services/Network Design & Segmentation

Segmentation and architecture simple enough to run and defend.

Most networks grow organically until they're too complex to change safely. We design networks simple enough to understand, operate and defend, from flat-network segmentation to a full OT architecture.

Target architecture — zone model DESIGN
IT zoneoffice, serversVLAN 10 · 20
— policy enforced —
DMZjump hosts, shared servicesVLAN 50
— policy enforced —
OT zonecells, controllers, HMIsVLAN 100 · 110 · 120
— policy enforced —
Managementout-of-band accessVLAN 200
4 zones · segmented · a policy at every boundary
[ Why it matters ]

A network you can't change safely is a network you can't defend.

Devices get added, VLANs multiply, documentation lags, until the network is too tangled to touch with confidence. Design work is the right move when you know change is needed, but the target architecture isn't there yet.

01

Flat network, no segmentation

Everything on one or two VLANs. A compromised device can reach the whole network. You need zones, but the architecture doesn't exist yet.

02

A segmentation project, no plan

The project is approved and budgeted, but nobody has designed the target. Firewall rules without an architecture is just complexity without structure.

03

IT and OT converging

The two are merging without a plan. OT wants isolation, IT wants integration. You need an architecture that gives both sides what they need.

04

Regulatory pressure

NIS2, the IKT-Minimalstandard, ISO 27001: they demand documented segmentation. You need an architecture you can defend in an audit.

[ What we deliver ]

An architecture, not just a firewall ruleset.

We design zone models, addressing and segmentation concepts, and a realistic path to get there. Every design starts from real network data, not interviews and assumptions alone.

A · ZONE ARCHITECTURE

The segmentation concept

A zone model with clear boundaries for IT, OT, DMZ and management: the structure the whole network hangs from.

B · VLAN / VRF LAYOUT

Addressing and structure

An IP addressing plan, VLAN assignments, VRF structure and naming conventions, consistent and ready to grow.

C · ACCESS POLICIES

What may talk to what

Firewall rule sets, inter-zone policies and traffic-flow definitions: the rules that make the zones real.

D · MIGRATION PLAN

A realistic path there

A phased rollout from the current state to the target, with rollback points. No big-bang required.

[ How we work ]

From the real network to a design your team can run.

From understanding the current state to handing over a design your team can implement and maintain.

1

Discovery

Explorer and assessment data show the real network: topology, traffic flows, dependencies.

2

Architecture design

We create the zone model, the VLAN/VRF layout, the IP plan and the inter-zone policies.

3

Review workshop

We walk the design through with your team: challenge assumptions, refine constraints, align on priorities.

4

Implementation support

We support the rollout: config generation with OT Connect, IP planning with IPAM, device protection with Diode.

5

Handover

Documentation, runbooks and knowledge transfer, so your team can maintain and evolve the design.

In practice: a design is developed together with the people who will run it.

[ Proof ]

Architecture work in real operational environments.

Energy · utility

Eniwa

A full network architecture redesign for a Swiss utility: from a flat OT network to zone-based segmentation, with OT Connect.

Critical infrastructure

Kernkraftwerk Gösgen

Network security architecture for nuclear-power-plant infrastructure: the highest compliance requirements.

Research · campus

sciCORE · University of Basel

Campus network segmentation for a high-performance computing and research environment.

[ Frequently asked ]

The specifics.

How long does a design project take?

Typically 1–3 months from kickoff to handover, depending on scope such as network size and whether an assessment was already done.

Do you also implement the design?

Yes. We offer implementation support, from config generation with OT Connect to hands-on deployment. Some teams prefer to implement themselves with our design as the blueprint. Both work.

What if we already have a partial design?

We review what exists, identify the gaps, and extend or refine it. No need to start from scratch. Many projects begin with a concept that needs to be validated and completed.

How does this relate to the assessment?

The assessment creates the baseline: current state, risks, priorities. Design turns that baseline into a target architecture. They are complementary, but can be done independently.

[ Related work ]

Designs we have built.

Network architectures delivered for real critical-infrastructure operators.

Design the architecture that works in practice.

Whether you're starting from a flat network or refining an existing segmentation concept, we help you get to a design your team can actually run.

Discuss your architecture