New research from Forescout Vedere Labs has found that critical operational and medical devices are frequently sharing network segments with IT and IoT assets, potentially giving attackers more opportunities to move laterally following an initial compromise.
The cybersecurity research team analysed 47,700 real-world network segments containing more than 2.5 million devices across 209 organisations. Devices were divided into four categories, IT, operational technology (OT), IoT and Internet of Medical Things (IoMT), as well as 327 individual device functions.
While 62% of the segments analysed contained devices from a single category, the picture changed significantly when researchers looked specifically at specialist OT and medical equipment.
Just 13% of segments containing OT devices were OT-only, falling to only 6% for segments containing IoMT equipment. In almost half of both types of segment, specialist devices were operating alongside IT and IoT assets. Network segmentation is intended to restrict unnecessary communication between systems and limit an attacker’s ability to move through an organisation following a compromise. Mixing different device types can create unintended pathways between assets that would ideally be isolated.
One Compromised Device, 53 Others at Risk
Forescout’s analysis also looked at the potential “blast radius” created by individual network segments and found that the average segment contained 54 devices across four different device functions. Forescout said this means that, in a typical segment, compromising one device could potentially put another 53 devices in the same segment at risk.
Around 17% of those analysed were micro-segments containing a single device, while 72% contained between two and 50 devices. A further 11% contained more than 51. Business and professional services, healthcare and oil and gas recorded the largest average blast radii.
Researchers also found that half of the device functions most commonly appearing in mixed segments featured in Forescout’s list of the riskiest connected devices of 2026. These included IP cameras, programmable logic controllers, building automation controllers, patient monitors and infusion pumps.
IP Cameras Highlight Lateral Movement Risk
IP cameras provide a particularly striking example of the problem. Researchers identified 2,266 segments containing IP cameras, representing almost 5% of all segments analysed. However, only 51, or 2%, contained IP cameras alone. Instead, 60% of those segments also contained workstations, 47% contained printers and 37% contained servers. According to Forescout, this means that in more than half of cases where an attacker compromises an IP camera, an IT workstation or server is present within the same segment.
The research points to similar concerns in retail environments. Of 478 segments containing point-of-sale systems, just 20% were exclusive to PoS devices. Printers appeared alongside PoS systems in 46% of cases, VoIP devices in 36% and IP cameras in 30%.
Segmentation Needs to Create Security Boundaries
Forescout said organisations do not necessarily need to redesign their networks completely to address the problem.
Instead, security teams should identify segments where different device categories converge, particularly combinations of IT with OT, medical or IoT assets. Critical operational systems should be separated from general-purpose IT wherever possible, while oversized segments can be broken into smaller environments to limit lateral movement.
The researchers also recommend policy-based access controls between segments and continuous monitoring for “segmentation drift”, where changes to devices and business requirements gradually result in previously isolated environments becoming interconnected. The findings underline that simply dividing a network into segments does not necessarily provide effective isolation. The security value comes from creating meaningful boundaries between systems so that compromising one device does not provide an easy route to the rest of the organisation.
Read the full research blog here: https://www.forescout.com/blog/what-47700-segments-reveal-about-network-segmentation/

