Network segmentation
Dividing a network into zones with controlled traffic between them, so a compromise in one does not reach the others.
A flat network means anything that lands on a reception PC can reach the server, the backup appliance, and the cameras. Segmentation forces an attacker through choke points where they can be filtered and observed.
The highest-value separations for most businesses are backup infrastructure, building systems and IoT, guest wireless, and any regulated workload with its own compliance boundary.
Where this comes up
Network segmentation sits inside our networks and infrastructure work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.