Forescout Research Revealed Network Security Risks

New findings show that few operational technology segments remain fully isolated from other network devices.

Updated on Sept. 22, 2026 in Cybersecurity

Isometric editorial illustration showing a dense grid of server racks and thick cabling, representing networked digital infrastructure.
Forescout research into 2.5 million devices indicates that 87% of operational technology segments are not fully isolated from broader IT infrastructure. AI Illustration. Upload story photo >

Live Poll

Do you trust that most major organizations effectively protect their critical infrastructure from cyberattacks?

Forescout research has found that only 13% of operational technology network segments are fully isolated from broader infrastructure. The study analyzed 2.5 million devices across 209 organizations to determine current levels of network segmentation.

Why it matters

Inadequate network isolation poses significant security risks, as mixing device categories can allow threats to spread easily between IT, IoT, and operational systems. Proper segmentation is critical for protecting sensitive infrastructure from lateral movement by malicious actors.

The analysis of 2.5 million devices across 47,700 segments revealed that 54% of segments contain only IT devices, while the average segment houses 54 total devices. Only 6% of segments containing medical devices are dedicated exclusively to that category.

The players

Forescout Vedere Labs

This is a specialized cybersecurity research division focused on identifying threats and vulnerabilities within connected devices and operational technology environments.

The details

Researchers sorted 2.5 million devices into four primary categories: IT, OT, IoT, and medical. The data shows that 26% of network segments feature a mix of IT and IoT devices, and only 20% of segments containing point-of-sale systems are restricted to those systems alone.

Timeline

  1. September 2026 marks the publication of the Forescout Vedere Labs research report.

The Tech Race

This research highlights a widespread departure from the cybersecurity standards set by the NIST Guide to Industrial Control Systems Security. As networks increasingly converge, the failure to adopt strict segmentation reflects an ongoing struggle to secure critical infrastructure against modern threats.

The lack of network isolation means that security breaches in standard IT hardware can potentially compromise critical operational or medical devices on the same network. Organizations must evaluate their current segmentation to prevent lateral movement and reduce the risk of system-wide failures.

The takeaway

Effective network security relies on the strict separation of device categories to ensure that a compromise in one area does not impact the entire ecosystem. Organizations should prioritize micro-segmentation to improve their defensive posture against evolving digital threats.

Further reading

For more information on securing digital infrastructure, visit the Cybersecurity section.

Live Poll

Do you trust that most major organizations effectively protect their critical infrastructure from cyberattacks?