Network segmentation divides networks into isolated sub-networks to improve security by limiting adversary movement and protecting sensitive government data.
Think of network segmentation like the watertight compartments in a ship. If one compartment is breached and floods, the watertight doors prevent water from spreading to other compartments, limiting damage and keeping the ship afloat.
Similarly, network segmentation creates boundaries within your network so that if adversaries compromise one segment, they face additional barriers preventing them from easily reaching other segments. Without segmentation, networks resemble open-plan spaces where anyone who gets in can access everything—segmentation creates rooms with locked doors that require additional credentials and controls to pass through.
Defence contractors typically have diverse network zones with different security requirements. Public-facing systems like corporate websites, marketing email servers, and customer portals need internet accessibility but contain less sensitive information.
General business systems including email, file servers, HR systems, and financial applications support day-to-day operations. Development and testing environments contain pre-release software and test data. Operational technology (OT) or industrial control systems may operate manufacturing or physical security systems.
Most critically, systems handling specified information process, store, or transmit sensitive government data requiring heightened protection. Mixing these diverse environments on a single flat network creates unnecessary risk—a compromised web server shouldn't provide attackers direct access to systems containing defence contract information, yet that's exactly what happens without segmentation.
The CPCSC standard includes multiple requirements related to segmentation, particularly in the System and Communications Protection family. These requirements stem from NIST SP 800-171 control families addressing the architecture principle of defense-in-depth, where multiple layers of security controls protect against threats.
Organizations must meet the following requirements:
Several architectural approaches implement network segmentation effectively:
Each approach has tradeoffs between security granularity, implementation complexity, and operational overhead.
Practical segmentation implementation involves several technical components:
The specific technologies depend on your infrastructure, scale, and budget, but the principles remain consistent.
Remote workers accessing systems that handle specified information create particular segmentation challenges. VPN solutions should terminate remote connections in a dedicated security zone, not directly on the internal network, allowing firewall controls between the VPN segment and specified information systems.
Multi-factor authentication should protect VPN access to verify user identity before granting network access. Split-tunneling (where some traffic routes through VPN and other traffic goes direct to internet) is often discouraged for users accessing specified information, as it creates risk of cross-contamination.
Cloud-based secure access service edge (SASE) or zero-trust network access (ZTNA) solutions provide more granular control, authenticating and authorizing each access request rather than granting broad network access once VPN connects. The goal is ensuring remote access receives the same segmentation benefits and controls as on-premise access.
As contractors increasingly use cloud services, segmentation principles extend to cloud environments through security groups, network security groups, or virtual private clouds (VPCs) that isolate cloud resources logically. Separate cloud accounts or subscriptions for different environments (production, development, specified information, general business) create strong isolation.
Network segmentation within cloud environments separates public-facing services, application tiers, and data storage. Private connectivity between on-premise environments and cloud (AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect) rather than traversing the public internet protects specified information in transit.
Identity-based segmentation supplements network segmentation, as cloud environments often emphasize identity and access controls over traditional network boundaries. Organizations operating hybrid environments spanning on-premise and cloud must extend their segmentation architecture cohesively across both.
Employee-owned devices and mobile devices create segmentation challenges since they're less controlled than corporate assets. Several approaches address these challenges:
For CPCSC purposes, mobile devices accessing specified information should be corporate-controlled rather than personal devices, or should use robust containerization and access controls if BYOD is permitted.
Segmentation is only effective if it's properly maintained over time. Several ongoing activities prevent segmentation erosion:
These ongoing activities prevent segmentation erosion that commonly occurs as operational pressures drive exceptions and shortcuts that gradually undermine the security architecture.
Organizations often fall into segmentation anti-patterns:
Each of these mistakes undermines the defense-in-depth benefits that segmentation is meant to provide.
Implementing network segmentation can impact business processes that previously relied on flat network connectivity. Users accustomed to accessing any system may encounter access restrictions requiring requests and approvals. Applications that communicated freely across the network may require firewall rule changes to maintain functionality.
Management protocols and monitoring tools may need architectural changes to work across segment boundaries. These disruptions are temporary and manageable with good planning, communication, and change management, but they're real and should be anticipated rather than surprising stakeholders.
Network segmentation requires investment in several areas:
For small organizations, basic segmentation using existing firewall and switch capabilities may be achievable with minimal incremental cost. Larger organizations with complex environments may invest substantially in sophisticated segmentation architectures.
The investment is justified by the risk reduction segmentation provides—numerous high-profile breaches were amplified by flat networks that allowed initial compromises to spread unchecked throughout the environment.
Network segmentation is a single layer in a comprehensive security strategy. It works in concert with access controls limiting who can authenticate to systems, endpoint protection detecting and preventing malware, data encryption protecting information even if accessed, security monitoring detecting suspicious activity, and incident response containing and remediating breaches.
No single control is sufficient—defense-in-depth means adversaries must overcome multiple independent security layers to achieve their objectives. Segmentation ensures that even if perimeter defenses fail and adversaries gain initial access, they face additional obstacles before reaching sensitive specified information systems.
The following resources provide additional guidance on network segmentation:
Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.
As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.
Why we're the superior choice:
CPCSC-ready—with proven defense contractor experience guiding every step.
A plurilock representative will contact you within one business day.
Contact Plurilock
+1 (888) 776-9234 (Plurilock)