Particle.news

Forescout Finds Widespread Failures in Network Segmentation

The analysis shows poor isolation of operational and medical devices increases attackers' ability to move laterally.

Overview

  • Forescout Vedere Labs published on Tuesday a large analysis of 47,700 real network segments that covered more than 2.5 million devices across 209 organizations.
  • Only 13% of segments that include operational technology were OT-only and just 6% of segments with medical devices were IoMT-only, showing most critical systems share networks with general IT or IoT.
  • The average network segment held 54 devices and the average device appeared in 1.5 segments, creating large 'blast radii' where compromising one device can put dozens of others at risk.
  • IP cameras were especially poorly isolated, with only about 2% of camera-containing segments holding cameras alone, and Forescout tracked over 300 camera takeovers in 2026 that showed attackers use exposed cameras to reach other systems.
  • Forescout urges practical fixes focused on full asset visibility, flagging convergence zones, moving critical OT/IoMT off general IT, splitting oversized segments, enforcing policy-based inter-segment controls, and continuous monitoring to prevent segmentation drift.