惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
B
Blog RSS Feed
A
About on SuperTechFans
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 司徒正美
D
Docker
F
Fortinet All Blogs
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
H
Help Net Security
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
博客园 - Franky
人人都是产品经理
人人都是产品经理
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements
Using LAN ZeroTrust for segmentation
Zach DeMeyer · 2026-01-09 · via Todyl Blog

Although remote work remains prominent, the local network is crucial in hybrid and in-office models as well as the at-home office. It is also a prime target for attackers once they have gained initial access to an organization.

Organizations must implement segmentation practices to reduce blast radius and limit lateral movement to protect internal network-bound assets. Using LAN ZeroTrust, you can easily microsegment the local network and improve your security posture.

Setting the stage for network segmentation

In a traditional perimeter-bound network model, the internal network contains all traffic and key resources for an organization. Users within the network have full access to said resources, and traffic originating from outside the network is barred from entry without a VPN or other ports.

With the rise of work-from-anywhere models and SaaS apps, the concept of the perimeter-bound network is dying off. That said, the principles it was built around remain pertinent. Many organizations rely on their internal network to house critical infrastructure and data. So, keeping the internal network secure is paramount.

Unlike the days of the network perimeter, however, few if any users are connected directly to the internal network. This means it can be accessed by anyone with a set of credentials. And, given the rise of phishing attacks and other methods for gaining initial access, accessing internal networks is surprisingly easier than it once was.

Why network segmentation?

Understanding this, network segmentation provides a method for limiting the effects of intrusions into internal networks. With network segmentation, the internal network is separated into smaller segments that contain specific users and resources. Users are only granted access to their specific segment and the resources within, unable to move between segments without express authorization.

In this way, network segmentation operates off the principle of least privilege, a cornerstone of Zero Trust Network Access (ZTNA). Least privilege is predicated on the concept that users are only granted the bare minimum access they need to effectively perform their duties—no more and no less.

With network segmentation, an authenticated user identity is only authorized access to their specific segment. Segmenting the network through this ZTNA approach has multiple benefits that result in a better security posture for the organization.

Limiting lateral movement

Primarily, network segmentation limits a bad actor’s ability to move horizontally within the network. If they are using a stolen set of credentials or an insider threat, they cannot gain access to any network segments or affect any resources they do not have access to. They are instead confined within the segment and unable to spread to other parts of the network.

Host isolation / Quarantining

In addition, network segmentation helps organizations address potential threats by isolating potentially infected hosts. If a system is infected with malware or another virus, it can only be spread to other devices within its segment. Putting the device within its own segment limits that spread even further, allowing for safe examination and remediation of the security threat.

Compliance

Many compliance regulations such as HIPAA or PCI DSS require that sensitive data and systems be in dedicated, protected environments. Organizations can easily create these areas easily through network segmentation, minimizing access and increasing security. Doing so helps with adhering to compliance requirements and keeping customer and employee data safe from prying eyes.

How LAN ZeroTrust enables network segmentation

Understanding the importance of network segmentation, organizations can use LAN ZeroTrust to implement it across their internal network. LAN ZeroTrust, a module within the Todyl Platform, leverages a deny-by-default design that helps organizations implement network segmentation. In a sense, this architecture microsegments network resources, putting up blockers that prevent all traffic to the resource unless explicitly granted by an administrator.

In practice, LAN ZeroTrust restricts all unauthorized access to internal network resources, relying on identity in a true ZTNA fashion. This makes it ideal for internal network-reliant businesses to scale and improve their security posture.

Learn more

You can see the power of LAN ZeroTrust in action today. Click here to book a free demo and learn how you can use network segmentation to better your business.

About Zach DeMeyer

Zach DeMeyer is Todyl's Product Marketing Specialist, sharing the story of how businesses can use the Todyl platform to consolidate their security operations with SASE, SIEM, MXDR, Endpoint, SOAR, and more. He loves being on the forefront of new and exciting technologies, spending the past 8 years working in identity, UCaaS, and other SaaS products in the cybersecurity and IT software space. When he's not working, Zach enjoys camping and hiking with his wife, dog, and friends, playing music, sewing, and eating tasty food.