Skip to content
Cybersecurity

Network Security for Businesses: What Switches, Firewalls, Access Points and Segmentation Are Really For

Plainly explained: the role of switches, firewalls and access points, why VLANs and port forwarding decide security and what zero trust means for SMEs.

Published on 5 min read

Network cabinet with three switches, blue and grey cables neatly routed downwards.

Most companies buy network technology because they need connectivity. That the same devices decide how far an attacker gets once inside is rarely considered. Properly configured, switches, firewalls and access points draw the boundaries at which an attack ends.

Why the network decides the damage

The 2025 situation report of the German Federal Office for Information Security (BSI) counts an average of 119 new vulnerabilities per day, and around 80 per cent of reported attacks targeted SMEs. For its Threat Landscape 2025, ENISA analysed 4,875 incidents: phishing was the dominant entry point at around 60 per cent, exploitation of vulnerabilities accounted for 21.3 per cent.

The first step of an attack therefore almost always succeeds through a person or an unpatched vulnerability. Whether it ends in an encrypted company is decided on the network: whether malware can move freely from the infected workstation to servers, backups and building services.

The switch: VLANs and access control

A switch connects the devices at a site and performs two security tasks. First, it separates the network into virtual subnetworks, VLANs. Devices in different VLANs cannot see each other unless a router or firewall explicitly allows it. Second, it controls who may connect. Port security or network access control (NAC) ensures an unknown laptop gets no access or only an isolated network.

IT-Grundschutz module NET.3.1 requires that switch ports be protected against unauthorised access and that routers and switches be administered only via a separate management network.

The firewall: rules in both directions

A firewall sits at transitions between networks, between company network and internet as well as between the VLANs in the building. Module NET.3.2 requires that all communication between networks passes through the firewall, that unambiguous rules define which connections are permitted, and all others are blocked. That is the allowlist approach: everything is prohibited except what is explicitly allowed.

The same logic applies to outbound traffic: malware that cannot reach its command servers is far less dangerous. NET.1.1 therefore requires data flows to be restricted to the required communication relationships, outbound as well as inbound.

A policy is such a rule in plain language before it becomes technology: “The guest Wi-Fi may only reach the internet.” A port forward deliberately opens access from outside to an internal service. The most common mistakes are covered in the article Firewall rules and port forwarding: the most common mistakes in SMEs.

The access point and the guest Wi-Fi

Because radio does not stop at the office wall, access points require particular care. Module NET.2.1 requires that methods less secure than WPA2 are no longer used and that a pre-shared key has at least 20 characters. Requirement A6 demands that Wi-Fi must not couple security zones and thereby bypass protective measures.

A guest Wi-Fi must bring guests to the internet and nowhere else: own SSID, own VLAN, an “internet only” firewall rule, isolation of guests from each other and separation from the staff Wi-Fi, which works with certificates or user accounts. How a hotel network is separated from the start is described in the checklist for networks in new builds and hotels.

Segmentation and zero trust

Segmentation divides the network into zones by protection requirement. Under NET.1.1.A4 the network must be separated at least into internal network, demilitarised zone (DMZ) and external connection. Under A5 clients and servers sit in different segments, under A6 only devices with a similar security level share a segment, and under A10 every internet-facing service belongs in an external DMZ.

For an SME this produces a manageable zone list: workstations, servers, backup, management, building services, guests. In the 2019 Emotet incident at the Berlin Kammergericht, the forensic final report named an unsegmented network and local administrative rights as decisive factors. Further cases are described in the article Cyber attacks on companies in Berlin and Brandenburg.

Zero trust means: no device and no user gets access simply because it is on the company network. For SMEs this means implementing the principles step by step: first the zones, then remote access with a second factor, then restricting rights to the necessary. The twelve measures are described in the article Protection against hacker attacks: 12 concrete measures.

Key points

  • The first step of an attack succeeds through phishing or an unpatched vulnerability; how far it gets is decided by switches, firewalls and access points.
  • Switches separate by VLAN, firewalls permit only explicitly defined connections in both directions, and access points must not couple the zones.
  • The IT-Grundschutz requires segmentation as a basic requirement; a switch with VLANs and a firewall in between suffice for most sites.

How DEVACON supports companies with planning, installing and operating switches, firewalls and Wi-Fi is described on the page Network and IT infrastructure.

Sources

  • Federal Office for Information Security (BSI): Die Lage der IT-Sicherheit in Deutschland 2025, reporting period 1 July 2024 to 30 June 2025, bsi.bund.de/lagebericht
  • BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.1.1 Netzarchitektur und -design, bsi.bund.de
  • BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.2.1 WLAN-Betrieb, bsi.bund.de
  • BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.3.1 Router und Switches, bsi.bund.de
  • BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.3.2 Firewall, bsi.bund.de
  • ENISA: Threat Landscape 2025, published 1 October 2025, analysis of 4,875 incidents from 1 July 2024 to 30 June 2025, enisa.europa.eu
  • G DATA: Kammergericht Berlin, final report on the Emotet infection, January 2020, gdata.de

Topics Network Firewall Wi-Fi Segmentation Zero Trust

This article comes from the DEVACON blog and was editorially revised for the new website.