Network Segmentation: Why Flat Networks Fail CERT-In and ISO 27001 Audits

By Arjun Mehta · 10 March 2026

Why Flat Networks Are a Compliance Liability

In a flat network architecture — still the dominant configuration in 54% of Indian mid-market enterprises according to InfraVeritas 360 field data — a single compromised endpoint has direct network access to every other device: servers, databases, management consoles, backup systems, and financial applications. The 2024 AIIMS Delhi ransomware attack, which paralysed hospital operations for weeks, exploited a flat network where malware spread laterally from a single workstation to critical servers with no barriers. ISO/IEC 27001:2022 Annex A.8.22 requires network segregation. CERT-In Directions 2022 mandate network access controls. The RBI Cybersecurity Framework requires BFSI organisations to implement network-level separation between user segments, server segments, and Internet-facing DMZ.

Recommended Network Segmentation Model — Indian Enterprise

VLAN / ZoneSystemsAccess Policy
DMZWeb servers, email gateways, public APIsInternet-accessible; isolated from internal
Server VLANDatabase servers, application servers, ERPNo direct user access; application-layer only
User VLANWorkstations, laptops, printersInternet + approved app access only
Management VLANNetwork devices, hypervisors, IPMI/iLO/iDRACJump server access only; no internet
Guest VLANVisitor Wi-Fi, contractor devicesInternet only; isolated from all internal
PCI/DPDP ZoneCardholder data systems, PII processorsStrictly segmented; log all access

Inter-VLAN Traffic Control

Segmentation without access control between segments is incomplete. Use a Next-Generation Firewall (NGFW) or Layer 3 ACLs to control all inter-VLAN routing. The default policy should be deny-all between segments, with explicit allow rules documented in your firewall policy. Log all inter-VLAN traffic. Review firewall rules quarterly — accumulated "temporary" rules are a common source of security debt.

Micro-Segmentation for High-Security Environments

For BFSI and healthcare organisations handling sensitive regulated data, VLAN segmentation is the minimum. Micro-segmentation — using software-defined networking (SDN) or endpoint-based solutions like Illumio or Akamai Guardicore — applies the zero-trust principle at the workload level, ensuring that even within the same VLAN, only explicitly permitted application-to-application communication is allowed.

Is Your Network Segmented for Compliance?

InfraVeritas 360 assesses your network architecture — VLAN design, inter-VLAN firewall policy, and DMZ configuration — against CERT-In and ISO 27001 requirements on-site.

Assess Your Network Architecture →