Network Segmentation Planner
Plan network segmentation strategies for zero trust architecture.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Turn a flat network into defensible zones
A flat network where everything can reach everything is the reason a single compromised laptop becomes a company-wide breach. Segmentation limits how far an intruder can move, but planning it is daunting. This tool helps you plan segmentation for a zero-trust approach based on your organisation type, network scale and specifics like whether you offer guest access.
Segmentation follows the compliance and risk you carry
What the segments should be depends on what you are protecting. A retailer handling card data has PCI-DSS boundaries to draw; a healthcare provider has patient data to isolate; an industrial site must keep control systems away from the office network. Taking your organisation type and scale as input, the planner suggests a segmentation shaped around the obligations and risks that actually apply, rather than a generic diagram.
A starting architecture, not a finished design
The output is a considered starting point: the zones worth having, why they exist, and how traffic between them should be controlled. It gives an architecture conversation something concrete to react to, which is far easier than starting from a blank page. The planning runs in your browser, so your organisational details are not uploaded.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
Why segment a network at all?
To limit lateral movement. In a flat network a single compromised device can reach everything; segmentation contains an intruder to one zone and forces them to cross controlled boundaries.
How does my industry affect the plan?
Different sectors carry different obligations: PCI-DSS for card data, HIPAA for healthcare, and control-system isolation for industrial sites. The suggested zones are shaped around the rules and risks that apply to you.
What is zero trust in this context?
An approach where no zone is implicitly trusted and traffic between segments is authenticated and authorised rather than allowed by default because it is internal.
Is the output a finished design?
No. It is a considered starting architecture to react to and refine, which is much easier than planning segmentation from a blank page.
Are my organisation details uploaded?
No. The planning runs entirely in your browser.
Privacy & Security
Planning done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.