Summary
New dependencies, inherited access, vendor connectivity, network address reuse and shared management platforms can gradually introduce communication paths that were not part of the original design. Over time, organisations may settle into recurring arrangements that appear workable but no longer provide the intended logical separation between systems and business functions. This publication describes these arrangements as anti-patterns: repeated but ineffective responses to common network security problems. It examines five selected anti-patterns: treating the approved design as the live environment treating network location as trusted allowing shared management paths to undermine intended separation treating controlled reachability as controlled risk treating the ability to change policy as rapid containment These anti-patterns are not exhaustive or prioritised. Together, they examine whether organisations understand their current network state, limit inherited trust and shared management reach, recognise the limits of reachability controls and can enforce containment when required.