Key Findings
We analyzed 47,700 network segments spanning 2.5 million+ devices across 209 organizations.
- Segmentation is often incomplete: nearly half of segments with OT or IoMT devices also mix in IT and IoT assets — widening the attack surface and opening the door to lateral movement.
- Only 13% of segments with OT devices are OT-only
- Just 6% of segments with IoMT devices are IoMT-only
Half of the device types most commonly found in mixed segments rank among 2026’s riskiest devices.
- Just 2% of segments with IP cameras contain only cameras
- IP cameras typically share a segment with workstations and servers — turning a single compromised IP camera into a potential network-wide breach.
The average segment holds 54 devices across four device types:
- 17% are ‘micro-segments’ with a single device
- 72% have 2–50 devices
- 11% exceed 51 devices
Business/professional services (accounting, law, consulting), healthcare, and oil & gas have the largest average ‘blast radius’.
However, industries with a lower average blast radius can still have risky device-category pairings to be identified and isolated.
Recommended Mitigation:
- Establish and maintain continuous visibility of all connected assets
- Identify and prioritize device convergence zones
- Separate critical operational assets from enterprise IT networks
- Reduce oversized network segments
- Implement policy-based access controls between segments
- Use asset intelligence to validate segmentation decisions
- Continuously monitor for segmentation drift
Network segmentation is an an effective defense against cyberattacks, especially proactive defense in the age of AI-assisted attacks. Yet, many organizations continue to operate networks where vastly different types of devices share the same segments.
While this may simplify deployment and day-to-day operations, it also creates unintended pathways for attackers. Flat networks allow breaches to spread to critical systems that should not be reachable. When diverse device types are grouped together without appropriate segmentation, compromising a single asset can have consequences far beyond its original scope.
To better understand how organizations segment their networks in practice, we analyzed 47,700 real-world network segments across organizations in multiple industries. We examined the number of devices within each segment, the types of devices that coexist on the same networks, and the prevalence of environments where IT, operational technology (OT), IoT, and medical assets (IoMT) operate side-by-side.
Our analysis reveals that mixed segments are common. Many business and critical systems share the same network segments with insecure OT and medical devices which expands the attack surface — and could allow lateral movement.
In this research, we identify the most common patterns of device mixing and discuss what these mean for cybersecurity risk, operational resilience, and the ability to contain attacks before they spread.
Network Segment Analysis
We analyzed a dataset of 47,700 network segments containing more than 2.5 million devices across 209 organizations.
Devices were split into four categories – IT, OT, IoT, and IoMT – and 327 functions, such as workstations, programmable logic controllers, IP cameras, and infusion pumps.
Network Segmentation by Device Category
- 62% of analyzed network segments contained a single device category
- 29% contained two categories
- 9% contained three or more
The most common device category combinations are:
- 54% of segments contain only IT devices
- 26% of segments contain IT and IoT devices
- 4% of segments contain IT, IoT, and IoMT devices
These numbers may give the impression that most segments are ‘safe,’ especially in the case of OT, which does not appear in any of the most common combinations. However, the numbers are skewed because of the massive presence of IT. If we look only at the segments containing specialized devices like OT and IoMT, we see that they are rarely ‘isolated’:
- Of all segments containing OT devices, 13% are OT-only
- Of all segments containing IoMT devices, 6% are IoMT-only
The most common combinations in these segments are shown below. In both cases, almost half of the segments contained the specialized devices together with IT and IoT assets.
The table below shows the device functions within each category that are most commonly found in mixed segments. The IoT devices are often seen in offices. OT equipment contains a mix of assets from data centers, such as UPS and PDUs, and smart buildings, such as building automation controllers and BACnet routers. Interestingly, half of the device functions on the table below are among the riskiest devices of 2026 (in red).
| IoT | OT | IoMT |
|---|---|---|
| Printer | Uninterruptible Power Supply (UPS) | Healthcare Workstation |
| VoIP | Building Automation Controller | Blood Glucose Meter |
| IP Camera | Programmable Logic Controller (PLC) | Patient Monitor |
| Smart TV | Power Distribution Unit (PDU) | Infusion Pump |
| Video Conferencing System | BACnet Router | Medication Dispensing System |
Blast Radius and Industry Analysis
On average, each network segment has 54 devices with four different functions. These 54 devices are the ‘blast radius’ of that segment: if one device is compromised, there are Additionally, many devices are part of more than one segment which increases the blast radius even further. On average, each device was part of 1.5 segments in our dataset.
