Most small businesses don't need a bespoke network — they need a proven blueprint adapted to their trade. A hotel, a clinic, and a professional office share 80% of the design and differ in the 20% that matters. These are the reference architectures: the segments, the edge, and the trade-specific twist for each, distilled from real builds.
Reference architectures exist so you're not designing from a blank page every time. Almost every small-business network is the same skeleton — a right-sized collapsed-core, a dual-WAN edge, and a segmentation plan of half a dozen zones — and the craft is knowing which zones and policies each trade actually needs. A hotel lives or dies on guest Wi-Fi and PMS isolation; a clinic on protecting patient records and medical devices; an office on staff productivity and a couple of published services. Same bones, different emphasis.
Below are three blueprints, each as the zone set + the edge + the one thing that trade must get right. They generalise the hotel build and audit field notes into reusable designs — start from the closest blueprint, then adapt, rather than inventing each time.
01
Start every SMB from the same base and adapt. If you can build this cleanly, you can build 90% of small-business networks.
| Element | Baseline |
|---|---|
| Topology | Collapsed-core, redundant L3 pair for anything critical |
| Edge | Dual-WAN (fibre + LTE/Starlink), path-following NAT |
| Core zones | Guest · Staff · Servers · CCTV/IoT · VoIP · Management |
| Inter-zone policy | Default-deny; guest = internet-only; CCTV = no internet |
| Wireless | VLAN-per-SSID, guest client-isolation, WPA3 |
| Ops baseline | Backups, off-box logging, OOB, a one-page runbook |
02
Guest experience is the product and the biggest attack surface. The build lives and dies on guest Wi-Fi that's fast, fair, and walled off from the business.
Zones as the skeleton, with guest as the star: room + lobby guest Wi-Fi on a generous subnet with client isolation and per-room fairness so one streamer doesn't starve the rest; a PMS/POS zone (card + passport data) that guests must never reach — the headline finding in every hospitality audit; CCTV recorded on-prem with no internet; VoIP at reception, priority-queued. The edge needs real failover because a full house with dead Wi-Fi is a reputation problem — fibre primary, Starlink/LTE backup. The one thing to get right: prove, from the guest network, that the PMS and cameras are unreachable — segmentation you've tested from the wrong side, not assumed.
03
Patient data and medical devices dominate. The design is about protecting records (GDPR/regulatory) and isolating devices that can't be patched — with uptime that's clinical, not just commercial.
The clinic reuses the skeleton but re-weights it around sensitive data and fragile devices: a tightly-controlled records/EMR zone (regulated data — the perimeter and access controls matter more here, and a screened subnet may be justified); a medical-device zone for imaging/lab kit that often runs unpatched, ancient OSes and must be isolated from both the internet and general staff — treat it like hostile IoT; a staff/clinical zone; and guest Wi-Fi for the waiting room, fully separated. Uptime carries real weight (booking, records access during clinic hours), so the redundant core and dual-WAN aren't optional. The one thing to get right: isolate the un-patchable medical devices — they're the softest target and the highest-consequence pivot.
04
Accounting firm, law office, agency. Fewer exotic zones, more emphasis on staff productivity, secure remote access, and a couple of published services.
The office is the leanest: staff (the bulk), servers (file/app), a small guest/visitor Wi-Fi, VoIP, and management. The distinctive needs are secure remote access (hybrid staff — IKEv2/SSTP road-warrior terminating in a controlled zone, not on the LAN) and often a published service or two (a portal, a mail server) that belong in a DMZ, not on the internal network. Data sensitivity is real (client files, legal/financial records) so backups and segmentation still matter, but the topology is simple — a clean collapsed-core, dual-WAN, and disciplined remote access covers it.
| Trade | The one thing to get right |
|---|---|
| Hotel | Guest Wi-Fi fast & fair, PMS/CCTV proven unreachable from it |
| Clinic | Isolate un-patchable medical devices; protect regulated records |
| Office | Secure remote access + a DMZ for anything published |
Takeaways
NOCTIS designs and deploys right-sized, proven network architectures for small businesses across Crete — segmented, resilient, and documented — adapted from real builds, not invented from scratch on your budget.
Book a Discovery Call →