Skip to content

Security3 publishers3 min readPublished

Forescout's 47,700-segment census finds OT isolated in 13% of the segments that carry it

The Sept. 22 study of 2.5 million devices in 209 organizations found cameras alone in 51 of 2,266 camera segments, and Black Hills Information Security's John Strand says the true isolation rate is lower.

The Watch · Security desk

Illustration accompanying Forescout's 47,700-segment census finds OT isolated in 13% of the segments that carry it

What happened

  • Forescout Research released a study on Sept. 22 covering 47,700 network segments, more than 2.5 million devices and 209 organizations, sorting each device as IT, OT, IoT or medical.
  • Of the segments holding at least one OT device, 13% held OT alone, and only 6% of segments with medical devices were dedicated to those devices.
  • Nearly half of the segments containing OT or medical devices also carried IT and IoT assets in the same segment.
  • IP cameras appeared in 2,266 segments and only 51 of those held cameras alone; Forescout says cameras typically share a segment with workstations and servers.
  • Forescout says the path has been used in anger: the Akira ransomware group worked through poorly segmented IP cameras in early 2025 to get around endpoint detection.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure In 87% of OT-bearing segments, an intruder who lands on an IT or IoT device is already inside the OT broadcast domain, so incident scoping has to start wider than the network diagram suggests.
  • decision The control that survives this census is a rehearsed disconnect, and Strand's version requires someone below the CTO to hold the authority to cut OT from external networks mid-incident.
  • constraint Forescout's remedy list stays inside inventory, convergence-zone triage and inter-segment access policy. The work lands on operations budgets, not on a network rebuild.
  • contradiction Strand rates the 13% as high based on years of offensive testing, which makes this census the optimistic reading of how much isolation actually exists.

Subtract the 51 exclusive camera segments and 2,215 remain where a camera shares its broadcast domain with something else [25]. Forescout puts the average segment at 54 devices [11]. Owning the camera in an average segment puts an attacker one hop from 53 other devices [26]. The average device in the dataset belongs to 1.5 segments, not one [12].

At the top level the picture looks tidy. Sixty-two percent of segments held a single device category, 29% held two and 9% held three or more [7]. IT alone accounts for 54% of all segments, and IT paired with IoT another 26% [8]. So IT-only segments make up 54 of those 62 points, about seven in eight of the single-category segments [28]. Eleven percent of segments held more than 51 devices, and 17% were single-device micro-segments [13].

Forescout found the largest average blast radius in business and professional services, healthcare, and oil and gas, with utilities, financial services and retail at the low end [14]. The retail average hides the point-of-sale case. Ninety-five of 478 segments containing POS systems were POS-only, leaving 383 that most often shared space with printers, VoIP equipment or IP cameras [15][29].

John Gallagher, vice president at Viakoo, tied the pattern to who owns the gear. "OT and IoT systems have often been managed and maintained by the line-of-business such as manufacturing, facilities, or physical security, and lack IT-level hygiene around network management and cybersecurity," Gallagher said [22].

John Strand, owner at Black Hills Information Security, said his testers rarely find the isolation clients describe. "We've been doing offensive security testing for years, and the vast majority of the time when an organization says a network is air-gapped, it really isn't," Strand said. "The only places where we consistently see truly air-gapped networks are classified environments and classified security assessments" [20]. He put the workable control elsewhere: "What's realistic is having a documented plan to rapidly disconnect OT systems from external networks during an incident. Organizations need to know exactly how that happens and who has the authority to make that call. That authority cannot be limited to waiting for the CTO or CEO" [21].

The exploitation record in the report comes from outside the census. "By 2026, we routinely see hacktivist groups gaining control over exposed IP cameras in targeted organizations," the report said, counting more than 300 instances this year, including operations by the pro-Russian group NoName057(16) against Estonian and Canadian targets in late August and early September [17][18].

What the study measures is which device categories sit in the same segment, plus industry averages for blast radius; it does not report a traversal test inside the 209 organizations [30]. Forescout's own framing of the consequence is short: "Flat networks allow breaches to spread to critical systems that should not be reachable" [24].

What to watch

  • Whether Forescout releases the per-industry segment data behind the blast-radius ranking, so healthcare and oil and gas operators can compare their own estates.
  • Whether the 300-plus camera takeovers tracked this year produce a documented intrusion that moved past the camera segment.
  • Whether the 6% IoMT-only figure draws regulator or payer attention in healthcare, which Forescout ranks near the top for average blast radius.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories