Network segmentation is not just about physical and logical separation of your network elements, but also accounts, permissions, applications, files, and services that your enterprise relies on daily.  Begin with a current assessment of your environment.  Get the right people using the right tools to help map it out.  Ask why X talks to Y, if it should, and how to do so securely.  Update your diagrams and documentation, keeping them dynamic to match the evolving infrastructure.  Separating the elements from each other can mitigate the amount of damage caused deliberately or accidentally.  Test all configurations and use change controls.

