VYPR
researchPublished Sep 22, 2026· 1 source

Forescout Research Reveals Widespread Lack of OT Network Isolation

New analysis from Forescout's Vedere Labs indicates that only 13% of operational technology (OT) network segments are fully isolated, posing significant cybersecurity risks across various industries.

A comprehensive study by Forescout's Vedere Labs has uncovered a critical gap in cybersecurity defenses for operational technology (OT) environments, revealing that a vast majority of organizations fail to adequately segment these sensitive networks. The research, which analyzed over 2.5 million devices across 47,700 network segments in 209 organizations, found that only a mere 13% of segments containing OT devices were exclusively dedicated to them. The remaining segments were found to be shared with IT or Internet of Things (IoT) devices, creating a significantly expanded attack surface.

While initial observations suggested a degree of network segmentation, with 62% of segments containing devices from a single category, a deeper dive into OT and medical (IoMT) environments painted a more concerning picture. For OT devices, the situation was dire, with only 13% of segments being OT-only. Medical device segments fared even worse, with just 6% dedicated solely to IoMT devices. This lack of isolation means that vulnerabilities or compromises in IT or IoT systems can more easily cascade into critical OT and medical infrastructure.

The research also highlighted specific device types that are particularly prone to being part of poorly segmented networks. IP cameras, commonly found in industrial and enterprise settings, were identified as the least isolated device type. They appeared in approximately 5% of all segments, but only about 2% of those segments contained cameras exclusively, indicating they are frequently co-located with other, potentially more critical, systems.

The study further detailed the complexity of these network environments, noting that the average segment contained 54 devices and that devices often spanned multiple segments. This interconnectedness, coupled with the lack of strict isolation for OT and IoMT, increases the potential 'blast radius' of a security incident. Forescout identified business and professional services, healthcare, and oil and gas as sectors with the largest average blast radius, underscoring the critical nature of these findings for industries reliant on continuous operational uptime and patient safety.

Even within sectors that might appear to have better segmentation on average, risky configurations can still exist. For instance, in the retail sector, while 20% of segments containing point-of-sale (POS) systems were dedicated solely to POS devices, the majority shared space with less secure devices like printers, VoIP equipment, or IP cameras, potentially exposing sensitive transaction data.

In response to these findings, Forescout recommends a strategic approach focused on enhancing visibility and containment rather than mandating a complete network overhaul. Key recommendations include establishing a comprehensive inventory of all connected devices, identifying and flagging segments where high-risk device types converge, migrating critical OT and IoMT systems to dedicated networks, breaking down overly large segments, and implementing strict traffic controls between segments to limit lateral movement.

The report emphasizes that achieving robust cybersecurity for OT and IoMT environments requires a proactive and layered defense strategy. By improving network visibility and implementing effective containment measures, organizations can better protect their critical infrastructure from the ever-evolving threat landscape.

Synthesized by Vypr AI
Forescout Research Reveals Widespread Lack of OT Network Isolation · VYPR