Your Network Segmentation: Research Highlights Critical Gaps in Security Effectiveness
Your Network Segmentation Is Failing Where It Matters Most, New Research Reveals
Most CISOs believe their networks are properly segmented. A sweeping new study of nearly 50,000 real-world network segments suggests that confidence is dangerously misplaced — especially where the stakes are highest.
Research published by Forescout's Vedere Labs on September 23, 2026, analyzed 47,700 network segments containing more than 2.5 million devices across 209 organizations. The findings expose a critical gap between the appearance of network segmentation and its actual effectiveness around operational technology (OT) and connected medical devices (IoMT). Understanding how network segmentation works as a security control is increasingly essential context for interpreting what this research reveals.
The study, titled What 47,700 Segments Reveal About Network Segmentation, arrives as ransomware groups and hacktivists increasingly exploit poorly isolated IoT devices as pivot points into critical infrastructure. For security teams that have long operated under the assumption that segmentation equals protection, this research delivers an uncomfortable correction.
The Numbers Look Reassuring — Until You Examine What Actually Matters
On the surface, the dataset offers some reassurance. Sixty-two percent of segments contained devices from a single category, and the two most common configurations were IT-only (54%) or IT paired with IoT (26%). For a broad network overview, that picture looks reasonably contained.
The reassurance evaporates once researchers focused on segments housing OT systems and IoMT devices — the equipment running physical industrial processes and patient care environments:
- Only 13% of OT-containing segments are OT-only
- Only 6% of IoMT-containing segments are IoMT-only
- Nearly half of both OT and IoMT segments simultaneously mix in IT and IoT assets
IP cameras emerged as the least isolated device type in the entire dataset. Cameras appeared in 2,266 segments — roughly 5% of the total — yet only 51 of those segments, approximately 2%, contained cameras alone. The remaining camera segments most commonly shared space with:
- Workstations (60%)
- Printers (47%)
- Servers (37%)
The average segment held 54 devices spanning four different device types. Because the average device belonged to 1.5 segments rather than one, the effective blast radius of any single compromised device compounds significantly. Business and professional services, healthcare, and oil and gas carried the largest average blast radii across the dataset.
Why the blast radius metric matters: In practical terms, a blast radius of 54 devices means a single compromised endpoint — including a seemingly inconsequential IP camera — can expose dozens of adjacent assets within the same segment. This figure translates directly into business risk language and can help security teams build the case for micro-segmentation investment at board level.
A Compromised Camera Is Rarely the End Goal
The most dangerous misconception in IoT security is treating device compromise as the incident itself, rather than as the entry point to something far larger.
Forescout grounds its risk assessment in documented incidents rather than hypothetical scenarios. In 2022, Vedere Labs demonstrated how a poorly segmented IP camera could hand ransomware operators a foothold into IT systems. That scenario became operational reality in early 2025 when the Akira ransomware gang reportedly used a compromised webcam to bypass endpoint detection and response (EDR) protections entirely.
By 2026, Forescout reports tracking more than 300 instances of hacktivist groups — including the pro-Russian collective NoName057(16) — seizing control of exposed IP cameras at targeted organizations, with recent campaigns directed at Estonian and Canadian targets. The pattern is consistent: a compromised camera is a pivot point, not a destination. Because most camera segments also contain workstations or servers connected to domain controllers, a seemingly minor IoT compromise can open the door to a much larger breach.
The retail sector illustrates the same problem in a different context. Only 95 of 478 segments containing point-of-sale systems — about 20% — were dedicated to those systems alone. The remainder were commonly paired with printers, VoIP equipment, or IP cameras, which Forescout separately identifies among 2026's riskiest device categories.
The Structural Problem Underneath the Statistics
These are not isolated configuration errors. They reflect a broader architectural reality: most enterprise networks were never designed with OT, IoMT, and IoT isolation as a primary objective. Segmentation was applied as an overlay to existing infrastructure, rather than engineered from the ground up around device risk profiles. The result is a patchwork of segments that appear defined on paper but function as open corridors in practice.
