I can think of three very good options. First, like you mentioned in your post, access lists. access lists are a great way of minimizing traffic to certain destinations. Second, you could create VLAN's. Meaning, that users from one VLAN would not be able to communicate with users for another VLAN. Third option is to buy PIX. I don't know how large your organization is, but if you consider it to be small-to-medium size business then I would recommend that you buy Cisco PIX 515E which will let you do VLANs. I have a 2610 router which does not have Fast Ethernet so it cannot do VLANs. Find out if your router is VLAN compatible with dot1q.