Breaking
SecurityDeveloping Story

OT Isolation Gap Leaves Devices Exposed

Forescout's Vedere Labs found most OT and medical devices share network segments with IT and IoT gear, widening potential attack paths.

··3 hours ago·4 min read
blue UTP cord
Photo by Jordan Harrison on Unsplash

Industrial control systems and connected medical devices often sit on the same network segments as ordinary business IT and consumer-grade IoT gear, according to new analysis from Forescout's Vedere Labs. The finding undercuts a common assumption that operational technology is walled off from the rest of the enterprise. For security teams, the gap between assumed and actual isolation is where incidents begin.

What the researchers examined

Vedere Labs pulled apart 47,700 network segments carrying more than 2.5 million devices across 209 organizations. Each device was sorted into one of four categories: IT, OT, IoT, or medical (IoMT). That categorization let the researchers test whether segments were actually single-purpose or quietly mixed.

At first glance, segmentation looks reasonably solid. The researchers found that 62% of segments contained devices from a single category. The most common arrangements were IT devices alone at 54%, or IT paired with IoT gear at 26%.

That top-line number is where the good news ends. Once OT and IoMT devices were isolated for a closer look, the picture changed sharply.

OT and medical devices share space

Of all segments that included at least one OT device, only 13% consisted of OT devices alone. The rest shared space with IT or IoT equipment. Segments containing medical devices fared worse, with just 6% dedicated solely to IoMT.

In other words, the vast majority of OT and medical deployments in the dataset are not on their own dedicated network segments, despite the common security guidance that they should be. The researchers' data suggests that organizations may believe they have isolated these systems when the segment-level view shows otherwise.

IP cameras stood out as the least isolated device type in the dataset. Cameras appeared in 2,266 segments, roughly 5% of the total, and only 51 of those, about 2%, contained cameras exclusively. The rest shared segments with other device types.

How big and how mixed segments get

The average segment in the dataset held 54 devices across four different device types, and the average device belonged to 1.5 segments rather than one. Roughly 11% of segments exceeded 51 devices, while 17% were single-device 'micro-segments'.

Those figures matter because segment size and device diversity both shape what an attacker can reach after compromising a single host. A segment with 54 devices spanning four categories is a very different containment problem than a micro-segment holding one device.

The researchers also looked at blast radius by industry. They found the largest average blast radius in business and professional services, healthcare, and oil and gas. Utilities, financial services, and retail sat on the low end.

Why averages can mislead

Forescout cautioned that a low industry-wide average can still hide risky pairings around specific high-value systems. Retail is the clearest example in the data. Only 95 of 478 segments containing point-of-sale systems, about 20%, were dedicated to POS alone. The rest most often shared space with printers, VoIP equipment, or IP cameras.

That means a retailer with a favorable overall blast-radius average could still have POS terminals sitting on segments alongside devices that are far harder to patch or monitor. The same logic applies to any industry where a handful of critical systems are surrounded by general-purpose gear.

What Forescout recommends

The firm's recommendations focus on visibility and containment rather than a full network redesign. Among them:

  • Build a full inventory of connected devices.
  • Flag segments where risky device types converge.
  • Move critical OT and IoMT systems off general IT networks.
  • Break up oversized segments.
  • Restrict unnecessary traffic between segments.

The full report is available on Forescout's website.

Who feels the consequences

The stakes are highest where OT and IoMT devices control physical processes or patient care. A compromised IP camera on a general IT segment is a nuisance; a compromised infusion pump or industrial controller on the same segment is a different category of problem.

For security leaders, the finding is less about a single flaw than about the gap between policy and practice. Segmentation guidance has been standard for years, but the data here suggests that in many organizations, the isolation exists on paper rather than in the network fabric.

Where the data points next

The dataset's scale, spanning 209 organizations and 47,700 segments, gives the analysis weight beyond a single-company case study. The pattern it describes is consistent across device categories: OT, IoMT, and cameras are the least likely to be alone.

What this means for defenders

For defenders, the practical takeaway is to verify isolation rather than assume it. An inventory that maps devices to segments, combined with rules that flag mixed-category segments, would surface the exact conditions the researchers found. Moving critical OT and IoMT systems off general IT networks, and breaking up oversized segments, are steps the researchers say reduce the blast radius if something on the segment is compromised.

The analysis does not name specific victims or incidents, and its findings describe the state of segmentation in the sampled organizations. Still, the gap it documents is one that many security teams may recognize in their own environments, and closing it depends on seeing the network as it is, not as the architecture diagram says it should be.

#ot security#network segmentation#forescout#iot#iomt

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories