OT Isolation Gap Leaves Devices Exposed
Forescout's Vedere Labs found most OT and medical devices share network segments with IT and IoT gear, widening potential attack paths.
Industrial control systems and connected medical devices often sit on the same network segments as ordinary business IT and consumer-grade IoT gear, according to new analysis from Forescout's Vedere Labs. The finding undercuts a common assumption that operational technology is walled off from the rest of the enterprise. For security teams, the gap between assumed and actual isolation is where incidents begin.
What the researchers examined
Vedere Labs pulled apart 47,700 network segments carrying more than 2.5 million devices across 209 organizations. Each device was sorted into one of four categories: IT, OT, IoT, or medical (IoMT). That categorization let the researchers test whether segments were actually single-purpose or quietly mixed.
At first glance, segmentation looks reasonably solid. The researchers found that 62% of segments contained devices from a single category. The most common arrangements were IT devices alone at 54%, or IT paired with IoT gear at 26%.
That top-line number is where the good news ends. Once OT and IoMT devices were isolated for a closer look, the picture changed sharply.
OT and medical devices share space
Of all segments that included at least one OT device, only 13% consisted of OT devices alone. The rest shared space with IT or IoT equipment. Segments containing medical devices fared worse, with just 6% dedicated solely to IoMT.
In other words, the vast majority of OT and medical deployments in the dataset are not on their own dedicated network segments, despite the common security guidance that they should be. The researchers' data suggests that organizations may believe they have isolated these systems when the segment-level view shows otherwise.
IP cameras stood out as the least isolated device type in the dataset. Cameras appeared in 2,266 segments, roughly 5% of the total, and only 51 of those, about 2%, contained cameras exclusively. The rest shared segments with other device types.
How big and how mixed segments get
The average segment in the dataset held 54 devices across four different device types, and the average device belonged to 1.5 segments rather than one. Roughly 11% of segments exceeded 51 devices, while 17% were single-device 'micro-segments'.
Those figures matter because segment size and device diversity both shape what an attacker can reach after compromising a single host. A segment with 54 devices spanning four categories is a very different containment problem than a micro-segment holding one device.
The researchers also looked at blast radius by industry. They found the largest average blast radius in business and professional services, healthcare, and oil and gas. Utilities, financial services, and retail sat on the low end.
Why averages can mislead
Forescout cautioned that a low industry-wide average can still hide risky pairings around specific high-value systems. Retail is the clearest example in the data. Only 95 of 478 segments containing point-of-sale systems, about 20%, were dedicated to POS alone. The rest most often shared space with printers, VoIP equipment, or IP cameras.
That means a retailer with a favorable overall blast-radius average could still have POS terminals sitting on segments alongside devices that are far harder to patch or monitor. The same logic applies to any industry where a handful of critical systems are surrounded by general-purpose gear.
What Forescout recommends
The firm's recommendations focus on visibility and containment rather than a full network redesign. Among them:
- Build a full inventory of connected devices.
- Flag segments where risky device types converge.
- Move critical OT and IoMT systems off general IT networks.
- Break up oversized segments.
- Restrict unnecessary traffic between segments.
The full report is available on Forescout's website.
Who feels the consequences
The stakes are highest where OT and IoMT devices control physical processes or patient care. A compromised IP camera on a general IT segment is a nuisance; a compromised infusion pump or industrial controller on the same segment is a different category of problem.
For security leaders, the finding is less about a single flaw than about the gap between policy and practice. Segmentation guidance has been standard for years, but the data here suggests that in many organizations, the isolation exists on paper rather than in the network fabric.
Where the data points next
The dataset's scale, spanning 209 organizations and 47,700 segments, gives the analysis weight beyond a single-company case study. The pattern it describes is consistent across device categories: OT, IoMT, and cameras are the least likely to be alone.
What this means for defenders
For defenders, the practical takeaway is to verify isolation rather than assume it. An inventory that maps devices to segments, combined with rules that flag mixed-category segments, would surface the exact conditions the researchers found. Moving critical OT and IoMT systems off general IT networks, and breaking up oversized segments, are steps the researchers say reduce the blast radius if something on the segment is compromised.
The analysis does not name specific victims or incidents, and its findings describe the state of segmentation in the sampled organizations. Still, the gap it documents is one that many security teams may recognize in their own environments, and closing it depends on seeing the network as it is, not as the architecture diagram says it should be.
Sources
- SecurityWeek Original source
- full report Also reporting
Continue Reading
Arista VeloCloud Flaw Exploited, Scores 10.0
Arista says attackers are actively exploiting CVE-2026-93952, a maximum-severity flaw in on-premises VeloCloud Orchestrator setups using certificate authentication.
AI Response Drills Fall Short as Use Grows
ISACA finds that 71% of organizations have not rehearsed for an AI-related security incident, even as AI adoption accelerates.
Google's PQC Roadmap Reshapes Digital Trust
Google's post-quantum cryptography roadmap accelerates a migration to 2029 and introduces Merkle Tree Certificates, pressuring traditional X.509 infrastructure.