Secure Your Internal Network

Contain threats before they spread.

Network segmentation built to industry standards — so a breach in one area can’t take down everything.

Cyber Essentials Plus certified20 years · Est. 2006130+ organisations supportedFixed monthly pricing
Cyber Essentials Plus certifiedMicrosoft & Fortinet partnerOldham Business Awards 2022 winnerDBS-cleared engineersUK-based helpdesk

Quick answer

Network segmentation splits a flat network into separate, walled-off zones (VLANs) — corporate, guest, IoT and servers — so a breach in one area cannot spread to everything. Foresight IT Services designs and builds segmented internal networks to industry standards for organisations across Greater Manchester and the UK, from £1,500, with least-privilege rules and documented design.

What we cover

Segmentation that limits the blast radius

Separate, controlled zones for the different parts of your network.

VLAN segmentation

Split a flat network into walled-off zones by role and risk.

Guest & IoT isolation

Keep visitor Wi-Fi and smart devices away from core systems.

Server zone protection

Tighter controls and outbound rules around your servers.

Least-privilege rules

Allow only the traffic that’s genuinely needed.

Learn more →

Documented design

A clear, maintained record of how your network is built.

Standards-aligned

Designed to recognised security best practice.

20
years supporting GM business
130+
organisations supported
24/7
monitoring & response
CE+
Cyber Essentials Plus certified
“They feel like our own IT department — quick to respond, and always a step ahead of problems.”
— Illustrative testimonial placeholder
Property Alliance GroupRussell WBHOMoya ColeDr Kershaw’s HospiceKingfisher Learning Trust

Pricing

Project pricing that fits your network

Costed to the size and complexity of your sites.

Pricing

Project pricing that fits your network

Every network is different, so segmentation is scoped and priced to yours — sites, switches, VLANs and devices.

A one-off project — including design, implementation and documentation. Drag to see an indicative price for the size of your network.

Single site
Single siteMediumMulti-site
Indicative project priceFrom £1,500

One location with the core zones — corporate, guest, IoT and servers.

What affects the price: number of sites, switches and VLANs, and the number of devices involved
Any hardware needed (managed switches or a capable firewall) is quoted separately if your current kit doesn’t support segmentation
Ongoing management is available as part of a managed IT support agreement

Prices are a guide, correct at the time of publication (July 2026), exclude VAT and are subject to change. Ask us for a scoped, fixed quote for your network.

FAQs

Your questions, answered

What is network segmentation?
Splitting your network into separate, walled-off zones (VLANs) instead of one big flat network, so devices only reach what they genuinely need to. If one zone is compromised, the problem is contained rather than spreading everywhere.
What is a VLAN?
A VLAN (Virtual Local Area Network) is a way of logically separating one physical network into several isolated networks. Devices on different VLANs can’t talk to each other unless a firewall rule specifically allows it.
Why is a flat network a risk?
On a flat network every device can see every other device. A single infected laptop, a compromised IoT camera or a guest’s phone can then reach your servers, cameras and management systems. Segmentation removes those open paths.
What zones will you create?
Typically a corporate zone for staff and business systems, a locked-down guest network, a segregated IoT/devices zone, a protected server and data zone, and often a separate voice/telephony zone — all tailored to your environment.
Do you really block servers from uploading files out?
Yes. We can apply outbound rules that stop servers initiating file uploads to the internet, so a compromised server can’t be used to quietly exfiltrate your data. Legitimate, approved destinations are allowed by exception.
How are IoT devices handled?
Cameras, sensors, printers, door-entry and other smart devices are placed on their own segregated VLAN with tightly controlled access. They can still do their job, but can’t be used as a stepping stone into your corporate systems.
What about the guest Wi-Fi?
Guests get internet access only, on a fully isolated network. They can’t see your internal systems — or each other — so visitor access stays convenient but harmless.
Can devices still talk across zones when they need to?
Yes, where it’s justified. We use least-privilege firewall rules so only the specific, necessary traffic is allowed between zones — everything else is denied by default.
Will it disrupt our business while you set it up?
We plan the cut-over carefully, usually staging changes and switching over out of hours or in phases, to keep disruption to a minimum.
Do we need new hardware?
It depends on your current kit. Segmentation needs managed switches and a capable firewall. If yours support it, we’ll use what you have; if not, we’ll quote for the necessary equipment as part of the project.
Does this help with Cyber Essentials, ISO 27001 or other compliance?
Yes. Segmentation is a recognised security control and supports the network-security and access-control expectations of Cyber Essentials, ISO 27001 and frameworks such as the NHS DSPT.
How is it priced?
As a one-off project, scoped to the size and complexity of your network — the number of sites, switches, VLANs and devices involved. Projects start from £1,500, excluding VAT.
How long does it take?
A single-site project is often completed within a few days of planning and implementation; larger or multi-site networks take longer. We’ll give you a clear timeline when we scope the work.
Can you manage it for us afterwards?
Yes. We can monitor and maintain the segmented network as part of a managed IT support agreement, including any future changes to rules or zones.
Is it suitable for schools and healthcare?
Very much so — separating curriculum, admin, guest and IoT traffic, or clinical versus corporate systems, is exactly the kind of control these sectors need, and something we do regularly.

Let’s harden your network

Talk to a Greater Manchester team that has looked after growing organisations for 20 years.