HomeRisk ManagementsNetwork Segmentation Failures Widen the Corporate Attack Surface

Network Segmentation Failures Widen the Corporate Attack Surface

Published on

spot_img

In a recent analysis conducted by Forescout, a significant security concern regarding network segmentation has emerged, revealing the vulnerabilities associated with a mix of operational technology (OT) and medical devices, known as the Internet of Medical Things (IoMT). The study highlights that nearly half of the network segments housing OT or IoMT devices also encompass information technology (IT) and Internet of Things (IoT) devices. This juxtaposition broadens the potential attack surface and escalates the risk of lateral movement within corporate networks.

Forescout’s comprehensive report, titled What 47,700 Segments Reveal About Network Segmentation, draws on an extensive analysis of 47,700 real-world network segments from various organizations spanning multiple industries. The findings shed light on the complexity and challenges of managing network security in environments where diverse devices coexist.

According to the report, the average network segment comprises 54 devices, categorized into four types: IT, OT, IoT, and IoMT. Notably, over 60% of these segments contain merely one category of device. However, a substantial 29% host two different categories, while nearly 10% are home to three or more categories. Alarmingly, a quarter of these mixed segments consist of both IT and IoT devices. In contrast, only 13% of the segments featuring OT devices contain OT only, and a mere 6% are exclusive to IoMT devices.

The implications of these findings are significant. Forescout emphasizes that many of the device types commonly found in mixed segments fall within a category identified as the riskiest devices of 2026. For instance, only 2% of segments containing Internet Protocol (IP) cameras contain solely those devices. The report reveals that IP cameras frequently share segments with workstations and servers, creating a situation where a single compromised device might provide a gateway into the larger corporate network.

This concern is far from hypothetical; Forescout has previously demonstrated real-world scenarios where inadequately segmented IP cameras were exploited by ransomware groups. An illustrative case occurred in early 2025 when the Akira group utilized this method to circumvent Endpoint Detection and Response (EDR) systems. The report indicates that by 2026, the organization expects to routinely observe hacktivist groups compromising exposed IP cameras across targeted organizations, underlining the urgency of addressing segmentation weaknesses.

Forescout’s analysis reveals a troubling trend, citing that over 300 incidents have been tracked this year, including notable attacks executed by the pro-Russian group NoName057(16) against targets in Estonia and Canada in late August and early September. These incidents further underscore the critical nature of addressing the security risks posed by mixed device segments.

To address the potential threats and reinforce network security, Forescout has provided several recommendations for security teams. These include establishing and maintaining continuous visibility of all connected assets, with a focus on creating an accurate inventory of devices and understanding their locations and communication links. Additionally, prioritizing “device convergence zones,” which refer to segments featuring multiple device categories with potentially risky combinations, is essential.

Security teams are also urged to separate crucial operational assets from enterprise IT networks. Reducing oversized network segments, which may contain dozens of devices, into smaller, purpose-built segments is another vital strategy to mitigate risks. Furthermore, implementing policy-based access controls between segments can ensure that devices are only permitted to communicate with the systems necessary for their respective functions.

The utilization of asset intelligence to comprehend device types, roles, and behaviors further validates segmentation decisions. Finally, Forescout stresses the importance of continuously monitoring for segmentation drift, recognizing that networks evolve over time as new devices are introduced and business requirements shift.

In conclusion, Forescout’s report serves as a critical reminder that flat network architectures can facilitate the spread of breaches to critical systems that should remain isolated. The assurance that diverse device types can coexist without adequate segmentation can lead to dire consequences when a single asset is compromised. By proactively addressing these vulnerabilities through strategic segmentation and monitoring, organizations can enhance their cybersecurity posture and safeguard their vital systems against emerging threats.

Source link

Latest articles

Aembit Introduces Support for Okta Cross App Access, Expanding Enterprise Identity Controls to AI Agents

Silver Spring, Maryland, USA, September 22nd, 2026 - CyberNewswire Aembit, a leading identity and access...

Proofpoint Addresses Attacks Traditional Defenses Overlook in the AI Era

Proofpoint Unveils Innovative Agentic Collaboration Security System to Combat Cyber Threats SUNNYVALE, Calif. and Proofpoint...

Beware of Fake Websites Selling AI Assistant Subscriptions

In a recent report by cybersecurity company Malwarebytes, a concerning trend has emerged regarding...

Dubai Introduces Open-Source AI for Deepfake Detection

Cybersecurity Regulator Unveils Advanced AI Model to Combat Deepfakes with 91% Accuracy In a significant...

More like this

Aembit Introduces Support for Okta Cross App Access, Expanding Enterprise Identity Controls to AI Agents

Silver Spring, Maryland, USA, September 22nd, 2026 - CyberNewswire Aembit, a leading identity and access...

Proofpoint Addresses Attacks Traditional Defenses Overlook in the AI Era

Proofpoint Unveils Innovative Agentic Collaboration Security System to Combat Cyber Threats SUNNYVALE, Calif. and Proofpoint...

Beware of Fake Websites Selling AI Assistant Subscriptions

In a recent report by cybersecurity company Malwarebytes, a concerning trend has emerged regarding...