Skip to content
CONFIGLANE

Existing networks · Smaller companies

The network grew with you: seven signs it is time for a plan

Between “it works” and “nothing works” lies a long stretch on which a network becomes steadily harder to operate without ever failing. You recognise that stretch by symptoms, not by outages.

By ConfiglanePublished 5 min readSmall Business

The short version

  • Grown networks rarely fail. They slowly become unoperable: changes take longer, faults are harder to find, and nobody remembers why a rule exists.
  • The symptoms are easy to spot — from the unlabelled switch to a former provider's remote access to the firewall rule nobody dares delete.
  • Tidying is not rebuilding. In almost every case the order is survey, separation, access, documentation — replacing equipment comes last, not first.
  • The cheapest moment is an occasion that is coming anyway: a move, a new site, a line migration or a questionnaire from a customer.

Networks in smaller companies are rarely drawn on a board. They start with a router and five workstations and then grow with the business: a switch for the extension, an access point for the warehouse, a port forward for the new software, remote access for the accountant. Every single step was right. The sum eventually becomes something nobody knows completely.

Seven signs the limit has been reached

  • Nobody can say what is on a port. A cable gets unplugged and you wait to see who complains. That is not a joke but a widespread method — and a reliable indicator.
  • There are rules nobody wants to remove. A port forward or firewall rule whose purpose is unknown survives out of fear. The number of such rules only ever grows.
  • Former providers' remote access still exists. The vendor of the old inventory system, the phone system technician, the intern from 2021 — access is created and almost never removed.
  • The wireless password is a cultural artefact. It is on a note, every visitor of recent years knows it, and nobody dares change it because it is unclear which devices would stop working.
  • Changes need one particular person. When only one person knows how things fit together, the documentation is not poor — it does not exist.
  • Fault-finding starts with reboots. When the first step in every incident is restarting devices in turn, what is missing is visibility, not competence.
  • Everything is on one network. Point of sale, production, guests, servers and the camera at the gate share one address range. That works until one device is compromised.

Two or three of these are normal. Five or more mean every further change costs more than the last — and that during an incident the time goes into finding the cause rather than fixing it.

The order that works without downtime

The most common mistake when tidying up is starting with the most visible item, usually new hardware. That costs the most and changes the least. The order that works in small networks is the reverse and can be done alongside operations.

  1. Record what exists

    Devices, connections, access paths, contracts. Two days with a notepad, a camera and a look at the configuration achieve more than any purchase. The result is a list, not a concept.

  2. Tidy the access paths

    Every remote access gets a name and an expiry date; anything that cannot be attributed is switched off. This is the step with the best effort-to-risk-reduction ratio — and it costs nothing.

  3. Separate what does not belong together

    Guests out, production and cameras into their own areas, servers decoupled from the workstation network. In small networks that is three to five areas, not twenty.

  4. Label and document

    Ports, patch panel, devices, a one-page network diagram. Unspectacular, but it decides whether the next incident takes twenty minutes or half a day.

  5. Only then replace equipment

    Once it is clear what the network has to deliver, procurement becomes a short decision instead of a bet. Often less needs replacing than feared.

What to deliberately leave alone

Tidying does not mean redoing everything. Three things usually stay as they are: cabling that carries; devices that do their job and still receive updates; and grown routines that work. A tidy-up project that changes how the company works does not get finished — it gets abandoned.

Nor is there any point in rebuilding a corporation's architecture in a network with thirty workstations. What counts is enterprise care in the method — sized to fit. How we do that for smaller companies is described on the service page.

The right occasion

Tidying without an occasion rarely gets budgeted. It is therefore worth using the next date that is coming anyway: an office move, an additional site, the migration to fibre, a new cyber policy or a customer's security questionnaire.

All four occasions demand a survey regardless. Doing it once properly instead of four times halfway is the entire difference.

Sources

Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.

FAQ

Frequently asked questions about grown company networks

Do we have to redo everything?

Almost never. In most smaller networks the cabling is usable and some of the equipment stays in service. The effort sits in the survey, in tidying access paths and in separation — all work on configuration and documentation, not on procurement.

How long does this take?

For a single-site network with up to fifty workstations, the survey and access clean-up are a matter of days. Separation into areas runs over a few maintenance windows depending on preparation. What sets the duration is not the technology but how many unclear legacy relationships have to be resolved.

Can we do this during normal operations?

Yes, if the order is right. Survey and documentation disturb nobody. Tidying access paths needs coordination, not downtime. Only the separation into areas belongs in an announced window — and even that runs in stages rather than entirely over one weekend.

We already have IT support. Does this fit alongside?

Usually well. Day-to-day support and a one-off tidy-up are different tasks with different rhythms. What matters is that documentation exists at the end that the current support can work with — otherwise you gain a second dependency rather than fewer.

Enterprise Networks

Network migration and operations. Change without guesswork.

An evolved network contains more knowledge than its latest diagram. We expose dependencies, structure the migration and hand the new baseline into operations with clear responsibilities, evidence and recovery paths.

Discuss migration and operations

Assessment → first dependable change