Ask any CISO whether their network is segmented, and the answer is almost always yes. New research from Forescout's Vedere Labs suggests that answer deserves a follow-up question: segmented from what, exactly?
In What 47,700 Segments Reveal About Network Segmentation, Vedere Labs analyzed 47,700 real-world network segments holding more than 2.5 million devices across 209 organizations. The headline finding: segmentation looks fine on the surface but falls apart the moment you isolate the systems that actually matter—operational technology (OT) and connected medical devices (IoMT).
At a glance, the dataset looks reassuring. Sixty-two percent of segments contained devices from just one category, and the two most common configurations were IT-only (54%) or IT paired with IoT (26%). If that were the whole story, most networks would look reasonably well-contained.
It isn't the whole story. Once researchers isolated segments that actually contain OT or IoMT devices—the systems running physical processes and patient care—the picture inverts:
Only 13% of OT-containing segments are OT-only. The rest share space with IT or IoT equipment.
Only 6% of IoMT-containing segments are IoMT-only.
Nearly half of both OT and IoMT segments mix in IT and IoT assets simultaneously.
IP cameras came out as the least isolated device type Forescout measured. Cameras showed up in 2,266 segments (roughly 5% of the total), and only 51 of those, about 2%, were camera-only. The rest most commonly shared a segment with workstations (60%), printers (47%), and servers (37%).
Even industries with a favorable overall average aren't off the hook. In retail, only 95 of 478 segments containing point-of-sale systems (about 20%) were dedicated to PoS alone. The rest were commonly paired with printers, VoIP, or IP cameras, which Forescout separately flags among 2026's riskiest device categories.
The average segment held 54 devices spanning four different device types—the effective "blast radius" if any one device is compromised. And because the average device belonged to 1.5 segments rather than a single one, that blast radius compounds. Business and professional services, healthcare, and oil & gas carried the largest average blast radius; utilities, financial services, and retail sat at the low end—though Forescout is explicit that a low industry average can still mask dangerous pairings around specific high-value systems.
Forescout's report grounds the risk in precedent rather than hypotheticals. Back in 2022, Vedere Labs demonstrated how a poorly segmented IP camera could give ransomware operators a foothold into IT systems. That scenario stopped being theoretical in early 2025, when the Akira ransomware gang reportedly used a compromised webcam to bypass EDR protections entirely. In 2026, Forescout says it has tracked more than 300 instances of hacktivist groups—including the pro-Russian group NoName057(16)—seizing control of exposed IP cameras at targeted organizations, with recent campaigns against Estonian and Canadian targets.
The through-line: a compromised camera is rarely the end goal; it's a pivot point. And because most camera segments also contain workstations or servers tied to the domain controller, a "minor" IoT compromise can become the opening move in a much larger breach.
The 13% figure is landing hard across the security vendor community, not because it's shocking, but because it confirms what many practitioners already suspected and have struggled to fix.
John Gallagher, Vice President at Viakoo, frames it as an inherited hygiene gap: OT and IoT systems have historically been "managed and maintained by the line-of-business—manufacturing, facilities, physical security" rather than IT, which shows up in the same patterns as unpatched firmware and default credentials. He argues the 13% figure exposes "the illusion of separation" enterprises have been relying on, and that in an environment of AI-driven reconnaissance and automated lateral movement, attackers don't need to breach an OT controller directly—an unpatched camera or workstation is pivot enough. Gallagher's prescription is treating OT/IoT assets as zero-trust endpoints from the start: dedicated micro-segments with East-West traffic denied by default, and automated certificate provisioning (802.1X/TLS) to keep unverified devices out of sensitive VLANs.
Robert Costello, Chief Digital and Information Officer at Merlin Group, pushes back gently on framing this as purely a segmentation problem. He points to the underlying tension: connected medical, IoT, and OT devices were largely engineered for availability and mission function rather than today's threat environment, and the sectors running the most of them—healthcare, utilities, critical infrastructure—are also the most funding- and staff-constrained. His fix pairs technical controls with organizational ones: security engineered into devices from the start, plus the training, visibility, and affordable tooling IT teams need to know what's connected, enforce least privilege, and isolate a device without disrupting patient care or mission operations.
Agnidipta Sarkar, Chief Evangelist at ColorTokens, is more direct: "this report highlights what organizations have always known yet have ignored." Sarkar's read is that the riskiest OT devices tend to be facilities-owned rather than OT-security-owned, often missing from the CMDB, frequently outside the ICS vendor's support contract, and reachable from the corporate network because someone wanted a web UI. His recommended sequence: widen the asset definition, map dependencies rather than devices, microsegment by consequence rather than by Purdue level, and start with bridge devices—his stated "easy win"—before tackling reachability more broadly. He's also blunt that visibility is the first step, not the objective; the objective is machine-speed autonomous enforcement.
Christopher Hills, Chief Security Strategist at BeyondTrust, ties the finding back to OT's long-standing uptime-over-security culture. His concern is squarely foundational: default credentials that are never rotated, and the absence in OT of the layered access controls that typically backstop IT environments. Without those layers, he argues, OT is "vulnerable right from the start," and until organizations modernize legacy systems with modern controls, breaches and compromises across OT environments will continue.
The consensus across these four perspectives is narrower than it might first appear: segmentation isn't broken because the concept is flawed, it's broken because most environments were never mapped and enforced with OT, IoT, and IoMT treated as first-class, high-consequence assets. Forescout's own mitigation guidance reflects that same practical bent rather than a call for a network overhaul.
Build comprehensive, continuous asset visibility across IT, OT, IoT, and IoMT; you can't segment what you haven't inventoried.
Identify device convergence zones first. Segments mixing IT with OT, medical, or IoT devices are the highest-value attack paths and the highest-priority fixes.
Isolate critical operational assets—production systems, patient care devices, building automation—from general-purpose IT.
Break up oversized segments. Fewer devices per segment means a smaller blast radius when something goes wrong.
Enforce policy-based, least-privilege access between segments, restricting east-west traffic to what's operationally necessary.
Monitor continuously for segmentation drift. Networks that were properly segmented a year ago rarely stay that way without active maintenance.
The 13% figure is a useful gut-check for any security team that has assumed "we have network segmentation" means the job is done. As this research—and the ransomware and hacktivist activity it cites—makes clear, the gap between having segments and having isolation is exactly where attackers are living.