
A zone diagram takes an afternoon. Enforcing it in an occupied building takes far longer, and the gap is where segmentation work fails. The estate already has habits, and none are in the asset register.
What the diagram does not know
The first thing it misses is the undocumented flow. A scheduling application polls a controller on the building network. A licence server sits on whatever machine had a free slot, and workstations elsewhere still mount a share on it. Nobody wrote either down, because until a boundary appeared nobody had to.
The second is the device that must reach a server it should not. A building management head-end sends fault alarms through an SMTP relay. A nurse call server hands messages to a paging gateway. Refuse either without an alternative and the problem moves to whoever is on call.
The third is vendor access. Lifts, chillers, fire panels, medical devices and production plant carry maintenance contracts that assume a route in. Give that no controlled answer and someone will fit a mobile router in a riser. That obligation sits in a contract, not the network documentation, so ask early.
Broadcast discovery fails silently. A BACnet device answers a broadcast Who-Is, so splitting a subnet stops the answer arriving until a BBMD is configured on each side. Nothing logs an error. The device simply stops appearing.
The sequence that works
Audit from the switches, not the asset register. MAC and ARP tables, DHCP leases and flow records show what is connected and what it talks to. A switch ages a MAC entry out in about five minutes, so one snapshot shows only what was talking then. Three quiet days miss the monthly payroll run and the annual generator load test. Each becomes an incident once policy is live.
Then agree the zone model with the people who own the traffic. Estates, clinical engineering, production and IT share the cabling, and a model drawn by IT alone will cut a flow somebody's working day runs on.
Then write the flows down. Every permitted flow needs a source, a destination, a port, a reason, a named owner and a review date. A rule with no recorded reason is one nobody dares remove, and a rule base nobody prunes is how a segmented network becomes flat again.
Enforce last, and in stages. Run the policy in log-only mode and read what would have been denied. Then close one boundary at a time, each with a back-out the person on shift can apply.
What to ask for before sign-off
- The traffic observation, the dates it covers and the periods it misses.
- A zone model signed off by the traffic owner in each zone.
- A flow matrix where every line carries a reason and an owner.
- An authenticated, time-limited, logged route for each vendor that needs one.
Then ask what the design does about devices that cannot be re-addressed, authenticated or patched: a controller with a hardcoded address, a panel with no 802.1X supplicant. A design that does not name them has not looked.
Segmentation that holds is mostly survey and agreement. The rule base is the last part of the work, and the most mechanical.
Continue reading
Next step
Bring the complete environment into one conversation.
Tell us what you are planning, replacing, integrating or trying to stabilise. We will help define the right next step.

