OTSecurity

Forescout finds network convergence across IT, OT, IoT and IoMT could increase lateral movement and cyberattack impact


Forescout’s Vedere Labs analyzed 47,700 network segments containing more than 2.5 million devices across 209 organizations, finding that network segmentation frequently leaves IT, operational technology (OT), IoT and medical devices sharing the same environments. Overall, 62% of segments contained a single device category, while 29% contained two categories and 9% contained three or more. Among segments containing specialized devices, only 13% of those with OT devices were OT-only and 6% of those with IoMT devices were IoMT-only, while almost half included the specialized devices alongside IT and IoT assets. 

The analysis also found that the average network segment contained 54 devices spanning four device types, creating a potential blast radius if one device is compromised. Seventeen percent of segments contained a single device, 72% had between two and 50 devices, and 11% had more than 51 devices. IP cameras were particularly exposed: only 2% of the 2,266 segments containing cameras were camera-only, while 60% also contained workstations, 47% printers and 37% servers. 

“By 2026, we routinely see hacktivist groups gaining control over exposed IP cameras in targeted organizations. We tracked over 300 instances this year, including these examples carried out by the pro-Russian group, NoName057(16), in late August and early September against Estonian and Canadian targets,” according to the researchers. “The initial compromise of an IP camera may seem inconsequential, but organizations need to keep in mind that these cameras are rarely isolated in the corporate network. In our dataset, there were 2,266 segments with IP cameras (almost 5% of all segments). Out of those, only 51 (2%) contained IP cameras only.”

They added that in more than half of the cases where a threat actor compromises an IP camera, an IT workstation or server is present in the same segment. “These IT assets are typically connected to the organization’s domain controller — which can enable lateral movement and a pathway to the most sensitive parts of the organization. Ensuring those cameras are in dedicated network segments can prevent an initial breach from becoming a network-wide incident.”

Forescout said the findings highlight the need for organizations to maintain continuous asset visibility, identify device convergence zones, separate critical operational assets from enterprise IT networks and monitor for segmentation drift. It reported that 62% of the analyzed network segments contained devices from a single category, while 29% contained devices from two categories and 9% contained devices from three or more categories. The analysis found that 54% of network segments contained only IT devices, while 26% contained both IT and IoT devices. A further 4% of segments contained IT, IoT and IoMT devices.

The research revealed that 50% of IoMT network segments contained IoMT, IT and IoT devices, while 23% contained IoMT, IT, IoT and OT devices. Another 15% of IoMT segments contained IoMT and OT devices, while 6% contained only IoMT devices. The remaining segments included combinations of IoMT and IoT at 4%, IoMT, IT and OT at 1%, and IoMT, IoT and OT at 1%.

Among OT network segments, 42% contained OT, IT and IoT devices, while 23% contained OT, IT, IoT and IoMT devices, according to the analysis. A further 12% of OT segments contained only OT devices, while 11% contained OT and IT devices and 10% contained OT and IoT devices. The remaining 2% comprised segments containing OT, IT and IoMT at 1% and OT, IoT and IoMT at 1%.

Interestingly, Vedere Labs reported that on average, each network segment has 54 devices with four different functions. These 54 devices are the ‘blast radius’ of that segment: if one device is compromised, there are Additionally, many devices are part of more than one segment which increases the blast radius even further. On average, each device was part of 1.5 segments in the dataset.

The average does not tell the whole story, as it is heavily influenced by outliers and the industry. The analyzed segments can be divided by the number of devices they contain, including 17% were ‘micro-segments’ with a single device, 72% had between two and 50 devices, and 11% had more than 51 devices.

Business and professional services organizations face the largest average blast radius at 179, significantly exceeding all other sectors measured. Healthcare organizations experience an average blast radius of 116, more than double that of the oil and gas industry at 72. The ‘Other’ category reports an average blast radius of 77, followed by oil and gas at 72. Entertainment organizations face an average blast radius of 48, while manufacturing and government sectors both experience an average blast radius of 29.

Technology sector organizations report an average blast radius of 21, comparable to retail at 20 and financial services at 20. Utilities show the smallest average blast radius among the industries measured at 9.

