Large networks can be secured by separating domains based on trust, criticality, sensitivity, and organizational units. Every domain perimeter should be precisely defined, and organizations should control access between domains with a gateway based on security requirements. WiFi networks needing particular attention, and adjusting radio coverage should be considered for separation. Guest access to WiFi should be distinct from personnel access and have similar restrictions.