Network segmentation in a small company: how many VLANs is too many
A single flat network is simple until the first incident. Five segments are enough for most organisations, provided that policy stands between them and not just a VLAN number.
Most incidents do not come from a lack of tools but from permissions somebody granted long ago and forgot about. This area covers the fundamentals that work regardless of budget: a tiering model for privileged accounts, reducing the attack surface, patching, and configuration hygiene.
A single flat network is simple until the first incident. Five segments are enough for most organisations, provided that policy stands between them and not just a VLAN number.
You do not need to buy a privileged access management system to stop logging on to workstations with a domain administrator account. Three tiers, separate accounts and a few Group Policy settings are enough.
Publishing a strict policy in one day ends with your own invoices and newsletters being rejected. Sender authentication is rolled out in a specific order, with reports as the guide.
A message caught by a filter does not always generate a notification. Whether the user ever finds out depends on the quarantine policy assigned to the filter that caught it.