Education

Network Segmentation for Enterprise

Network segmentation is a critical architectural strategy for modern enterprises, dividing a computer network into smaller, isolated segments to enhance security, improve performance, and simplify compliance. In Indonesia, where digital transformation accelerates across industries such as manufacturing, finance, and logistics, the need for robust network segmentation has never been more pressing. By implementing VLANs, subnets, and firewall policies, organizations can contain cyber threats, reduce the attack surface, and ensure sensitive data remains protected. For instance, a manufacturing company in Bekasi can isolate its OT (Operational Technology) network from IT systems to prevent ransomware from disrupting production lines. Similarly, a financial institution in Jakarta can segment customer data from internal administrative traffic to meet regulatory requirements like POJK. Key technologies include Cisco's Catalyst switches for VLAN deployment, Fortinet's FortiGate firewalls for policy enforcement, and Ruijie's switches for cost-effective segmentation in branch offices. Proper segmentation also enables granular access control, reduces broadcast traffic, and improves network performance by limiting unnecessary data flows. Without segmentation, a single compromised endpoint can lead to lateral movement across the entire network, as seen in many high-profile breaches. Enterprises in Indonesia must prioritize network segmentation as part of their cybersecurity strategy, integrating it with networking solutions from trusted vendors. This approach not only safeguards critical assets but also supports business continuity and scalability. As organizations adopt hybrid cloud and IoT, segmentation becomes even more vital to manage complexity and ensure secure connectivity. Intilogy helps Indonesian enterprises design and implement segmented networks tailored to their specific operational needs, leveraging best practices and leading technologies.

Client: Confidential Education client

01

Client Profile & Background

A multinational manufacturing company with factories in Bekasi and Surabaya, employing over 5,000 staff across production, R&D, and administrative departments. The company operates a converged IT/OT network with over 500 devices, including PLCs, SCADA systems, and enterprise servers. They handle sensitive intellectual property and comply with ISO 27001 standards. Their existing network infrastructure consisted of flat Layer 2 switching from multiple vendors, lacking any segmentation between departments or between IT and OT environments.

02

Technical Challenge

The flat network architecture posed severe security risks: a single malware infection in the administrative LAN could propagate to production PLCs, causing 8-hour downtime per incident. In the past year, they experienced three ransomware attempts, each requiring 24-hour recovery. Additionally, broadcast storms from the R&D department's high-traffic applications degraded performance for critical SCADA systems, leading to 15% production inefficiency. Compliance audits revealed 12 non-conformities due to lack of network isolation. They needed to segment over 200 VLANs without disrupting ongoing operations.

03

Implemented Solution

Intilogy designed a multi-layered segmentation architecture using Cisco Catalyst 9300 switches at the core and distribution layers, implementing 802.1Q VLAN tagging for 250 logical segments. Fortinet FortiGate 600E firewalls were deployed for inter-VLAN routing with stateful inspection, enforcing least-privilege policies. OT networks were isolated using Ruijie RG-S2928G switches with private VLANs to prevent lateral movement. The solution integrated with existing VMware NSX for micro-segmentation in the virtualized server environment. All segmentation rules were automated via Microsoft System Center for consistent policy enforcement. The project was executed over 12 weekends to minimize downtime.

04

Results & ROI

Post-implementation, the attack surface reduced by 90%: no lateral movement from IT to OT was possible, eliminating ransomware propagation risk. Broadcast traffic dropped by 70%, improving SCADA response times by 40%. Compliance audit passed with zero non-conformities. The company achieved a 3-month ROI through avoided downtime costs estimated at IDR 2 billion per incident. Network performance improved, enabling a 20% increase in production throughput. The solution also simplified troubleshooting, reducing mean time to resolution (MTTR) from 4 hours to 30 minutes. Future scalability is ensured with support for up to 1,000 VLANs.

Catalog SKUs relevant to this project — shown only when published on the site.

Need a quotation or IT solution recommendation?

Send a short brief — our team will follow up on BoQ, sourcing, and implementation steps.

WhatsApp Consult on WhatsApp
Request Consultation WhatsApp