Back to Catalog

Network Segmentation: Why Guest Phones and Smart TVs Don't Belong on Your Corporate Network

Blue and grey ethernet cables plugged into a numbered network patch panel

Walk into almost any small office, dental clinic, or legal firm, and you will find an assortment of connected hardware: smart conference room televisions, connected coffee makers, digital thermostats, visitor smartphones, and employee personal tablets. In far too many businesses, all of these gadgets connect to the exact same Wi-Fi network and switch ports as your accounting servers and electronic records.

This "flat network" design is a major security hazard. If a visitor's infected phone connects to your Wi-Fi, malware can probe every computer in your office. Similarly, cheap smart TVs and IoT cameras rarely receive security firmware patches, making them popular footholds for hackers. As emphasized in the CISA Zero Trust Maturity Model network segmentation guidance (PDF), network partitioning is essential to contain security incidents.

"If an untrusted device is compromised on your network, it should only be able to see the internet—never your accounting database or patient records."

How Virtual LANs (VLANs) Work

You do not need to purchase separate physical cabling or individual routers for every department. Modern commercial switches and access points support Virtual Local Area Networks (VLANs). A VLAN uses software rules to partition a single physical network into isolated digital compartments.

Devices inside one VLAN cannot communicate with devices in another unless explicit firewall rules permit it. Following NIST Special Publication 800-41 guidelines on firewalls and network segmentation (PDF), every commercial workspace should establish at least four distinct network zones:

  • Corporate Core VLAN: Reserved exclusively for company-owned workstations, file servers, network-attached storage, and management portals. Access is restricted and encrypted.
  • Guest Wi-Fi VLAN: Completely isolated from the rest of the business. Visitors and patients can browse the web and stream media, but they cannot see or ping your office printers or server drives.
  • IoT & Facility VLAN: Dedicated to smart thermostats, conference room display screens, security cameras, and smart door locks. These devices only receive internet access to download manufacturer updates and communicate with their cloud apps.
  • VoIP Communications VLAN: Dedicated to office desk phones and teleconference equipment. Placing voice traffic on its own VLAN allows prioritization of audio packets, preventing stutter and jitter during heavy file downloads.

Client Isolation on Wireless Access Points

Beyond basic VLANs, enterprise Wi-Fi systems support a feature called "Client Isolation." When enabled on your Guest Wi-Fi, wireless devices cannot talk to one another even though they share the same access point. This prevents a malicious visitor in your waiting room from scanning another patient's laptop or mobile phone.

Build Stronger Digital Walls Inside Your Office

A flat network leaves your most critical business assets vulnerable to the weakest connected device on your premises. Take our 60-second IT Health Quiz to assess your network zoning, or contact James Hatch to schedule an architecture review and segment your infrastructure cleanly.