That average does not tell the whole story since it is heavily influenced by outliers and the industry. We can divide segments per number of devices as follows:
- 17% of the analyzed segments are ‘micro-segments’ with a single device
- Almost three quarters of segments (72%) have between two and 50 devices
- 11% of segments have more than 51 devices
The figure below shows the average blast radius per industry. (such as accounting, law and consulting firms), healthcare, and oil & gas, present the highest blast radius, while utilities, financial services, and retail have the lowest.
Even in industries with a lower average blast radius, organizations should pay attention to network segmentation, especially when protecting ‘crown jewels’ assets with sensitive data that are essential to business operations.
For example, point of sale (PoS) systems in the retail sector are part of the crown jewels. Yet, out of the 478 segments where a PoS was identified, only 95 (20%) of those were exclusive to PoS. The most common device pairs we saw in segments with PoS were linked with some of the riskiest device types:
- 46% printers
- 36% VoIP
- 30% IP cameras
Not coincidentally, these are the most common IoT devices overall on organizational networks. IP cameras, in particular, are very relevant in the current threat landscape. Despite retail being part of the second-lowest blast radius of all industries, the pairings to risky device-types is where organizations should focus security efforts.
Why Does Network Segmentation Matter? The IP Camera Example
Back in 2022, we demonstrated how poorly segmented IP cameras could be exploited by ransomware gangs to compromise IT devices. In early 2025, this scenario was executed by the Akira ransomware gang to bypass EDR protections.
By 2026, we routinely see hacktivist groups gaining control over exposed IP cameras in targeted organizations. We tracked over 300 instances this year, including these examples carried out by the pro-Russian group, NoName057(16), in late August and early September against Estonian and Canadian targets:
The initial compromise of an IP camera may seem inconsequential, but organizations need to keep in mind that these cameras are rarely isolated in the corporate network. In our dataset, there were 2,266 segments with IP cameras (almost 5% of all segments). Out of those, only 51 (2%) contained IP cameras-only. The most common devices with cameras in those segments were:
- 60% workstations
- 47% printers
- 37% servers
In more than half of the cases where a threat actor compromises an IP camera, an IT workstation or server is present in the same segment. These IT assets are typically connected to the organization’s domain controller — which can enable lateral movement and a pathway to the most sensitive parts of the organization.
Ensuring those cameras are in dedicated network segments can prevent an initial breach from becoming a network-wide incident.
Mitigation Recommendations
Segmentation is a security control, not just a network design choice.
Our research shows that network segments mixing device types are common across industries. IT systems, operational technology, IoT devices, and medical equipment frequently coexist within the same segments, creating environments where a single compromise can expose a wide range of assets with an oversized blast radius. While not every mixed segment represents a security issue, the data highlights how easily trust boundaries can disappear as networks evolve over time.
The good news is that organizations do not need to redesign their entire network architecture overnight to reduce risk. Instead, they can focus on a series of practical actions that limit attack paths and reduce the potential blast radius of a compromise:
- Establish comprehensive asset visibility. Build and maintain accurate inventory of all connected IT, OT, IoT, and IoMT assets. Continuous visibility into what is connected to the network, where devices are located, and how they communicate is foundational to identifying segmentation gaps, prioritizing risk, and reducing potential attack paths.
- Identify and prioritize device convergence zones. Start by locating segments that contain multiple device categories with risky combinations, such as IT and OT, IT and medical, or IT and IoT. These segments often represent high-value attack paths for adversaries.
- Separate critical operational assets from enterprise IT networks. Systems responsible for production, patient care, building operations, or other critical functions should be isolated from user workstations and general-purpose IT devices as much as possible.
- Reduce oversized network segments. increase the opportunities for lateral movement. Breaking these environments into smaller, purpose-built segments can significantly limit the impact of a breach.
- Implement policy-based access controls between segments. Devices should communicate only with the systems required for their function. Restricting unnecessary east-west network traffic makes it more difficult for attackers to pivot between environments.
- Use asset intelligence to validate segmentation decisions. Maintaining accurate and continuous visibility into device types, roles, and behaviors helps ensure segmentation policies align with operational requirements.
- Continuously monitor for segmentation drift. Networks change over time as new devices are added and business requirements evolve. Regular reviews can identify when previously isolated environments become unintentionally interconnected.
Ultimately, the goal of segmentation is not simply to organize networks more efficiently. It is to create meaningful security boundaries that prevent a compromise in one area from becoming an organization-wide incident. As attackers continue to exploit trusted relationships and move laterally across networks, effective segmentation remains one of the most practical and impactful controls available for improving cyber
For a deeper look at how modern segmentation strategies can help limit blast radius and support Zero Trust initiatives, read our guide, “Dynamic Network Segmentation in the Age of Zero Trust.”

