Untrusted Network
An untrusted network is any network that an organization does not control or manage directly, and which is therefore treated as potentially insecure. Because data crossing such a network could be intercepted or altered by malicious parties, connections to and from it require added protections. Common examples include the public internet and other external networks outside an organization's secured internal environment.
An untrusted network is a network segment or connection external to the boundaries an organization manages and secures, and which is assumed to carry a risk of interception, modification, or malicious traffic. In practice it is any network outside the defined trust boundary of the internal environment, most commonly the public internet, and traffic between trusted and untrusted networks is typically mediated by controls such as firewalls, segmentation, and encryption. The designation is a risk-based control assumption rather than an assertion about a specific technology; whether a given network is treated as trusted or untrusted, and the controls required at that boundary, depend on the organization's architecture, segmentation decisions, and applicable requirements, which should be confirmed against the current published standard governing the environment.
Why it matters
The concept of an untrusted network underpins much of network security architecture and PCI DSS boundary controls. Because data crossing an untrusted network such as the public internet could be intercepted or altered by malicious parties, the designation forces organizations to apply protections at the trust boundary rather than assuming traffic is safe by default. Treating the wrong network as trusted, or failing to enforce controls at the boundary between trusted and untrusted zones, can expose cardholder data and other sensitive information to interception or manipulation.
In payment environments, the distinction matters because it drives where controls like firewalls, segmentation, and encryption of transmitted data are required. Cardholder data transmitted across an untrusted network is typically expected to be protected with strong cryptography, while sensitive authentication data must not be stored after authorization regardless of the network it traverses. The specific requirements applicable to transmission across untrusted networks differ between PCI DSS versions in numbering and wording, so readers should confirm the applicable controls against the current published standard governing their environment.
Because the untrusted designation is a risk-based control assumption rather than a statement about a particular technology, the same physical network can be treated as trusted or untrusted depending on architecture and segmentation decisions. Misjudging this boundary is a common source of scope and control gaps; the correct classification depends on the organization's architecture, not on the label alone.
Who it's relevant to
Inside Untrusted Network
Common questions
Answers to the questions practitioners most commonly ask about Untrusted Network.