87% of OT Networks Lack Proper Isolation, Enabling Lateral Movement
Forescout Vedere Labs found that only 13% of OT network segments are properly isolated, meaning the vast majority of critical operational technology environments share network space with IT and IoT devices. This flat or poorly segmented architecture dramatically increases the blast radius of any initial compromise, allowing attackers to move laterally from a low-value IT asset to safety-critical OT or medical systems. The convergence of IT and OT without compensating security controls is a well-known risk that continues to be systematically underaddressed. This matters because OT and medical device compromises can have physical, safety, and life-threatening consequences far beyond typical data breaches.
Tactical Insight
Immediate actions
- Conduct a full network asset discovery to identify all OT, IT, IoT, and medical devices and map which segments they currently occupy.
- Apply emergency VLAN or firewall rules to isolate the most critical OT assets (e.g., PLCs, SCADA controllers, medical devices) from general IT traffic.
Long-term improvements
- Design and enforce a formal OT network segmentation architecture using the Purdue Model or IEC 62443 zones-and-conduits approach.
- Implement unidirectional security gateways or data diodes between IT and OT zones to enforce strict communication boundaries.
- Establish a formal change management process ensuring no new device can join an OT segment without security review and approval.
Detection measures
- Deploy OT-aware network monitoring tools (e.g., Claroty, Dragos, or Forescout) to detect anomalous cross-segment communication in real time.
- Set up alerts for any IT or IoT device that appears in a segment designated for OT assets, triggering an immediate investigation workflow.