Enterprise network segmentation may look stronger on paper than it is in practice, according to new research from Forescout.
Only 13% of network segments containing operational technology devices were dedicated solely to OT. For Internet of Medical Things devices, that figure fell to just 6%.
Forescout’s Vedere Labs analyzed 47,700 network segments containing more than 2.5 million devices across 209 organizations. Although 62% of the segments contained just one category of device, traditional IT heavily influenced that figure, with IT-only segments accounting for 54% of all segments studied.
Specialized devices frequently shared network space with IT and IoT systems, creating potential paths for attackers to move between systems after gaining an initial foothold.
Specialized Devices Share Space With IT Systems
Among the devices Forescout commonly found in mixed segments were printers, VoIP phones, smart TVs, UPS systems, building automation equipment, and medical and industrial systems.
Those mixed environments can also include devices managed outside traditional IT security processes. Half of the common device types Forescout found in mixed segments also appear on its 2026 list of riskiest devices.
“OT and IoT systems have often been managed and maintained by the line-of-business … and lack IT-level hygiene around network management and cybersecurity,” said John Gallagher, vice president at Viakoo.
The problem is a compromised peripheral device could provide a path toward more sensitive systems. A printer or camera may not be an attacker’s ultimate target but could provide an initial foothold.
IP Cameras Provide a Path for Lateral Movement
IP cameras offer one of the clearest examples of how segmentation gaps can increase the potential impact of a compromised device. Of the 2,266 segments Forescout analyzed that contained IP cameras, just 51 — about 2% — contained cameras alone. Workstations appeared in 60% of camera segments, printers in 47%, and servers in 37%.
Forescout has demonstrated how that kind of proximity could be abused. Its R4IoT proof of concept showed how an attacker could compromise an IP camera and use it as a foothold for lateral movement across a network.
Real-world incidents have also demonstrated how cameras can be used during attacks. In a 2025 incident cited by Forescout, Akira ransomware operators used a webcam to bypass endpoint detection and response. Forescout also observed more than 300 hacktivist camera compromises in 2026, demonstrating continued attacker interest in the devices.
Segmentation will not stop every device from being compromised, but it can limit what an attacker can reach next.
Segment Size Can Mask Risk
Segment size adds another layer to the findings. The average segment in Forescout’s dataset contained 54 devices spanning four different functions, and each device belonged to an average of 1.5 segments. That overlap can create additional paths between systems that might otherwise appear separated.
The spread was wide. Seventeen percent of segments qualified as microsegments, while 11% contained more than 51 devices. Business services, healthcare, and oil and gas had some of the largest average blast radii. Utilities, financial services, and retail sat toward the lower end.
But a low average can conceal potentially consequential combinations. In retail, only 95 of 478 segments containing point-of-sale systems were dedicated to POS. Printers shared those segments 46% of the time, VoIP devices 36%, and cameras 30%.
Operational Demands Complicate Segmentation
Experts pointed to operational demands, fragmented ownership, and legacy technology as factors that can undermine segmentation over time.
Networks change as equipment is added, replaced, or repurposed, potentially eroding boundaries that were established when systems were initially deployed. Ownership can add another complication. OT, IoT, and IoMT devices may be managed by facilities, clinical, manufacturing or other operational teams rather than traditional IT.
There are also practical constraints. Legacy equipment may not support modern security controls, while uptime requirements can complicate efforts to isolate systems.
“We have seen an explosion of connected medical, IoT, and OT devices, many of which were built first for availability and mission function, not for the cyber threat environment they operate in today,” said Robert Costello, Chief Digital and Information Officer at Merlin Group. “At the same time, healthcare, utilities, and other critical infrastructure sectors are dealing with limited cyber funding and IT teams under enormous operational pressure. That inevitably leads to deployments that meet the mission need but are not always architected the way we would want from a security standpoint.”
Shrinking the Blast Radius
The goal of stronger segmentation is not necessarily to redesign the network from scratch, but to reduce how far an attacker can move after one device is compromised.
Forescout recommends continuously identifying and classifying connected IT, IoT, OT, and IoMT assets rather than treating segmentation as a one-time design exercise. It also recommends prioritizing convergence points where general IT systems share access with medical, industrial, or other mission-critical devices.
Where operational requirements allow it, organizations can place sensitive systems into dedicated segments or microsegments, restrict unnecessary east-west traffic, and apply least-privilege rules to communication between segments. Forescout also recommends breaking up oversized segments while paying attention to smaller segments that contain high-value or vulnerable systems.
Those boundaries also require continued monitoring as networks and connected devices change. At the same time, isolation and enforcement controls have to account for uptime, patient care, industrial processes, and other operational requirements.
“We need stronger security capabilities engineered into these devices from the start, but we also need to give the IT teams operating them the training, visibility, and affordable solutions needed to secure these environments,” Costello said. “That means knowing what is connected, enforcing least privilege, properly segmenting systems, and being able to isolate a device, when necessary, without disrupting patient care or the mission.”
The point of segmentation is containment. A compromised camera, printer, workstation, or other endpoint may still become an entry point. Effective segmentation is intended to prevent that compromise from becoming a path to the rest of the network.