Skip to content

Cybersecurity flat network

The Flat Network Problem

When I connect to a customer's guest Wi-Fi as part of an assessment, I run a LAN scan to show them exactly what is visible to anyone who walks through the door. What shows up would surprise most business owners - and your guest Wi-Fi may be putting a stranger on the same road as your payroll server.

Illustration for the article: The Flat Network Problem
When I connect to a customer's guest Wi-Fi as part of an assessment, I run a LAN scan to show them exactly what is visible to anyone who walks through the door. What shows up would surprise most business owners - and your guest Wi-Fi may be putting a stranger on the same road as your payroll server.

Let me paint you a picture of what a hacker actually looks like.

It is not the guy in the corner of the coffee shop with the black hoodie, typing 150 words a minute on a laptop while he sips a latte. That person does not exist outside of movies. Nobody is dramatically hunched over a keyboard in a public place looking suspicious while they breach your network.

Here is who it actually is.

It is a college student in a tech program who just learned how to do a packet capture in class this week. It is someone at the hotel down the street who is bored and curious and downloaded a free tool that shows them every device on the network. It is someone looking to make a fast buck in any way they can, with just enough knowledge to be dangerous and just enough time on their hands to go looking.

I know this because I see it in the field.

When I connect to a customer’s guest Wi-Fi as part of an assessment – with their knowledge and permission – I run a LAN scan to show them exactly what is visible on the network they are offering to anyone who walks through the door. Not changing anything. Not accessing anything. Just looking at what is already exposed. And what shows up would surprise most business owners. Printers. Cameras. Workstations. Management interfaces with web portals. Point-of-sale terminals. Devices that were never meant to be visible to a customer sitting in the waiting room with a free Wi-Fi password.

If I can find all of that as part of a professional assessment, imagine what someone with actual intent can do with the same free tool and ten minutes of curiosity.

The Username and Password Problem

When I tell a business owner that their guest Wi-Fi and their payroll server are on the same network, the reaction is almost always the same.

“So what? The server has a username and password. They do not have it.”

This is a reasonable thing to believe. It is also wrong in a way that matters.

A username and password is one layer of protection. And it is a layer that can be attacked, guessed, phished, or bypassed in ways that have nothing to do with knowing the credentials in advance. But more importantly – being on the same network as a device means you can see it, probe it, test it, and look for weaknesses in it. You do not need the password to start that process. You just need to be on the same network.

And in a flat network – a network where everything is connected to everything else with no walls between them – being on the guest Wi-Fi puts you on the same road as the billing system, the payroll server, the file server, and every other device the business depends on.

The password is the lock on the door. A flat network means anyone can walk up to that door and start trying keys.

Also – We Do Not Live in a Place Where Things Happen

I hear this one a lot too.

“We live in an area where things like that just do not happen.”

I understand why people say this. And in terms of physical crime, maybe they are right. But a network attack does not require anyone to be physically near you. The college student who just learned packet monitoring does not have to be in your town. The person looking to make a fast buck does not have to know your business exists. They are scanning ranges of IP addresses looking for open doors, and geography has nothing to do with whether your door shows up in their results.

The internet does not have a small-town filter.

The Highway, the Frontage Road, and the Guard Shack

Here is how I explain network segmentation to a business owner without losing them in technical language.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

Think about a highway. That is your main production network – the road where the real traffic moves. Your servers, your workstations, your business systems. That is the highway.

Now think about a frontage road running alongside it. That is where your accounting department lives, or your HR systems, or any other sensitive function that needs its own lane. You can get there from the highway, but not directly. You have to take an exit, and before you can get onto that frontage road there is a guard shack. You have to show your ID. You have to be authorized to be there. Not everyone who is on the highway gets onto the frontage road – only the people who are supposed to be there.

Now someone comes into your business and wants to use the free Wi-Fi. That is fine. You built them an overpass. It goes in the same general direction as the production network – they can get where they are going – but it does not connect to the highway below. It does not cross the frontage road. I can see the traffic on that overpass and I can see the devices using it, but they never mix into the core network. They are on a one-lane road with no street lights, going exactly where I want them to go and nowhere else.

That is network segmentation. That is what a VLAN does. It builds the walls that a flat network is missing.

What a Flat Network Actually Looks Like

A flat network has no walls. Everything is on the same road. The guest who connected to your Wi-Fi to check their email is technically on the same network segment as your point-of-sale system, your file server, and your domain controller.

They probably cannot access those things. Probably.

But they can see them. They can probe them. And if there is a vulnerability anywhere in that environment – an unpatched system, a weak password, an open port that nobody knew was open – someone on that guest network has a path to it.

This is not theoretical. This is how real incidents happen. Not through dramatic Hollywood hacking but through basic network reconnaissance done by someone with free time, a free tool, and a connection to your guest Wi-Fi.

The fix is not complicated. It is a conversation about architecture – about building the highway and the frontage road and the overpass and the guard shack before something goes wrong instead of after.

The Question Worth Asking Your IT Provider

If you have a managed service provider or an internal IT team, ask them this question:

Is our guest Wi-Fi on a separate network segment from our production systems?

If the answer is yes – great. Ask them to show you the documentation.

If the answer is “I think so” or “it should be” or anything other than a confident yes with evidence – you have a flat network problem worth addressing.

The guard shack does not build itself. But once it is built, you stop worrying about who is on the highway.

Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.

Key Takeaways

  • It is not the hooded hacker in the coffee shop — it is a college student who just learned packet monitoring this week
  • A flat network means anyone can walk up to your server door and start trying keys
  • The internet does not have a small-town filter
  • Network segmentation builds the walls a flat network is missing
  • The guard shack does not build itself — but once it is built you stop worrying about who is on the highway