VLAN is an acronym that a company director often hears from their IT supplier without fully understanding what it means or why they should care. Yet, it represents one of the simplest and most effective ways to secure a corporate network, requiring no additional cabling or new equipment.
Without this separation, the company network tends to be "flat" - all devices, from computers and cameras to printers, can see each other because they are technically on the same network. For normal operation this is not an issue until something fails or someone misuses the network; then a problem that should have remained isolated to one device can easily spread further. Segmentation using VLANs prevents this spread without requiring any changes to the physical cabling.
What VLAN means in a nutshell
VLAN (Virtual Local Area Network) is a method of dividing one physical network into several separate networks without the need to run separate cables for each. Devices connected to the same switch can thus be "logically" in completely different networks that do not see each other unless explicitly permitted by the administrator. For a company, this is mainly advantageous financially and practically: a single cabling system can handle operations that would otherwise require a separate network infrastructure.
Why separate the camera system
Cameras and recording devices typically communicate over a network and are often among the least secure elements in a building, manufacturers frequently do not deploy updates as often as they do for computers. If cameras share the same network as company computers, an attacker who gains access through a vulnerability in a camera can proceed to more sensitive systems. A separate network isolates this risk, even if something happens on the camera side, the rest of the company network remains out of reach.
Why separate IoT devices
IoT (Internet of Things) commonly includes printers, time clocks, smart thermostats or connected coffee machines in companies, devices that no one perceives as a security risk but which are often just as vulnerable as cameras. The same logic applies here: a separate network means that a weakness in one smart device does not endanger the rest of the infrastructure.
Why separate the guest network
A visitor, supplier or client in the meeting room needs internet access, not access to corporate data. A guest network on a separate VLAN allows visitors to connect to WiFi without any route to internal systems, shared drives or printers containing sensitive documents. This separation is usually the first thing companies address, as the risk is most visible, foreign devices on the same network as corporate data. How a guest network is correctly designed from both coverage and WiFi perspectives is described in our article about design of a corporate WiFi network.
Why separate accounting and sensitive data
The same principle works in reverse for the most sensitive company data, accounting, payroll or internal documentation. Even within your own company, it may not be desirable for every computer to have network access to these systems. A separate network for the accounting department limits the range of devices from which the data can be accessed, even if something happens elsewhere in the network.
How this is handled in practice
The good news is that VLANs do not require new cabling or separate switches for each network, switches that support VLANs are sufficient (essentially any enterprise-grade, not home, devices), along with correct configuration-level settings. Physically, the same network infrastructure remains in the building; it is only logically divided according to what needs to communicate with what and what does not. Configuration is a one-time task for the network administrator, after which operation proceeds without further intervention.
In practice, this means that every device: a switch port or a WiFi access point, is assigned to a specific VLAN based on its function. A camera is connected to the "camera" VLAN, a company computer to the "internal" VLAN, and a guest laptop to the "guest" VLAN, and so on. The firewall then controls what individual VLANs are permitted to communicate with each other: typically ensuring that the guest network has no access to anything other than the internet.
Summary
VLAN is a tool to separate cameras, IoT devices, guests and sensitive data from each other, without new cabling, just by correctly configuring the existing network. For managing directors, the main message is simple: it is a cheap and effective measure against a problem in one part of the network spreading to the whole company.