Back to blog

Architecture  ·  Design  ·  July 2026

Network Architecture
SMB Reference Designs

Most small businesses don't need a bespoke network — they need a proven blueprint adapted to their trade. A hotel, a clinic, and a professional office share 80% of the design and differ in the 20% that matters. These are the reference architectures: the segments, the edge, and the trade-specific twist for each, distilled from real builds.

Architecture SMB Reference Design Hospitality Healthcare

Reference architectures exist so you're not designing from a blank page every time. Almost every small-business network is the same skeleton — a right-sized collapsed-core, a dual-WAN edge, and a segmentation plan of half a dozen zones — and the craft is knowing which zones and policies each trade actually needs. A hotel lives or dies on guest Wi-Fi and PMS isolation; a clinic on protecting patient records and medical devices; an office on staff productivity and a couple of published services. Same bones, different emphasis.

Below are three blueprints, each as the zone set + the edge + the one thing that trade must get right. They generalise the hotel build and audit field notes into reusable designs — start from the closest blueprint, then adapt, rather than inventing each time.

Reads alongside

01

The Common Skeleton

Start every SMB from the same base and adapt. If you can build this cleanly, you can build 90% of small-business networks.

ElementBaseline
TopologyCollapsed-core, redundant L3 pair for anything critical
EdgeDual-WAN (fibre + LTE/Starlink), path-following NAT
Core zonesGuest · Staff · Servers · CCTV/IoT · VoIP · Management
Inter-zone policyDefault-deny; guest = internet-only; CCTV = no internet
WirelessVLAN-per-SSID, guest client-isolation, WPA3
Ops baselineBackups, off-box logging, OOB, a one-page runbook

02

Blueprint: The Hotel

Guest experience is the product and the biggest attack surface. The build lives and dies on guest Wi-Fi that's fast, fair, and walled off from the business.

Zones as the skeleton, with guest as the star: room + lobby guest Wi-Fi on a generous subnet with client isolation and per-room fairness so one streamer doesn't starve the rest; a PMS/POS zone (card + passport data) that guests must never reach — the headline finding in every hospitality audit; CCTV recorded on-prem with no internet; VoIP at reception, priority-queued. The edge needs real failover because a full house with dead Wi-Fi is a reputation problem — fibre primary, Starlink/LTE backup. The one thing to get right: prove, from the guest network, that the PMS and cameras are unreachable — segmentation you've tested from the wrong side, not assumed.

03

Blueprint: The Clinic

Patient data and medical devices dominate. The design is about protecting records (GDPR/regulatory) and isolating devices that can't be patched — with uptime that's clinical, not just commercial.

The clinic reuses the skeleton but re-weights it around sensitive data and fragile devices: a tightly-controlled records/EMR zone (regulated data — the perimeter and access controls matter more here, and a screened subnet may be justified); a medical-device zone for imaging/lab kit that often runs unpatched, ancient OSes and must be isolated from both the internet and general staff — treat it like hostile IoT; a staff/clinical zone; and guest Wi-Fi for the waiting room, fully separated. Uptime carries real weight (booking, records access during clinic hours), so the redundant core and dual-WAN aren't optional. The one thing to get right: isolate the un-patchable medical devices — they're the softest target and the highest-consequence pivot.

04

Blueprint: The Professional Office Reference

Accounting firm, law office, agency. Fewer exotic zones, more emphasis on staff productivity, secure remote access, and a couple of published services.

The office is the leanest: staff (the bulk), servers (file/app), a small guest/visitor Wi-Fi, VoIP, and management. The distinctive needs are secure remote access (hybrid staff — IKEv2/SSTP road-warrior terminating in a controlled zone, not on the LAN) and often a published service or two (a portal, a mail server) that belong in a DMZ, not on the internal network. Data sensitivity is real (client files, legal/financial records) so backups and segmentation still matter, but the topology is simple — a clean collapsed-core, dual-WAN, and disciplined remote access covers it.

TradeThe one thing to get right
HotelGuest Wi-Fi fast & fair, PMS/CCTV proven unreachable from it
ClinicIsolate un-patchable medical devices; protect regulated records
OfficeSecure remote access + a DMZ for anything published

Takeaways

  1. Don't design SMBs from a blank page — start from a reference blueprint and adapt the 20% that's trade-specific.
  2. The common skeleton — right-sized collapsed-core, dual-WAN edge, six default-deny zones, VLAN-per-SSID wireless, and an ops baseline — covers 90% of small businesses.
  3. Hotel: guest Wi-Fi is the product and the attack surface; prove PMS/CCTV are unreachable from it.
  4. Clinic: isolate un-patchable medical devices and protect regulated records; uptime is clinical.
  5. Office: lean zones, but nail secure remote access and put published services in a DMZ.
  6. Same bones, different emphasis — knowing which zones and policies each trade needs is the craft.

Building or rebuilding a network for a hotel, clinic, or office in Crete?

NOCTIS designs and deploys right-sized, proven network architectures for small businesses across Crete — segmented, resilient, and documented — adapted from real builds, not invented from scratch on your budget.

Book a Discovery Call →