All insights
Cyber & risk·11 min

Network design security for large enterprises: beyond the perimeter

How to design, segment and operate a secure enterprise network that supports zero trust, resilience and Australian regulatory expectations.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory3 August 2026

Why network design is a board-level issue

A large enterprise network is no longer a single boundary around a trusted interior. It is a mesh of cloud workloads, SaaS tenants, remote endpoints, operational technology, supplier connections and mobile devices. The design decisions made five or ten years ago — flat subnets, implicit trust inside the perimeter, privileged access for anything on the LAN — now magnify every other security control failure.

When a ransomware actor moves from a phishing inbox to a domain controller in minutes, the issue is rarely the endpoint tool alone. It is the absence of segmentation, the over-collection of privileges, and the network topology that treats every connected asset as equally trustworthy. Network design is therefore a risk architecture question, not only an engineering one.

The case against perimeter-only thinking

Perimeter defence still matters: internet-facing controls, secure DNS, DDoS protection and ingress inspection are necessary. But they are not sufficient. An attacker who compromises a valid identity, a misconfigured cloud integration or a trusted supplier connection has already bypassed the perimeter.

The alternative is not to abandon the perimeter; it is to add controls that assume breach. Every session, device and user should reach only the resources it genuinely needs, and only under conditions the organisation can verify. That is the practical core of zero trust architecture.

Start with what the network carries

Before drawing new boundaries, catalogue the critical services, data classes, regulated information and operational technology that depend on the network. A payment gateway, a manufacturing control system, a hospital patient record environment and a public marketing website have completely different resilience, isolation and monitoring requirements.

Map traffic flows between those assets, the identities that access them, and the paths an attacker could use to move between them. This mapping is tedious and often resisted, but it is the basis of every sensible segmentation decision.

Segmentation that limits blast radius

Network segmentation is the practice of dividing the environment into zones and controlling traffic between them. In a large enterprise, the goal is not perfect micro-segmentation everywhere; it is to place the strongest boundaries around the highest-consequence assets and to make lateral movement costly.

Common zones include user access, server estates, development and test, production workloads, database tiers, backup infrastructure, operational technology, guest or contractor access, and third-party connections. Each zone should have explicit allow rules, default-deny posture, and logging that makes traversal visible.

For operational technology and critical infrastructure, segmentation is often a regulatory expectation under the SOCI Act and related sector rules. Even where it is not mandated, it is the control that keeps an IT incident from becoming a physical or safety incident.

Zero trust: verify every session

Zero trust is sometimes misunderstood as a product category. It is better understood as a design principle: never trust, always verify, and enforce least privilege. NIST SP 800-207 describes an architecture that uses strong identity verification, device health, least-privilege access and continuous monitoring rather than network location as the basis for trust.

In practice, this means identity-aware proxies, conditional access, just-in-time elevation, short-lived credentials and per-application authorisation. It also means accepting that a device on the corporate Wi-Fi has no automatic right to reach internal systems.

Identity, devices and the new edge

The modern edge is wherever a user, device or service connects. That makes identity the most important control point. Multi-factor authentication, phishing-resistant credentials, privileged access management and lifecycle management for service accounts are network controls in a zero-trust model.

Device health matters too. A managed, patched, encrypted endpoint with attestation should receive different access to an unmanaged personal device. This is particularly important for executives, administrators and anyone with access to production or sensitive data zones.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

Visibility and detection

A well-designed network produces telemetry. DNS queries, authentication events, flow logs, proxy logs, endpoint activity and cloud network traffic should feed a detection capability that can spot anomalous movement, not just known signatures.

The value of detection is proportional to the response it triggers. Large enterprises should design their network so that alerts lead to containment actions: isolate a host, revoke a session, block an identity or quarantine a segment. Detection without response is an audit log, not a control.

Resilience under pressure

Resilience is the ability to maintain or recover critical services during an attack. Network design supports resilience through redundant paths, out-of-band management, immutable backups, clearly defined recovery zones and the ability to isolate affected segments without shutting down the entire enterprise.

Test these capabilities before they are needed. Tabletop exercises, purple-team simulations and controlled failover tests reveal whether the design actually works or merely looks good on a diagram.

Australian regulatory context

Australian enterprises must align network design with the ACSC Essential Eight, sector-specific requirements such as APRA CPS 234 for regulated entities, and the security obligations under the SOCI Act for critical infrastructure. The Essential Eight maturity model explicitly asks organisations to restrict administrative privileges, patch operating systems and applications, and configure Microsoft Office macros and application controls — all of which depend on network and asset visibility.

For organisations handling personal information, network design also supports the Privacy Act security safeguard. A breach that spreads because of flat topology and excessive access becomes harder to defend when the regulator asks what reasonable steps were taken.

A 90-day design review sequence

Days 1 to 30 — establish the truth. Inventory critical assets, data classes, identities, traffic flows and current segmentation. Identify the highest-consequence paths an attacker could use and the controls that currently exist.

Days 31 to 60 — design the priority zones. Define segmentation for the highest-risk environments first: production, operational technology, privileged access and regulated data. Choose identity and access controls that enforce least privilege and just-in-time elevation.

Days 61 to 90 — pilot, measure and govern. Implement one high-value segment, validate that legitimate traffic still flows, test detection and response, and document the decision model. Then expand zone by zone rather than attempting a big-bang redesign of the entire enterprise.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.