Most small business networks are flat: everything connected can reach everything else. The camera system can reach the file server. The visitor's laptop can reach the accounts machine. The smart thermostat can reach the till.
Nothing is going wrong today, which is why nobody addresses it.
What a VLAN actually does
It divides one physical network into several logical ones. Devices in different segments cannot reach each other directly, even though they are plugged into the same switches and running over the same cables.
Traffic between segments must pass through a router or firewall, which is where you decide what is permitted. The camera network can reach the internet for updates and nothing else. Guests reach the internet and nothing else. Staff computers reach the file server but not the building controls.
You get separation without a second set of cabling, which is what makes it practical.
Why it matters
Containment
The primary reason. Security is not only about keeping things out — it is about limiting what happens once something gets in.
A compromised device on a flat network can attempt to reach everything. The same device on an isolated segment can reach the internet and nothing else, which turns an incident into a nuisance.
This matters most for the equipment you maintain least: cameras, door entry systems, building management, printers. That equipment often runs software that will never be updated, and it is a well-known route into business networks.
Visitors
Guest wi-fi on the same network as your business systems means every visitor's laptop — including whatever it is carrying — is inside your network. Separation here is straightforward and is the most common first step.
Performance
Certain kinds of network traffic are sent to every device in a segment. In a large flat network that becomes significant, and it particularly affects wireless clients. Smaller segments reduce it.
Segmentation also lets you prioritise. Voice traffic on its own segment can be given priority so a large file transfer does not degrade a customer call.
Diagnosis
When something is behaving oddly on a flat network, everything is a suspect. With segmentation you can narrow it immediately, and the address of a device tells you what kind of thing it is.
Segmentation does not prevent a compromise. It decides whether one compromised device is an incident or a disaster.
How many segments
For most small businesses, four:
Staff. Computers, laptops, phones used for work. Access to business systems.
Guests. Internet only, isolated from everything, with a bandwidth limit.
Devices that are not computers. Cameras, printers, door entry, building controls, till systems. Internet where genuinely required, and no access to business systems.
Voice, if you use IP telephony. Separated and prioritised.
Larger or more regulated businesses may need more — a segment for card payment systems, for instance, or separation between departments handling different categories of data. Below that scale, additional segments add administration without adding much protection.
The rules between segments
Creating segments is the easy part. Deciding what may cross between them is the design work.
Default to denying, then permit what is genuinely needed. Staff computers need to reach the file server on specific services, not on everything. Printers need to receive print jobs, not to initiate connections to workstations.
Two rules that catch people out:
Printers and scanners need thought. Scan-to-email and scan-to-folder mean the device initiates connections into other segments. Permit the specific path rather than opening the segment.
Management access needs a route. Somebody has to administer the cameras. Provide a controlled path from an administrative machine rather than leaving the segment open.
What it requires
Managed switches, and a firewall or router capable of routing and filtering between segments. The step up in cost from unmanaged equipment is modest, and managed switches also give you the ability to see which port a device is on — which alone repays the difference the first time you are tracing a fault.
Wireless access points need to support multiple networks mapped to different segments, which business equipment does and most consumer equipment does not.
Doing it to an existing network
It can be done incrementally, and should be.
- Guest first. Isolated, no access to anything internal. Lowest risk, immediate benefit.
- Then the non-computer devices. Cameras, printers, building systems. Expect to spend time working out what each genuinely needs to reach.
- Then voice, if applicable.
- Then any further separation your circumstances require.
Do each during a planned window, and test properly afterwards — particularly printing and scanning, which are what people notice first.
Document the segments, their address ranges, and the rules between them. An undocumented segmented network is harder to work on than a flat one, which is the failure mode to avoid. See business network design for the wider picture.
Our infrastructure team segments business networks across Suffolk and Norfolk, in stages, without stopping the business. Start a conversation.








