Network segmentation
Small zones, small problems.
The network is divided into separate zones. If one is compromised, the trouble stays there.
A flat network is like an open-plan office with one front door. Get past the door and you can walk anywhere. Segmentation adds internal doors.
The idea is that each part of the platform sits in its own zone and can talk only to the parts it needs. The line between operational and office systems is the most important of those doors.
Zones limit where traffic can go. Zero trust then checks every request that is allowed through.