Why Flat Networks Are a Compliance Liability
In a flat network architecture — still the dominant configuration in 54% of Indian mid-market enterprises according to InfraVeritas 360 field data — a single compromised endpoint has direct network access to every other device: servers, databases, management consoles, backup systems, and financial applications. The 2024 AIIMS Delhi ransomware attack, which paralysed hospital operations for weeks, exploited a flat network where malware spread laterally from a single workstation to critical servers with no barriers. ISO/IEC 27001:2022 Annex A.8.22 requires network segregation. CERT-In Directions 2022 mandate network access controls. The RBI Cybersecurity Framework requires BFSI organisations to implement network-level separation between user segments, server segments, and Internet-facing DMZ.
Recommended Network Segmentation Model — Indian Enterprise
| VLAN / Zone | Systems | Access Policy |
|---|---|---|
| DMZ | Web servers, email gateways, public APIs | Internet-accessible; isolated from internal |
| Server VLAN | Database servers, application servers, ERP | No direct user access; application-layer only |
| User VLAN | Workstations, laptops, printers | Internet + approved app access only |
| Management VLAN | Network devices, hypervisors, IPMI/iLO/iDRAC | Jump server access only; no internet |
| Guest VLAN | Visitor Wi-Fi, contractor devices | Internet only; isolated from all internal |
| PCI/DPDP Zone | Cardholder data systems, PII processors | Strictly segmented; log all access |
Inter-VLAN Traffic Control
Segmentation without access control between segments is incomplete. Use a Next-Generation Firewall (NGFW) or Layer 3 ACLs to control all inter-VLAN routing. The default policy should be deny-all between segments, with explicit allow rules documented in your firewall policy. Log all inter-VLAN traffic. Review firewall rules quarterly — accumulated "temporary" rules are a common source of security debt.
Micro-Segmentation for High-Security Environments
For BFSI and healthcare organisations handling sensitive regulated data, VLAN segmentation is the minimum. Micro-segmentation — using software-defined networking (SDN) or endpoint-based solutions like Illumio or Akamai Guardicore — applies the zero-trust principle at the workload level, ensuring that even within the same VLAN, only explicitly permitted application-to-application communication is allowed.
Is Your Network Segmented for Compliance?
InfraVeritas 360 assesses your network architecture — VLAN design, inter-VLAN firewall policy, and DMZ configuration — against CERT-In and ISO 27001 requirements on-site.
Assess Your Network Architecture →