Full Report
Forescout’s Vedere Labs analyzed 47,700 network segments containing more than 2.5 million devices across 209 organizations, finding that... The post Forescout finds network convergence across IT, OT, IoT and IoMT could increase lateral movement and cyberattack impact appeared first on Industrial Cyber.
Analysis Summary
# Research: Network Convergence and Segmentation Drift Across IT, OT, IoT, and IoMT
## Metadata
- **Authors:** Vedere Labs
- **Institution:** Forescout
- **Publication:** Industrial Cyber
- **Date:** September 24, 2026
## Abstract
This research investigates the current state of network segmentation across global organizations, specifically examining the convergence of Information Technology (IT), Operational Technology (OT), Internet of Things (IoT), and Internet of Medical Things (IoMT). By analyzing millions of devices, Vedere Labs identified that specialized devices (OT/IoMT) are rarely isolated, frequently sharing network segments with general IT assets. This lack of robust segmentation significantly expands the potential "blast radius" for cyberattacks, facilitating lateral movement from non-critical devices (like IP cameras) to sensitive domain controllers and industrial systems.
## Research Objective
The study aims to quantify the degree of network convergence—the blending of different technology domains—within modern enterprise environments and assess how this convergence impacts the potential for lateral movement and the overall scale of cyberattack consequences.
## Methodology
### Approach
The researchers conducted a large-scale empirical analysis of network segment composition, categorizing devices by function and technology domain (IT, OT, IoT, IoMT) to determine how often these domains are isolated versus mixed.
### Dataset/Environment
- **Scale:** 47,700 network segments.
- **Scope:** Over 2.5 million devices.
- **Diversity:** 209 different organizations.
### Tools & Technologies
The research utilized Forescout’s proprietary network visibility and intelligence platforms to identify device types, functions, and cross-segment communication patterns.
## Key Findings
### Primary Results
1. **High Convergence Rates:** Only 13% of segments containing OT devices were OT-only, and only 6% of IoMT segments were IoMT-only.
2. **Multidomain Segments:** 29% of segments contained two device categories, while 9% contained three or more.
3. **The Blast Radius:** The average network segment contains 54 devices spanning four different functions, representing the immediate area of impact should one device be compromised.
4. **IP Camera Vulnerability:** IP cameras are highly integrated; 60% of segments with cameras also contained workstations, and 37% contained servers.
### Supporting Evidence
- **OT Composition:** 42% of segments with OT devices also included IT and IoT assets.
- **Medical Risk:** 50% of IoMT segments contained a mix of IoMT, IT, and IoT devices.
- **Camera Isolation Failure:** Out of 2,266 segments containing IP cameras, only 51 (2%) were properly isolated.
### Novel Contributions
- Provides empirical data debunking the "air-gapped" or "isolated OT" myth in modern infrastructure.
- Quantifies the "blast radius" concept specifically through the lens of device-type diversity within segments.
## Technical Details
The research highlights a critical technical pathway for lateral movement: the presence of IT workstations and servers in the same segments as vulnerable IoT devices (like IP cameras). Because these IT assets are frequently connected to an organization's **Domain Controller**, a compromise of a low-security IoT device can lead directly to the compromise of the organization's primary identity and access management system, effectively granting the attacker control over the entire network.
## Practical Implications
### For Security Practitioners
- **Visibility is Paramount:** Organizations cannot secure what they cannot see. Identifying "convergence zones" where IT and OT meet is the first priority.
- **Segment Auditing:** Regular audits are required to catch "segmentation drift," where new devices are added to incorrect VLANs over time.
### For Defenders
- **Isolate High-Risk IoT:** Prioritize the isolation of IP cameras and printers into dedicated, restricted segments.
- **Zero Trust Architecture:** Implement granular access controls between segments to ensure that even if a segment is breached, movement to the domain controller or critical OT assets is blocked.
### For Researchers
- **Drift Analysis:** Future research should investigate the *rate* at which segmentation degrades over time in large enterprises.
- **Automated Remediation:** Developing methods to automatically re-segment devices based on behavior rather than just MAC address or port.
## Limitations
- The study focuses on network layer segmentation and may not fully account for application-layer security controls or software-defined perimeters that could mitigate risks despite network convergence.
- The dataset is limited to Forescout customers, which may represent a specific maturity level in cybersecurity.
## Comparison to Prior Work
While previous research has focused on vulnerabilities within specific OT or IoT devices, this study builds upon that by looking at the **relational architecture**. It shifts the focus from "how a device is hacked" to "how a hacked device facilitates the collapse of the entire network hierarchy."
## Real-world Applications
- **Infrastructure Hardening:** Used as a blueprint for CISOs to justify budgets for network re-architecting and NAC (Network Access Control) deployments.
- **Incident Response:** Provides IR teams with a "blast radius" metric to estimate the potential extent of a breach during the containment phase.
## Future Work
- **Impact of AI on Lateral Movement:** Investigating how attackers might use AI to navigate these converged segments more rapidly.
- **Comparative Analysis:** Longitudinal studies to see if the adoption of Zero Trust architectures is successfully reducing the reported blast radius.
## References
- Forescout Vedere Labs (2026). *Network Convergence Report.*
- Related Research: [hXXps://industrialcyber.co/threat-landscape/]
- Related Case Study: Pro-Russian group NoName057(16) camera exploitation (2026).