All work
Deep dive · Network segmentation

Planning segmentation, interactively.

IEC 62443Purdue modelVendor-independentBrowser-based

Network segmentation is one of the most effective things you can do for OT and IT security. It is also one of the easiest to plan badly. Zones, VLANs, communication relationships, firewall rules, an operating model, responsibilities, a realistic roadmap. Most teams try to hold all of that in a spreadsheet and a Visio diagram that were never designed for the job.

Why a tool, not a spreadsheet

A segmentation concept is not one artefact. It is a zone model, a VLAN and subnet plan, a communication matrix, a derived firewall rule set, an operating model with roles and responsibilities, and an implementation roadmap, and all of those have to stay consistent with each other. The moment a zone changes, the matrix, the rules and the roadmap should change with it. Spreadsheets and drawing tools do not do that.

The narrowin segmentation toolbox is a browser-based planning environment built specifically for this. It is the same toolbox the firewall rule cleanup config parser belongs to, here seen as a whole. Three principles run through it:

Structured, not ad hoc

Pre-built templates for the Purdue model, enterprise campus and IT/OT convergence: a starting structure instead of a blank page.

Vendor-independent

The toolbox plans the design, not a specific vendor's box. No lock-in: the output is an architecture, not a configuration.

Ready in the browser

No installation, no account for the open tools, and the working data stays local in the browser; nothing is sent to a server.

Three areas, one goal

The toolbox covers the whole planning process: from the technical network design, through the organisational operating model, to the implementation roadmap. It is organised into three areas, each with its own set of tools.

Area 01

Network segmentation

The technical design: zones, VLANs, subnets, the communication relationships between them and the resulting firewall rule set.

Area 02

Operating model

The organisation around the segmented infrastructure: roles, processes, responsibilities and a RACI that says who decides what.

Area 03

Roadmap planning

From analysis to implementation: a timeline, a prioritisation by risk and effort, and structured work packages.

The toolbox zone planner – security zones with VLANs structured by Purdue level
Security zones: segments structured by Purdue level, each carrying its VLANs, started from a template or built from scratch

Define what may talk to what

Once the zones exist, the central question is which of them may communicate, and over which protocols. The communication matrix makes that decision explicit: every pair of zones gets a deliberate verdict, and the result is the authoritative reference the firewall rule set is derived from.

The matrix below is a working example with eight Purdue zones, using the toolbox's own demo data. Select any cell to see the protocols permitted across that zone boundary.

Allowed Restricted Blocked Same zone
No cell selected. The matrix reads source zone (rows) to destination zone (columns). Pick a cell to see the verdict and the protocols behind it.
Recreated from the toolbox's interactive demo: in the toolbox itself, any number of zones, rules and protocols can be defined

More than a network diagram

Segmentation projects rarely fail on technology. They fail on organisation: nobody defined who owns a zone, who approves a new communication path, or what happens when a device joins the network. A clean zone model with no operating model behind it is outdated within months.

That is why the toolbox treats the operating model as a first-class area, not an afterthought. It maps roles and teams, processes, a RACI matrix and FTE capacity onto the segmented infrastructure, so the design has an owner before it has a single rule.

The toolbox operating-model planner – capacity planning, roles and unassigned responsibilities
The operating-model planner: roles, capacity and a RACI that surfaces unassigned responsibilities before they become gaps

A roadmap you can actually run

A complete segmentation concept is rarely fewer than thirty work packages spread over several quarters: from network documentation, through zone design and firewall cleanup, to NAC, monitoring and compliance. Planned as one block, it stalls.

The roadmap planner ships with a template, "Network Security & Resilience", of 34 work packages across eight categories. Each package carries an owner, an effort-versus-benefit rating, its dependencies and a target quarter. Priorities follow risk and effort (quick wins first), and progress is tracked per category, not just per quarter.

