Incomplete network segmentation across IT, OT, IoT and medical networks is quietly enlarging the blast radius of corporate breaches, new data from Forescout warns.[1][2] Researchers at the company’s Vedere Labs say that as diverse device types are clustered together on shared segments, a single compromised asset increasingly serves as a launchpad for lateral movement into critical systems.[1][2]
Forescout’s latest analysis of real-world networks found that nearly half of segments containing operational technology or connected medical devices also host IT and IoT assets, creating dense “convergence zones” where attackers can pivot quickly once they gain any foothold.[1][2] Of all segments that included at least one OT device, only 13% were fully isolated to OT, while segments with medical devices fared even worse, with just 6% dedicated solely to IoMT equipment.[2][14] The study also observed that an average network segment held 54 devices spanning four different device types, and that the typical device appeared in 1.5 segments, further complicating efforts to contain compromise.[2]
The risk is especially pronounced around IP cameras and similar IoT endpoints that often share segments with workstations and servers, effectively bridging edge devices directly into the corporate network.[1][2] Forescout has previously demonstrated how poorly segmented cameras can be abused by ransomware operators, and reported that in early 2025 the Akira ransomware group used this kind of access to bypass endpoint detection and response controls and move deeper into victim environments.[1] By 2026, the company was routinely observing hacktivist groups gaining control of exposed cameras inside targeted organizations, turning misconfigured segments into surveillance and access channels for disruptive activity.[1]
The findings underscore what Forescout describes as the “illusion of segmentation”: policy built on incomplete device visibility, where security teams believe zones are isolated but in reality lack accurate maps of which assets communicate and over which ports and protocols.[3][10] In its risk-aware segmentation guidance, the company notes that IoT asset exploits rose to 19% of observed incidents in 2025, tied with network infrastructure as the second-largest exploit category, while average device risk per country climbed 33% year over year.[3] Flat or under-segmented networks, Forescout warns, allow threats to move freely across IT, OT and IoT domains, expanding exposure as organizations bring more connected devices online.[7][13]
Rather than calling for wholesale network redesigns, Forescout’s recommendations focus on visibility, containment and policy enforcement at scale.[1][2] The company urges security teams to build and maintain a continuous inventory of all connected assets, identify and prioritize segments where risky device categories converge, and separate critical OT and medical systems from general IT networks wherever possible.[1][2] Oversized segments with dozens of heterogeneous devices should be broken into smaller, purpose-built zones, with policy-based access controls ensuring that each device can only communicate with the systems required for its function.[1][2][13]
Forescout also stresses the need to monitor for segmentation drift as networks evolve, and to pair segmentation with Zero Trust-style enforcement so that every boundary meaningfully increases attacker costs.[3][5] Asset intelligence on device types, roles and behaviors can be used to validate segmentation decisions and assess potential blast radius for critical assets, turning segmentation from a static network design exercise into a dynamic risk management control.[3][6][13] For enterprises facing growing ransomware pressure and rapid adoption of connected OT and IoMT, the message is clear: without accurate visibility and rigorous segmentation, the corporate attack surface will continue to expand in ways that are difficult to detect and even harder to contain.[1][2][7]
References
- Network Segmentation Failures Expand the Corporate Attack Surface
- Only 13% of OT Network Segments Are Fully Isolated: Analysis
- Risk-Aware Network Segmentation for the Hybrid Enterprise
- Frontier AI Readiness Resource Center
- The Forescout Continuum Platform Solution Brief | Forescout
- Network Segmentation Cybersecurity Software Solutions
- Forescout eyeSegment
- Accelerate Enterprise-Wide Network Segmentation with eyeSegment
- Only 13% of OT Network Segments Are Fully Isolated: Analysis