SecurityWeek

Only 13% of OT Network Segments Are Fully Isolated: Analysis


Most organizations running operational technology (OT) or connected medical devices do not keep those systems on their own dedicated network segments, according to new research from Forescout’s Vedere Labs. 

The cybersecurity firm’s researchers examined 47,700 network segments holding more than 2.5 million devices across 209 organizations, sorting each device into one of four categories: IT, OT, IoT, or medical (IoMT).

At the surface level, segmentation looks reasonably solid. The researchers found that 62% of segments contained devices from a single category, and the most common setups were IT devices alone (54%) or paired with IoT gear (26%).

However, that picture changes once OT and IoMT devices are isolated for a closer look. Of all segments that included at least one OT device, only 13% consisted of OT devices alone, while the rest shared space with IT or IoT equipment. Segments with medical devices fared worse, with just 6% dedicated solely to IoMT.

IP cameras stood out as the least isolated device type in the dataset. Cameras appeared in 2,266 segments, roughly 5% of the total, and only 51 of those, about 2%, contained cameras exclusively. 

The average segment in the dataset held 54 devices across four different device types, and the average device belonged to 1.5 segments rather than one. Roughly 11% of segments exceeded 51 devices, while 17% were single-device ‘micro-segments’.

Forescout found the largest average blast radius in business and professional services, healthcare, and oil and gas, with utilities, financial services, and retail on the low end. 

Advertisement. Scroll to continue reading.

However, the researchers cautioned that a low industry-wide average can still hide risky pairings around specific high-value systems. In retail, for example, only 95 of 478 segments containing point-of-sale systems, about 20%, were dedicated to POS alone. The rest most often shared space with printers, VoIP equipment or IP cameras.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

Forescout’s recommendations focus on visibility and containment rather than a network redesign. Recommendations include building a full inventory of connected devices, flagging segments where risky device types converge, moving critical OT and IoMT systems off general IT networks, breaking up oversized segments, and restricting unnecessary traffic between segments.

The full report is available on Forescout’s website.

Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Related: Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Related: Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels



Source link