The researchers noted that even in industries with a lower average blast radius, organizations should pay attention to network segmentation, especially when protecting ‘crown jewels’ assets with sensitive data that are essential to business operations. “For example, point-of-sale (PoS) systems in the retail sector are part of the crown jewels. Yet, out of the 478 segments where a PoS was identified, only 95 (20%) of those were exclusive to PoS.” 

Most common device pairs Forescout saw in segments with PoS were linked with some of the riskiest device types, including 46% with printers, 36% with VoIP devices, and 30% with IP cameras. “Not coincidentally, these are the most common IoT devices overall on organizational networks. IP cameras, in particular, are very relevant in the current threat landscape. Despite retail being part of the second-lowest blast radius of all industries, the pairings to risky device types are where organizations should focus security efforts.”

Commenting on the Forescout data, John Gallagher, vice president at Viakoo, wrote in an emailed statement that OT and IoT systems have often been managed and maintained by the line-of-business, such as manufacturing, facilities, and physical security, and lack IT-level hygiene around network management and cybersecurity. 

“This is another example alongside things like not updating firmware or using default passwords that also are found in OT/IoT systems,” he added. “The Forescout findings highlight a dangerous reality for the enterprise overall: enterprise networks still rely on the illusion of separation. With only 13% of OT segments genuinely isolated, the vast majority share broadcast domains and pathways with IT and peripheral IoT devices like cameras and printers, making them into attack vectors.”

Agnidipta Sarkar, chief evangelist at ColorTokens, wrote that the report highlights what organizations have always known yet have ignored. “Enterprises are taking a significant risk if they don’t plan for the next cyberattack. In 2026, AI-powered attacks are overwhelming cyber defenders with machine-speed attacks. All it needs is a route to reach the OT systems.” 

“This report shows that the riskiest OT devices are owned by facilities rather than the OT security team, are usually absent from the CMDB, are usually outside the ICS vendor’s support contract, and are frequently reachable from the corporate network because someone wanted a web UI,” he added. “Bridge devices have now become targets, and breach exposure is shifting from IT to embedded management access. The need of the hour is to divide the OT environment into zones that contain microsegments, with conduits that can be disconnected the moment a behavior anomaly is noted. OT leaders should consider implementing microsegmentation platforms that cover both IT and OT in a single platform to eliminate gaps in configurations and changes made when IT and OT connect with SaaS and AI.”

“For many years, OT has prioritized uptime over security and threat actors know this, which is why they continue to compromise these OT environments in the way they do,” Christopher Hills, chief security strategist at BeyondTrust, identified. “However, one thing remains: foundational security practices do not need modern security to take basic steps in security.”

Forescout notes that organizations do not need to redesign their entire network architecture overnight to reduce risk. Instead, they can focus on practical actions that limit attack paths and reduce potential blast radius of a compromise.

Organizations should establish comprehensive asset visibility by building and maintaining an accurate inventory of all connected IT, OT, IoT, and IoMT assets. Continuous visibility into what is connected to the network, where devices are located, and how they communicate is foundational to identifying segmentation gaps, prioritizing risk, and reducing potential attack paths.

A critical step involves identifying and prioritizing device convergence zones by locating segments that contain multiple device categories with risky combinations, such as IT and OT, IT and medical, or IT and IoT. These segments often represent high-value attack paths for adversaries.

Furthermore, organizations should separate critical operational assets from enterprise IT networks, ensuring that systems responsible for production, patient care, building operations, or other critical functions are isolated from user workstations and general-purpose IT devices as much as possible.

Reducing oversized network segments is essential, as large environments increase the opportunities for lateral movement. Breaking these environments into smaller, purpose-built segments can significantly limit the impact of a breach. Implementing policy-based access controls between segments ensures devices communicate only with the systems required for their function, and restricting unnecessary east-west network traffic makes it more difficult for attackers to pivot between environments.

Organizations can use asset intelligence to validate segmentation decisions by maintaining accurate and continuous visibility into device types, roles, and behaviors to ensure segmentation policies align with operational requirements. Finally, organizations must continuously monitor for segmentation drift, since networks change over time as new devices are added and business requirements evolve. Regular reviews can identify when previously isolated environments become unintentionally interconnected.



Source link