Download Privacy Needle App

Type to search

Cybersecurity

Incomplete Network Segmentation Widens Corporate Attack Surface

Share

Incomplete network segmentation is significantly expanding the corporate attack surface, increasing the risk that a single compromised device can facilitate lateral movement across an organisation. Research from cybersecurity vendor Forescout reveals that nearly half of all network segments containing operational technology (OT) or internet of medical things (IoMT) devices also include IT and IoT assets.

Analysing 47,700 real-world network segments, the Forescout report, titled “What 47,700 Segments Reveal About Network Segmentation”, found that the average segment contains 54 devices across four primary categories: IT, OT, IoT, and IoMT. While 62% of segments contained only one device category, nearly 30% contained two, and 9% contained three or more.

Increased Risk in OT and Medical Environments

The lack of isolation is particularly acute in critical infrastructure and healthcare environments. Only 13% of segments containing OT devices were exclusively dedicated to OT, while a mere 6% of IoMT segments were isolated from other device types. This convergence creates pathways for attackers to move from less secure devices into sensitive operational or clinical networks.

IP cameras represent a notable vulnerability in these mixed environments. The research found that only 2% of segments containing IP cameras were dedicated solely to those devices. Most cameras share segments with workstations and servers, providing a direct route into the broader corporate network if the camera is compromised.

This vulnerability has been exploited in recent years. In early 2025, the Akira ransomware group used poorly segmented IP cameras to bypass endpoint detection and response (EDR) systems. Furthermore, the pro-Russian hacktivist group NoName057(16) has carried out over 300 instances of IP camera exploitation this year, including recent attacks against targets in Estonia and Canada during late August and early September 2026.

Mitigating Segmentation Drift

To reduce the potential blast radius of an attack, Forescout recommends that security teams implement several key strategies:

  • Establish continuous visibility: Maintain an accurate inventory of all connected assets, including their location and communication patterns.
  • Identify convergence zones: Prioritise the securing of segments that contain high-risk combinations of multiple device categories.
  • Isolate critical assets: Ensure operational assets are strictly separated from enterprise IT networks.
  • Reduce segment size: Break down oversized segments containing dozens of devices into smaller, purpose-built units.
  • Apply policy-based controls: Implement access controls so devices can only communicate with the specific systems required for their function.
  • Monitor for drift: Continuously audit networks to ensure that new device additions or changing business requirements do not erode existing segmentation.
Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.