Imagine your company network as a large office complex. If a burglar gets through the front door, can he then simply get into every department, office or confidential document? Ideally not, because there are hopefully locked doors, access controls and specially protected areas. This is precisely the idea behind segmentation. Areas are demarcated in the network and protected separately so that attackers cannot simply move freely around the system and act as they please.