New network research suggests that many organizations have implemented segmentation in name without creating meaningful isolation for their most sensitive operational systems. Forescout's Vedere Labs examined 47,700 network segments containing more than 2.5 million devices across 209 organizations.
Although 62 percent of the observed segments contained devices from only one broad category, the results changed significantly when researchers focused on operational technology and connected medical equipment. Only 13 percent of segments containing an OT device were exclusively dedicated to OT. For medical devices, the figure fell to 6 percent.
Mixed Networks Expand the Blast Radius
Placing controllers, medical systems, printers, cameras and conventional computers on overlapping networks creates opportunities for lateral movement. An attacker who compromises an ordinary IT or IoT device may gain a network path toward systems that control physical processes or support patient care.
IP cameras were among the least isolated assets in the dataset. They appeared across thousands of segments, but only about 2 percent of those segments contained cameras alone. In retail environments, most segments containing point-of-sale systems also included devices such as printers, voice equipment or cameras.
Mixed segments are not automatically vulnerable, and operational requirements sometimes make communication between device classes necessary. The problem arises when connectivity exists by default, without a documented business purpose, restrictive access controls or sufficient monitoring.
A Practical Segmentation Program
- Build an accurate inventory that identifies device function, ownership and criticality.
- Map which systems communicate and verify whether each connection is necessary.
- Prioritize separation around safety systems, medical devices and critical controllers.
- Use access-control lists, firewalls and microsegmentation to restrict lateral traffic.
- Monitor blocked and permitted connections for unexpected protocols or destinations.
- Break up unusually large segments that combine numerous device types.
Organizations should avoid starting with an indiscriminate redesign. Changes to OT and medical networks can disrupt essential operations. A phased approach should begin with visibility, followed by risk ranking, controlled testing and carefully scheduled enforcement.
Segmentation Must Be Measured by Containment
In my view, the findings highlight a common governance problem: teams often measure whether virtual networks or VLANs exist rather than whether they actually contain an intrusion. A network diagram can appear orderly while broad routing rules quietly allow unrestricted movement between supposedly separated environments.
Effective segmentation should be tested from an attacker's perspective. Security teams need to determine whether a compromised workstation, camera or printer can reach a critical controller and what authentication or inspection stands in the way. The real objective is not creating more segments. It is reducing the number of credible paths into systems where a digital incident could produce physical or clinical consequences.
