, harvest credentials and move laterally towards valuable systems. A flat network removes every obstacle to that movement and gives defenders no natural place to detect it. Regulators and auditors increasingly expect demonstrable separation between user, server, payment, management and guest environments.

Segmentation: from VLANs to micro-segmentation

Segmentation should be layered, starting simple and getting finer where risk justifies the effort.

  • VLANs and subnets separate users, servers, printers, IoT, voice and guests at layer 2 and layer 3.
  • VRFs create fully separate routing tables, which suits separating production from test, or one business unit or tenant from another, over shared hardware.
  • Firewall zones enforce policy between segments with a default-deny stance. Allow only documented flows, and review the rules regularly.
  • Micro-segmentation applies host- or workload-level policy, for example between application tiers in a data centre or between virtual machines, so that even two servers in the same subnet cannot talk freely.

Start by classifying assets and mapping real traffic flows. Protect the crown jewels first, such as core banking, payment systems, identity servers and backup infrastructure. This approach also supports the Zero Trust direction described in NIST SP 800-207, where no network location is trusted by default.

NGFW, secure web gateway and visibility

A next-generation firewall (NGFW) adds application awareness, user identity, intrusion prevention and optional TLS inspection to classic port-based filtering. A secure web gateway (SWG) controls outbound web traffic, blocks malicious categories and enforces acceptable-use policy. Both are only as good as their configuration, so tune policies, keep signatures and firmware current, and be clear about which traffic you inspect and why.

Prevention is not enough. Network detection and response (NDR) analyses traffic, often from mirrored ports or sensors, to spot scanning, unusual east-west movement, command-and-control patterns and data exfiltration, including activity on devices that cannot run an agent. Feed NDR and firewall logs into your SIEM so network evidence sits beside endpoint and identity evidence. MITRE ATT&CK is a useful way to check which lateral movement techniques you can actually detect.

Secure remote access and management plane

Remote access should use strong authentication with MFA, device posture checks and access limited to the applications a person needs, rather than full network access. Retire shared VPN accounts and unmanaged third-party access.

The management plane deserves the same care as the data plane, because whoever controls your network devices controls your traffic.

  • Place device management interfaces on a dedicated out-of-band or management network, reachable only through a hardened jump host.
  • Use centralised authentication (TACACS+ or RADIUS) with role-based access and per-user accounts, and disable default credentials and unused services.
  • Use SSH and HTTPS only, and disable Telnet and plain HTTP.
  • Back up configurations, log changes and alert on unexpected configuration drift.
  • Patch network devices on a defined schedule, as they are frequent targets.

How Wethaq ICT helps

Wethaq ICT designs and reviews network architectures, plans phased segmentation, deploys and tunes NGFW and web-filtering platforms, integrates network visibility into monitoring, and hardens device management. Our teams also run the network day to day, so designs are built with operations in mind from the start.

Back to insights

Let’s build a secure foundation for your digital future

It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.