The convergence of IT and OT environments — once physically separate — has accelerated this exposure. As organizations have connected industrial systems to corporate networks for monitoring, remote access, and operational efficiency, they have introduced adjacencies that attackers now exploit systematically. Implementing a zero trust network access strategy is increasingly cited by security architects as the most structurally sound response to exactly this kind of convergence risk.
What Security Leaders Identify as Root Causes — and Fixes
The Inherited Hygiene Gap
John Gallagher, Vice President at Viakoo, describes the problem as an inherited hygiene gap. OT and IoT systems have historically been "managed and maintained by the line-of-business — manufacturing, facilities, physical security" rather than by IT departments, which explains the persistent patterns of unpatched firmware and default credentials. He argues the 13% figure exposes "the illusion of separation" enterprises have been relying on.
Gallagher's recommended approach: treat OT and IoT assets as zero-trust endpoints from deployment — dedicated micro-segments with East-West traffic denied by default, and automated certificate provisioning to keep unverified devices out of sensitive VLANs.
The Funding and Staffing Constraint
Robert Costello, Chief Digital and Information Officer at Merlin Group, adds organizational context to the technical argument. Connected medical, IoT, and OT devices were largely engineered for availability and mission function rather than for today's threat environment. The sectors running the most of these devices — healthcare, utilities, and critical infrastructure — are also the most funding- and staff-constrained.
His recommended approach pairs security engineered into devices from the start with the training, visibility, and affordable tooling IT teams need to enforce least privilege without disrupting patient care or operations.
The Ignored Problem
Agnidipta Sarkar, Chief Evangelist at ColorTokens, is more pointed: "this report highlights what organizations have always known yet have ignored." Sarkar notes that the riskiest OT devices tend to be facilities-owned rather than security-owned, frequently absent from configuration management databases, and reachable from corporate networks because someone wanted a web interface.
His recommended sequence:
- Widen asset definitions to include facilities-owned and unmanaged devices
- Map dependencies rather than devices — understand what connects to what, and why
- Microsegment by operational consequence rather than by architectural level
- Start with bridge devices as an accessible first win before tackling the broader environment
The Uptime-Over-Security Culture
Christopher Hills, Chief Security Strategist at BeyondTrust, ties the finding to OT's long-standing uptime-over-security culture — specifically default credentials that are never rotated and the absence of layered access controls that typically backstop IT environments. Without those foundational controls, he argues, OT systems are "vulnerable right from the start."
Where the Consensus Points
The consensus across all four experts points to the same underlying failure: most environments were never mapped and enforced with OT, IoT, and IoMT treated as high-consequence assets requiring dedicated isolation. Proper VLAN configuration and management represents one foundational element of that isolation strategy — though experts are clear that VLANs alone, without continuous enforcement and monitoring, are insufficient against modern lateral movement techniques.
Forescout's own mitigation guidance calls for:
- Continuous asset visibility across all device categories, including those owned outside IT departments
- Priority attention to convergence zones where IT and OT or medical devices share segments
- Enforcement of least-privilege East-West traffic policies rather than relying on perimeter controls
- Active monitoring for segmentation drift — because networks that were properly segmented a year ago rarely remain that way without ongoing maintenance
The 13% figure serves as a practical gut-check for any security team that has equated having network segments with having genuine isolation. As the ransomware campaigns and hacktivist activity cited in this research make clear, the gap between those two things is precisely where attackers are operating.
Security leaders attending SecureWorld Detroit on September 17, 2026, will have the opportunity to examine these findings in depth alongside peers navigating the same segmentation challenges across critical sectors. The full Forescout Vedere Labs research is available at Forescout's Research Labs for security teams that want to benchmark their own segmentation posture against the dataset.
How you can use this information:
- Audit your convergence zones first. Identify every segment where OT, IoMT, or IoT devices share space with general-purpose IT assets — those are your highest-priority remediation targets before any broader network redesign.
- Use the blast radius metric as a board-level communication tool. The average of 54 devices per segment translates directly into business risk language and can help security teams secure funding for micro-segmentation projects.
- Treat asset inventory as a prerequisite, not a parallel workstream. Forescout's guidance is explicit that you cannot enforce segmentation on devices you have not yet discovered — beginning with a comprehensive, continuous asset visibility program is the non-negotiable first step.