Back to Feed
IoT/OTSep 22, 2026

Only 13% of OT Network Segments Are Fully Isolated: Analysis

Forescout research reveals only 13% of OT network segments are fully isolated from IT/IoT devices.

Summary

Forescout's Vedere Labs analyzed over 2.5 million devices across 209 organizations and found that most operational technology (OT) and medical devices are not isolated on their own network segments. Only 13% of OT segments and 6% of medical device segments were exclusively dedicated to those device types, with the rest sharing space with IT or IoT equipment. The research highlights a significant lack of network segmentation, increasing the potential blast radius of cyberattacks.

Full text

Most organizations running operational technology (OT) or connected medical devices do not keep those systems on their own dedicated network segments, according to new research from Forescout’s Vedere Labs. The cybersecurity firm’s researchers examined 47,700 network segments holding more than 2.5 million devices across 209 organizations, sorting each device into one of four categories: IT, OT, IoT, or medical (IoMT). At the surface level, segmentation looks reasonably solid. The researchers found that 62% of segments contained devices from a single category, and the most common setups were IT devices alone (54%) or paired with IoT gear (26%). However, that picture changes once OT and IoMT devices are isolated for a closer look. Of all segments that included at least one OT device, only 13% consisted of OT devices alone, while the rest shared space with IT or IoT equipment. Segments with medical devices fared worse, with just 6% dedicated solely to IoMT. IP cameras stood out as the least isolated device type in the dataset. Cameras appeared in 2,266 segments, roughly 5% of the total, and only 51 of those, about 2%, contained cameras exclusively. The average segment in the dataset held 54 devices across four different device types, and the average device belonged to 1.5 segments rather than one. Roughly 11% of segments exceeded 51 devices, while 17% were single-device ‘micro-segments’. Forescout found the largest average blast radius in business and professional services, healthcare, and oil and gas, with utilities, financial services, and retail on the low end. Advertisement. Scroll to continue reading. However, the researchers cautioned that a low industry-wide average can still hide risky pairings around specific high-value systems. In retail, for example, only 95 of 478 segments containing point-of-sale systems, about 20%, were dedicated to POS alone. The rest most often shared space with printers, VoIP equipment or IP cameras. Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference Forescout’s recommendations focus on visibility and containment rather than a network redesign. Recommendations include building a full inventory of connected devices, flagging segments where risky device types converge, moving critical OT and IoMT systems off general IT networks, breaking up oversized segments, and restricting unnecessary traffic between segments. The full report is available on Forescout’s website. Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems Related: Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows Related: Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Dragos Completes NetRise and runZero Acquisitions Following Accenture DealRust Team Members and Popular Crate Owners Targeted via Video CallsColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsGoogle Confirms Gemini AI Breached Three FirmsAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code23 Million User Records Compromised in Gyazo Data Breach Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsCheck Point, Kaspersky, Tanium Patch Product Vulnerabilities Latest News Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeUS Proposes AI Incident Alert System in Talks With China, Bessent SaysGoogle Hit With $463 Million Fine for EU Location Data Rule BreachFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Vedere Labs (product)Forescout (vendor)OT (technology)IoT (technology)IoMT (technology)