Back to blog
VLAN • 3 min read10 June 2026

Network Segmentation: Why POS Terminals, Cameras and Accounting Don't Belong Together

VLAN segmentation is the cheapest security measure with the biggest impact, and most small networks don't have it. Here's how it works.

Picture a building with no interior walls and no doors: whoever gets through the entrance has reached everything. That's exactly what most small business networks look like, one switch, one router, and every device in the same "room": employee computers, POS terminals, cameras, printers, the smart TV in the meeting room and guests' phones.

While everything works, nobody notices the problem. It becomes visible the day any one of those devices is compromised, because on a flat network, one infected device sees all the others.

The weakest link decides for everyone

The security of a flat network isn't the security of your strongest device. It's the security of your weakest. And the weakest is usually the one nobody thinks about: an IP camera with 2019 firmware, a printer with a default password, an air-conditioner with a Wi-Fi module. Such devices rarely get updates, and for attackers they make a perfect foothold, a quiet spot from which to explore the network for weeks.

VLANs: walls and doors inside the network

Segmentation divides the network into logical zones, VLANs, using equipment you probably already own or that isn't expensive. A typical layout for a small company: employees in one zone, business servers in another, cameras and other "smart" devices in a third, POS terminals in a fourth, guests in a fifth.

Between the zones sits a firewall with clear rules: POS terminals talk only to their server, cameras only to the recorder, guests only to the internet. If an attacker takes over a camera, they stay trapped in the camera zone. There's simply no path to accounting.

A bonus that's often forgotten: segmentation helps with perfectly ordinary problems too. A chatty device flooding the network, an addressing conflict, a guest's laptop spreading something nasty. It all stays in its zone instead of taking down the whole company.

How big a job is it?

Smaller than it sounds. For a typical small company it's a project of a few days: mapping the current state, planning the zones, configuring switches and the firewall, and migrating devices in a controlled way: without downtime. Hardware with VLAN support is standard today even in the affordable price range.

Of all security measures, segmentation may have the best ratio of effort to payoff: a one-time intervention that permanently changes what a single incident can, and cannot. Become.

Get in touch
MSS IT | Network Segmentation: Why POS Terminals, Cameras and Accounting Don't Belong Together