Recent research conducted by Forescout Vedere Labs reveals significant security vulnerabilities involving operational and medical devices sharing network segments with IT and IoT assets. This convergence raises concerns that attackers could exploit these connections to move laterally within organizations after an initial compromise.
The cybersecurity team at Forescout meticulously analyzed 47,700 real-world network segments, which collectively housed over 2.5 million devices spread across 209 organizations. In the study, devices were classified into four critical categories: IT, operational technology (OT), Internet of Things (IoT), and the Internet of Medical Things (IoMT). Researchers also scrutinized 327 individual device functions to gain comprehensive insights into network configurations.
While the analysis found that a substantial 62% of the segments analyzed contained devices from a single category, the landscape shifted dramatically when specialists focused specifically on OT and medical equipment. Alarmingly, only 13% of segments containing OT devices were dedicated entirely to OT, with the figure plummeting to a mere 6% for segments housing IoMT equipment. In nearly half of the segments evaluated, specialized devices coexisted with IT and IoT assets. Such mixing contradicts the goal of network segmentation, which is designed to limit unwanted communication between disparate systems and thereby restrict the avenues available for an attacker to traverse an organization after a breach.
The Implications of Compromise
Forescout further explored the potential "blast radius" resulting from vulnerabilities within these mixed segments. Their findings indicated that the average network segment contained approximately 54 devices across four distinct functions. In such configurations, compromising just one device could place an additional 53 devices at risk within that same segment. Approximately 17% of the segments analyzed were identified as micro-segments containing a single device, while the majority—72%—contained between two and 50 devices. An additional 11% had more than 51 devices. Notably, sectors such as business and professional services, healthcare, and oil and gas exhibited the largest average blast radii.
The research also spotlighted that half of the device functions appearing in mixed segments were listed among Forescout’s riskiest connected devices projected for 2026. Key devices included IP cameras, programmable logic controllers, building automation controllers, patient monitors, and infusion pumps, all of which pose significant risks.
Case Study: The Lurking Dangers of IP Cameras
IP cameras emerge as a compelling case study within this context. Researchers identified a total of 2,266 segments that included IP cameras, representing almost 5% of the segments under scrutiny. Alarmingly, only 51 of these segments, or 2%, contained IP cameras in isolation. More troubling is the fact that 60% of the segments featuring IP cameras also included workstations, 47% had printers, and 37% contained servers. This data suggests that in over half of the instances, if an attacker were to compromise an IP camera, they would also gain access to an IT workstation or server located within the same segment.
The research underscored comparable risks in retail environments. Among 478 segments housing point-of-sale (PoS) systems, only 20% were composed entirely of PoS devices. Notably, printers were present alongside PoS systems in 46% of cases, VoIP devices in 36%, and IP cameras in 30% of instances.
Rethinking Segmentation for Enhanced Security
Forescout asserts that organizations do not necessarily need to undergo a complete network redesign to mitigate these issues. Instead, security teams should focus on identifying segments where various device categories overlap, particularly the mixtures of IT with OT, medical, or IoT assets. Critical operational systems ought to be isolated from general-purpose IT whenever feasible. Additionally, segments that are overly large can be subdivided into smaller environments to further restrict lateral movements.
The researchers advocate for implementing policy-based access controls between different segments, as well as ongoing monitoring for "segmentation drift." This phenomenon occurs when changes in devices and business requirements gradually lead to interconnected environments that were originally intended to remain isolated. Ultimately, the research emphasizes that simply dividing a network into segments does not guarantee effective isolation. True security derives from creating meaningful boundaries between systems, ensuring that the compromise of a single device does not unlock access to the wider organizational network.
For further details, the complete research blog can be accessed here.
This critical examination of network segmentation dynamics presents a stark reminder of the need for vigilance in cybersecurity practices, especially regarding the interplay between diverse device categories in modern operational frameworks.