The toolbox roadmap planner – work packages on a multi-quarter timeline, grouped by category
The roadmap planner: work packages on a multi-quarter timeline, grouped by category and prioritised by risk and effort

Starting in a brownfield network

Most segmentation projects do not start on a greenfield. They start in networks with organically grown VLANs, undocumented communication paths and inherited firewall rules. The toolbox is built for exactly that, not as a greenfield designer but as a planning tool that takes the existing environment seriously, in three moves.

1
Capture

Capture the baseline

Config import reads the existing firewall rules, interfaces and zones. The VLAN Planner documents the current structure. Network Explorer data adds topology and port context.

2
Plan

Plan the target

Security Zones map the segments to Purdue levels. The communication matrix defines the allowed transitions. IPAM and the operating model give the target architecture its structure.

3
Implement

Implement in waves

The roadmap planner turns the target into waves with maintenance windows, responsibilities and dependencies. No big bang, controlled packages instead.

What makes it practical

The toolbox is deliberately lightweight where it can be, so that planning work is never blocked on installation, licences or a server.

Browser-based

Runs entirely in the browser. No installation, no server, and no account for the open tools.

Local data storage

Working data stays in the browser. Nothing is sent to a server while you plan.

Templates & presets

Purdue model, enterprise campus, hospital IT/OT and other industry-specific starting points.

Export & documentation

Export zones, VLANs and the matrix as JSON, PDF or a structured report.

Config import

Import firewall configurations and analyse the rule set automatically, with the parser from the cleanup work.

German & English

Fully bilingual. Switch language at any time; the data is preserved.

Try it yourself

The toolbox is live

The full segmentation toolbox (all planning, operating-model and roadmap tools) runs at toolbox.narrowin.ch behind a login. Three tools are open without any registration: the VLAN Planner, the Subnet Calculator and the Communication Matrix.

Frequently asked

Why is segmentation more than a technical project?
Segmentation is often treated as pure infrastructure work: create VLANs, write firewall rules, done. In practice it rarely fails on technology. The hard parts are organisational: who defines the zones, who approves a communication relationship, what happens when a new device joins. Without clear responsibilities, processes and an operating model, segmentation stays a one-off project that is outdated within months.
What is the biggest challenge with IT/OT convergence?
IT and OT have fundamentally different priorities: IT optimises for confidentiality, OT for availability. When both worlds share a network, different patch cycles, responsibilities and risk appetites collide. Convergence therefore needs more than a technical zone model: it needs a shared governance framework, with aligned processes for change management, incident response and asset ownership across organisational boundaries.
How do you plan a segmentation project realistically?
A complete concept typically comprises thirty or more work packages over several quarters: from network documentation through zone design and firewall cleanup to NAC, monitoring and compliance. A realistic plan prioritises by risk and effort, with quick wins first, defines clear phases and tracks progress per category, not just per quarter. That is exactly what the roadmap planner in the toolbox is built for.
Is an operating model really needed for segmentation?
Yes. Segmentation is not a state but an ongoing process. New devices, changed communication requirements and firmware updates all require zones, VLANs and firewall rules to be reviewed and adjusted. Without defined roles (who may change a rule?), processes (how is a new VLAN requested?) and a RACI matrix, segmentation gets bypassed in day-to-day operations. That is why the toolbox includes a dedicated operating-model area.
How are the zone model, the matrix and the firewall rules related?
The zone model defines what is separated: Purdue levels, DMZ, management. The communication matrix defines which zones may communicate and with what restrictions. From that, concrete firewall rules are derived: protocols, ports, direction. These three layers should be planned consistently, not in isolation. In the toolbox they are linked: a zone change updates the matrix, and the matrix can be exported as a firewall rule set.
Where do you start with an existing network?
Brownfield is the norm. Most networks have organically grown VLAN structures, undocumented communication relationships and legacy firewall rules. The first step is an as-is assessment: which VLANs exist, which devices communicate where, which rules are still active and relevant. The toolbox supports that entry point with Config Import for firewall rule sets and the VLAN Planner to document the existing structure and gradually transition it into a zone model.
← All work