Connectivity should not imply unrestricted access
Employee computers, guest phones, printers and cameras serve different purposes. There is usually no business requirement for every device to reach every other device. Segmentation helps separate these groups and control communication between them. CISA’s infrastructure guidance discusses segmentation alongside firewall and access controls; creating different network names alone is not enough.
Technical source: CISA — Enhanced Visibility and Hardening Guidance for Communications Infrastructure
List communication requirements beside device groups
Your starting table should identify each group, its owner and the services it needs. A guest may need internet access without access to accounting files. A camera may need to send video to a recorder without reaching every employee computer. These are illustrative scenarios: validate actual rules against the technical requirements of your devices and applications.
Account for less visible dependencies
Printing, device discovery, time synchronization and management access can create unexpected issues during separation. Use a phased rollout rather than declaring the work complete after splitting the network. Pilot one group and record the communication it needs. If something fails, identify the specific missing flow instead of restoring unrestricted access as a permanent workaround.
Treat management access separately
Permission to use a device is different from permission to administer it. An employee may print without needing access to the printer’s management interface. Someone viewing camera footage does not necessarily need to change network settings. Discuss service users, administrators and external support teams separately when defining rules. Include an expiry point for temporary support access.
Test boundaries as well as connectivity
A successful project allows required work while blocking unnecessary access. Test guest connectivity, printing, video recording and administration separately during acceptance. Keep the diagram, address plan and rule ownership current. When the right group for a new device is clear, segmentation becomes an operating process that can be maintained rather than a one-time installation.