Research Found Most Network Segments Lack Isolation

A new industry report shows that critical operational and medical device networks often fail to achieve full isolation.

Updated on Sept. 22, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a geometric network hardware unit with dense cable connections, representing infrastructure isolation policy.
Forescout research into 2.5 million devices across 209 organizations found that only 13% of operational network segments are fully isolated from general traffic. AI Illustration. Upload story photo >

Live Poll

Do you trust that most major organizations effectively protect their critical infrastructure from cyberattacks?

Forescout research into 2.5 million devices across 209 organizations revealed that only 13% of operational technology network segments are fully isolated. The findings indicate that most network environments mix different types of hardware, creating significant security gaps.

Why it matters

The lack of network segmentation complicates efforts to contain security breaches, as compromised IT devices can potentially serve as entry points to sensitive operational or medical equipment. As industrial and healthcare environments digitize, these findings highlight a widespread failure to implement standard network defense architecture.

Across 47,700 analyzed network segments, only 6% of segments containing medical devices were dedicated solely to that hardware, while just 20% of point-of-sale systems operated in isolated environments. On average, each network segment contained 54 devices, with 11% of segments holding more than 51 units.

The players

Forescout Vedere Labs

A research division focused on threat intelligence and device security within the broader Forescout cybersecurity platform.

The details

Researchers categorized devices into IT, OT (operational technology — hardware controlling physical industrial processes), IoT (internet of things — networked smart devices), and medical classes to assess isolation. By analyzing network traffic architecture, the team determined whether segments were restricted to single device categories or mixed. The data shows that 62% of segments contain only one category of device, but true isolation—separating critical systems from general networks—remains rare.

Timeline

  1. September 22, 2026: Publication of the Forescout Vedere Labs research report.

The Tech Race

This research provides a quantitative look at the industry's struggle to implement the micro-segmentation required by zero-trust frameworks. It marks a departure from the idealized security postures many organizations claim to hold in their official documentation.

Network architects and security teams should assess their existing infrastructure to identify mixed-device segments that could allow lateral movement during a cyberattack. These findings serve as a baseline for auditing internal network hygiene and prioritizing the isolation of legacy medical and OT hardware.

The takeaway

The vast majority of operational and medical hardware is exposed to broader network traffic, increasing the risk of cross-contamination during security incidents. Organizations should monitor the upcoming release of related threat intelligence benchmarks from Forescout to see if current segmentation practices improve over time.

Further reading

For broader trends in enterprise defense, visit our Cybersecurity section.

Live Poll

Do you trust that most major organizations effectively protect their critical infrastructure from cyberattacks?

Research Found Most Network Segments Lack Isolation