The Australian Signals Directorate has released two new resources on network segmentation and segregation that are worth reviewing across IT, OT, critical infrastructure, and other complex environments.
Network segmentation is one of Gate 15’s 15 from 15 cybersecurity fundamentals for a reason: separate what should not talk, control what must, and build an architecture you can support.
ASD’s new Network segmentation and segregation – Overview takes the issue beyond simply deploying firewalls or creating network zones. ASD emphasizes segmentation and segregation as foundational elements of modern defensible architecture and Zero Trust, helping organizations constrain lateral movement, reduce the blast radius of compromise, improve visibility, protect critical systems, and rapidly isolate affected environments during an incident. Network segmentation and segregation – Overview.
Just as importantly, ASD released Network segmentation and segregation – Anti-patterns, focused on how segmentation can fail over time. Networks change. Dependencies accumulate. Vendors receive access. Management platforms become shared. Temporary configurations become permanent. The result can be an environment that looks segmented on an architecture diagram but contains communication paths and inherited trust relationships that undermine the intended separation. Network segmentation and segregation – Anti-patterns.
The takeaway: Do not just ask whether your network is segmented. Ask whether the segmentation you designed is still the segmentation you actually have—and whether you have tested that it will contain an adversary when it matters.
That means understanding critical assets and dependencies, controlling authorized communications, continuously validating trust boundaries, monitoring traffic across those boundaries, and testing the ability to isolate critical systems without creating unacceptable operational disruption.
This is exactly the kind of blocking and tackling highlighted in Gate 15’s 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals. Network Segmentation is one of the 15 fundamentals, alongside Assess, Security Stack, Patching, Planning, Test, Exercise, and other foundational practices that collectively strengthen organizational resilience.
The complete 15 from 15 white paper is now available, with practical recommendations, current government guidance, and real-world examples for each of the fifteen fundamentals. 15 from 15: Blocking and Tackling Cybersecurity & Resilience — including access to the white paper.
Action: Share ASD’s guidance with your network, security, architecture, and resilience teams. Then ask one question: When did we last validate that our actual network segmentation matches our intended architecture—and test whether we can rapidly isolate our most critical systems during a compromise?
Cyber and all-hazards risk and resilience. At Gate 15 we apply a threat-informed & risk-based approach to analysis, resilience, & operations, helping to secure America’s People, Places, Data, & Dollars. Learn more at www.gate15.global. Join Gate 15’s Resilience and Intelligence Portal (GRIP) and connect to our homeland security community. Join the GRIP!
Additional Info
- ASD: Network segmentation and segregation – Overview
- ASD: Network segmentation and segregation – Anti-patterns
- Gate 15: 15 from 15: Blocking and Tackling Cybersecurity & Resilience (link to white paper)

Understand the Threats.
Assess the Risks.
Take Action.