Infrastructure · 6 min

VLANs and network segmentation — why and how

Segmentation is a security layer most companies still lack.

31 October 2025

IT infrastructure is the foundation — if the network, power or servers fail, the whole company grinds to a halt. In this article we show how to approach VLANs and network segmentation — why and how so you avoid the most common mistakes that later cost tens of thousands of złoty.

Segmentation is a security layer most companies still lack.

Why segment

The answer is "it depends" — but it depends on a few very concrete things that can fit on one page. For VLANs and network segmentation — why and how the four key variables are: company size, industry, downtime tolerance, and budget.

  • Companies up to 20 people — outsourcing and public cloud usually win.
  • 20–100 people — a mixed model: a dedicated account manager + provider's team.
  • 100+ people — an internal IT department supported by external specialists (security, cloud).
  • Regulated industries (medical, financial) — always additional compliance layers, regardless of size.

VLAN design

This section frames the topic "VLAN design" in the context of VLANs and network segmentation — why and how. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Network and system stability that users perceive as "things just work here".
  • Ability to scale the office without rebuilding cabling and the network.
  • Safe segmentation — an incident in one segment does not take the whole company down.

Most common mistakes

  • Saving on cabling and access points — the cost shows up in user complaints.
  • No network segmentation — one infected device infects the whole company.
  • A UPS with no periodic battery replacement — works until the first real outage.

Firewall between VLANs

Modern IT security works in layers. No single solution protects a company 100% — only a full set of layers (identity, endpoints, network, data, people) provides real effect. In the context of VLANs and network segmentation — why and how it is worth starting with the basics:

  • MFA on all accounts (no exceptions for the board — the most common gap).
  • EDR/XDR instead of classic antivirus — it detects behaviour, not just signatures.
  • Backups in several locations, including an offline or immutable copy — ransomware cannot encrypt them.
  • Patches within 14 days of the vendor's release.
  • Anti-phishing training at least quarterly, with simulations.
Rule of thumb: spending on prevention is on average 10–15× lower than the cost of recovering from a successful ransomware attack (not counting lost reputation and GDPR fines).

Best practices

This section frames the topic "Best practices" in the context of VLANs and network segmentation — why and how. We approach it from the business side — what concrete value or risk it brings to the company.

What you gain

  • Network and system stability that users perceive as "things just work here".
  • Ability to scale the office without rebuilding cabling and the network.
  • Safe segmentation — an incident in one segment does not take the whole company down.

Most common mistakes

  • Saving on cabling and access points — the cost shows up in user complaints.
  • No network segmentation — one infected device infects the whole company.
  • A UPS with no periodic battery replacement — works until the first real outage.

Key takeaways

  • Network and system stability that users perceive as "things just work here".
  • Saving on cabling and access points — the cost shows up in user complaints.
  • Treat the topic of "VLANs and network segmentation — why and how" as a project, not a one-off purchase — the best results come from a step-by-step approach.

Frequently asked questions

Let's take care of the foundation of your IT

Book a free infrastructure consultation. We will analyse your network, power, monitoring and security, then point out priority investments with real ROI.