Introduction: The Security Rule NPRM modifies numerous administrative safeguards and introduces several new technical safeguard requirements. One of those new technical requirements involves network segmentation. Our colleague Liam Dwyer explains what network segmentation is in this post.
When developing a strong cybersecurity program, particularly one that needs to support privacy and security compliance requirements, you’ll often hear infosec experts talk about network segmentation. Everyone who’s not IT or infosec savvy may just nod along like they understand but not realize why it’s essential in a cybersecurity context.
It makes a lot more sense when you understand what network segmentation is – the practice of dividing a computer network into smaller, distinct subnetworks, or segments. Each network segment can function independently. It’s often isolated based on the that network’s function, level of sensitivity of the data it handles, or due to security requirements.
Segmentation not only helps control data traffic flow, but it also limits a cyberattacker’s reach– because they can only access one part of the network.
Why your CISO or Infosec Lead might be emphatic about network segmentation.
Let’s look at a few of the main reasons – and associated real-world scenarios – of why your CISO or Infosec Lead might be emphatic about network segmentation in your organization.
1. Breach Containment
- Purpose: If a threat actor – aka hacker, malware, etc. – breaches one segment, they can’t easily move laterally to other parts of the network.
- Benefit: In a segmented network, a compromised marketing workstation can’t directly access a database server in the finance segment.
2. Reduced Attack Surface
- Purpose: Limiting unnecessary access between systems reduces the number of paths an attacker can exploit.
- Benefit: Only essential systems can communicate, making it harder for malware or attackers to spread.
3. Improved Monitoring and Detection
- Purpose: Traffic within a segment can be more easily monitored and baseline behaviors established.
- Benefit: Uncharacteristic activity becomes easier to detect when it’s not mixed with unrelated network traffic.
4. Access Control Enforcement
- Purpose: Implement granular access rules using firewalls, ACLs (Access Control List), or VLANs (Virtual Local Area Network) between segments.
- Benefit: For example, HR systems may only allow access from specific HR user machines and deny all others.
5. Regulatory Compliance
- Purpose: Many regulations like HIPAA or the Payment Card Industry Data Security Standard (PCI DSS) require that sensitive data be isolated from general-purpose systems.
- Benefit: Segmentation helps meet these regulatory requirements simply by separating systems that handle the regulated data (e.g, PHI, PII, payment information).
6. Improved Performance
- Purpose: By separating traffic types, you can reduce congestion and improve speed and reliability.
- Benefit: Helps prioritize critical application traffic, while isolating bandwidth-heavy or less secure traffic.
So how big of a breach could network segmentation help prevent, or at least make less terrible? Remember Target’s 2013 data breach? Over 40 million customers had their payment card data and associated personal information compromised.
The reason you, me, and pretty much anyone who’d recently shopped at Target, were affected is because the attackers were able to easily move from the HVAC vendor’s (yep, HVAC!) network segment to the payment card environment (PCI zone), due to insufficient segmentation (and the result of poor 3rd party vendor management practices, as well).
Liam Dwyer is a dynamic cybersecurity leader with a proven track record, adept in cybersecurity frameworks and strategic planning. Liam has spearheaded comprehensive security programs, integrating risk management and incident response to safeguard global healthcare organizations. Liam’s professional experiences over the past 15 years include positions as a network security engineer, lead security engineer, and information security engineer. Connect with Liam on LinkedIn.