VYPR
researchPublished Sep 22, 2026· 1 source

Network Segmentation Failures Expose Organizations to Increased Attack Surface

Forescout analysis reveals nearly half of network segments containing OT or IoMT devices also include IT and IoT, creating pathways for lateral movement and expanding the attack surface.

A recent analysis by security vendor Forescout has uncovered a significant vulnerability in modern network architectures: the widespread failure to properly segment networks. The study, which examined 47,700 real-world network segments across various industries, found that nearly half of segments containing Operational Technology (OT) or Internet of Medical Things (IoMT) devices also host Information Technology (IT) and Internet of Things (IoT) devices. This convergence dramatically broadens the attack surface and increases the risk of attackers achieving lateral movement within an organization's infrastructure.

The report, titled 'What 47,700 Segments Reveal About Network Segmentation,' highlights that the average network segment contains 54 devices spanning four primary categories: IT, OT, IoT, and IoMT. While a majority of segments (62%) contained only one device category, a substantial portion exhibited mixed device types. Specifically, 29% contained two categories, and a concerning 9% included three or more distinct device types. This mixing is particularly prevalent in segments housing OT and IoMT devices, with only 13% of OT segments being OT-only and a mere 6% of IoMT segments being exclusively for medical devices.

Forescout points out that many of the device types most frequently found in these mixed segments are also among the riskiest. For instance, IP cameras, often found sharing segments with critical workstations and servers, were present in only 2% of segments that contained *just* IP cameras. This proximity means that a single compromised IP camera, a common entry point for attackers, can serve as a direct pathway into the core corporate network. This is not a hypothetical scenario; Forescout has previously documented how poorly segmented IP cameras have been exploited by ransomware gangs, such as the Akira group, to bypass endpoint detection and response (EDR) systems.

The implications of these segmentation failures are severe. The report notes that by 2026, hacktivist groups are increasingly observed gaining control over exposed IP cameras in targeted organizations, with over 300 instances tracked in the year leading up to the report's publication. These attacks, including those attributed to the pro-Russian group NoName057(16) against Estonian and Canadian targets, underscore the real-world threat posed by insecure network segmentation. The ability for attackers to move laterally from a seemingly innocuous device like a camera to critical systems can have devastating consequences.

To address these critical issues, Forescout urges security teams to implement a multi-faceted approach to network segmentation. Key recommendations include establishing and maintaining continuous visibility of all connected assets, accurately inventorying devices, and understanding their locations and communication patterns. Organizations should prioritize identifying and segmenting "device convergence zones," especially those with risky combinations of device types. Furthermore, critical operational assets must be strictly separated from enterprise IT networks.

Forescout also advises reducing the size of overly large network segments, breaking them down into smaller, purpose-built segments to limit the blast radius of any potential breach. Implementing policy-based access controls between these segments is crucial, ensuring that devices can only communicate with the systems strictly necessary for their function. Continuous monitoring for "segmentation drift" is also essential, as networks are dynamic and can evolve over time, potentially reintroducing vulnerabilities if not actively managed.

Ultimately, the report serves as a stark warning: "Flat networks allow breaches to spread to critical systems that should not be reachable." When diverse device types are grouped without appropriate segmentation, the compromise of a single asset can have consequences far beyond its initial scope. The findings emphasize the urgent need for organizations to re-evaluate and strengthen their network segmentation strategies to protect against the expanding attack surface and the increasing sophistication of threat actors.

Synthesized by Vypr AI
Network Segmentation Failures Expose Organizations to Increased Attack Surface · VYPR