Why Network Segmentation Fails as a Standalone OT/IoT Security Strategy

Network segmentation is often mistaken for comprehensive OT/IoT security, but it leaves many gaps unaddressed. Organizations may believe they are safe by design while overlooking other critical vulnerabilities. The article argues that segmentation alone does not protect against the full range of threats facing industrial systems.
Forescout’s Vedere Labs examined over 47,700 network segments across 209 enterprise environments, finding that while 62% of segments contain devices from a single category, this apparent isolation collapses in operational settings. Only 13% of segments with OT devices are purely OT, and in healthcare just 6% of segments with medical devices are dedicated exclusively to them. IP cameras, building controllers, VoIP endpoints, and printers frequently share broadcast domains with critical assets—among more than 2,200 segments containing IP cameras, only 2% housed cameras alone.
The research underscores that segmentation often coexists with poor cyber hygiene, such as unpatched firmware or default passwords. Attackers exploit these weaknesses to move laterally, meaning segmentation alone cannot prevent breaches. Organizations may believe they are safe by design, but the data shows that mixed-device segments are the norm, not the exception, leaving operational technology exposed despite apparent network boundaries.
This finding could reshape how industrial and healthcare organizations prioritize security investments. If segmentation is widely assumed to be sufficient, many may remain vulnerable to lateral movement and device-level exploits, potentially disrupting critical services like power or patient care. The analysis may push regulators and security teams to demand stronger device hygiene and continuous monitoring, though adoption could be slow given legacy infrastructure constraints.