What are the layers of network security in IT infrastructure?
Six layers sit inside a typical IT infrastructure. None of them is sufficient alone, and the order matters less than the coverage. If you are designing a new estate rather than defending an old one, our note on building scalable infrastructure covers where these decisions sit.
The perimeter, and why it is no longer the boundary
What it does. Firewalls, gateways and filtering control traffic entering and leaving. Next-generation firewalls inspect application traffic rather than just ports.
What it stops. Opportunistic scanning, known-bad traffic, and unauthorised outbound connections, which matter as much as inbound.
The mistake. Treating the perimeter as the security model. Staff work from home, workloads run in someone else's data centre, and suppliers connect in. The perimeter is now a series of edges rather than a wall, which is why the cloud or on-premise decision is a security decision too.
Segmentation, and stopping lateral movement
What it does. Divides the internal network so that reaching one system does not mean reaching the rest. VLANs and internal firewalls at the coarse level; micro-segmentation per workload at the fine level.
What it stops. The part of an incident that turns a nuisance into a breach. Ransomware spreads through flat networks.
The mistake. Segmenting at the network layer and then allowing any-to-any rules because an application team complained. A segment with an open rule is a drawing, not a control.
Identity as the control point
What it does. Decides who and what can reach each segment and service. MFA, privileged access management, and access that expires.
What it stops. Credential-based entry, which was 13% of breaches directly and sits behind far more once phishing is counted.
The mistake. MFA on the staff VPN and nowhere else. Service accounts, administrator consoles and supplier logins are where it is missing. Our note on cloud security best practices covers the same gap in cloud consoles.
Encryption in transit
What it does. Protects traffic between systems, sites and users, internally as well as externally.
What it stops. Interception, and quiet data collection by an attacker already inside.
The mistake. Encrypting north-south traffic to the internet and leaving east-west traffic between internal systems in the clear, on the assumption that the internal network is trusted. That assumption is what zero trust exists to remove.
Monitoring, logging and detection
What it does. Collects the evidence and raises the alarm. Intrusion detection, network traffic analysis, and a SIEM that someone actually watches.
What it stops. Nothing, directly. It shortens the time between compromise and response, which is the difference between an incident and a disaster.
The mistake. Buying the tooling and not the people. A SIEM with nobody reading it is an expensive log archive. Who watches it is the question in the ownership section below.
Patching and configuration hygiene
What it does. Removes the vulnerabilities before they are exploited, and keeps configuration from drifting into exposure.
What it stops. The 31% category. The largest single entry point in the data.
The mistake. Treating patching as maintenance rather than as security work, and measuring it monthly when internet-facing systems need days. Automation helps here more than anywhere else, as our note on automation in infrastructure services sets out.