Network Segmentation Architecture Design
Project Overview
Project Type: Infrastructure Security and Network Architecture
Organisation: National Railway Museum
Role: Cyber Security Volunteer
Executive Summary
This project focused on improving network security through the design and validation of a segmented network architecture intended to reduce exposure, improve separation of critical systems, and limit opportunities for lateral movement.
The work involved analysing the existing network environment, reviewing system dependencies, identifying communication requirements, developing a proposed future-state architecture, coordinating implementation requirements, and validating newly configured isolated firewall interfaces before production migration.
The Challenge
The existing environment operated with limited network segmentation, resulting in broad communication paths between user devices, infrastructure systems, storage platforms, and CCTV systems.
This increased the potential impact of a compromised endpoint and made it difficult to apply more granular security controls.
The challenge was to improve security without disrupting operational requirements or introducing unnecessary complexity.
Approach
The project followed a structured assessment and design process.
Activities included:
- Asset discovery
- Infrastructure analysis
- Dependency mapping
- Communication path analysis
- Current-state architecture review
- Security zone design
- Segmentation rule development
- Firewall-interface validation
- Migration-readiness planning
Solution Design
User Zone
Included:
- Office workstations
- Library computers
- Shop systems
- Wireless access points
- General user devices
Server Zone
Included:
- Domain services
- Shared storage
- Archive systems
- Backup infrastructure
- Internal services
CCTV Zone
Included:
- CCTV cameras
- Recording infrastructure
- CCTV management systems
Security Objectives
The design aimed to:
- Reduce unnecessary communication
- Limit lateral movement opportunities
- Improve protection of critical systems
- Support granular access controls
- Improve security management capabilities
Key Deliverables
- Current-state network review
- Dependency mapping documentation
- CCTV architecture review
- Proposed segmented architecture
- Segmentation rules and communication logic
- Infrastructure validation notes
- Implementation planning and validation documentation
Outcomes
The project produced a practical network segmentation model aligned with organisational requirements and infrastructure constraints.
The proposed architecture established clearer security zones, supported provider configuration requirements, and improved understanding of system relationships throughout the environment. Newly configured isolated server and CCTV interfaces were validated before production migration, with CCTV/server migration prepared as a controlled follow-on activity.
Skills Demonstrated
- Network Architecture Review
- Infrastructure Security
- Dependency Mapping
- Segmentation Design
- Firewall-Interface Validation
- Security Improvement Planning
- Risk Analysis
- Stakeholder Communication
Lessons Learned
Effective segmentation requires more than simply separating systems. Understanding dependencies, operational requirements, and communication flows is critical to ensuring security improvements remain practical and sustainable.