Segmentation: fire compartments for your network
In a flat network, an attacker who takes over a single PC can reach everything from there — servers, finance, production. Segmentation builds fire walls: the network is divided into zones (office, servers, production, guests), and a firewall between the zones decides which traffic is genuinely needed. A compromised device stays contained in its compartment instead of moving sideways through the building. Against the spread of ransomware, this is the single most effective measure in the network.

