Incomplete Network Segmentation Widens Corporate Attack Surface
Share
Incomplete network segmentation is significantly expanding the corporate attack surface, increasing the risk that a single compromised device can facilitate lateral movement across an organisation. Research from cybersecurity vendor Forescout reveals that nearly half of all network segments containing operational technology (OT) or internet of medical things (IoMT) devices also include IT and IoT assets.
Analysing 47,700 real-world network segments, the Forescout report, titled “What 47,700 Segments Reveal About Network Segmentation”, found that the average segment contains 54 devices across four primary categories: IT, OT, IoT, and IoMT. While 62% of segments contained only one device category, nearly 30% contained two, and 9% contained three or more.
Increased Risk in OT and Medical Environments
The lack of isolation is particularly acute in critical infrastructure and healthcare environments. Only 13% of segments containing OT devices were exclusively dedicated to OT, while a mere 6% of IoMT segments were isolated from other device types. This convergence creates pathways for attackers to move from less secure devices into sensitive operational or clinical networks.
IP cameras represent a notable vulnerability in these mixed environments. The research found that only 2% of segments containing IP cameras were dedicated solely to those devices. Most cameras share segments with workstations and servers, providing a direct route into the broader corporate network if the camera is compromised.
This vulnerability has been exploited in recent years. In early 2025, the Akira ransomware group used poorly segmented IP cameras to bypass endpoint detection and response (EDR) systems. Furthermore, the pro-Russian hacktivist group NoName057(16) has carried out over 300 instances of IP camera exploitation this year, including recent attacks against targets in Estonia and Canada during late August and early September 2026.
Mitigating Segmentation Drift
To reduce the potential blast radius of an attack, Forescout recommends that security teams implement several key strategies:
- Establish continuous visibility: Maintain an accurate inventory of all connected assets, including their location and communication patterns.
- Identify convergence zones: Prioritise the securing of segments that contain high-risk combinations of multiple device categories.
- Isolate critical assets: Ensure operational assets are strictly separated from enterprise IT networks.
- Reduce segment size: Break down oversized segments containing dozens of devices into smaller, purpose-built units.
- Apply policy-based controls: Implement access controls so devices can only communicate with the specific systems required for their function.
- Monitor for drift: Continuously audit networks to ensure that new device additions or changing business requirements do not erode existing segmentation.




Leave a Reply