Security News

Poor Network Segmentation Is Quietly Widening the Attack Surface for Businesses

Infosecurity Magazine · 22 Sept 2026
Key Takeaway Small businesses should map out which devices sit on which parts of their network and separate everyday IT equipment from cameras, smart devices, and any OT or medical systems to limit how far an attacker can spread if one device is compromised.

A new report from security vendor Forescout has found that many organisations are unintentionally making it easier for attackers to spread through their networks. After analysing 47,700 real-world network segments, the company found that almost half of segments containing operational technology (OT) or connected medical devices also included regular IT and IoT devices. This mixing of device types means that a single compromised device, such as an IP camera, printer, or smart sensor, can act as a stepping stone into far more sensitive parts of a business's network.

The report highlighted that devices like IP cameras are rarely isolated: in most cases they share a network segment with workstations and servers. This is not just a theoretical risk. Forescout noted that ransomware group Akira exploited poorly segmented IP cameras in 2025 to bypass endpoint security tools, and that hacktivist groups have increasingly taken control of exposed cameras throughout 2026, including attacks attributed to the pro-Russian group NoName057(16).

Forescout's core warning is that flat, poorly divided networks allow a single breach to cascade into critical systems that should otherwise be out of reach. When different types of devices, from everyday laptops to sensitive medical or industrial equipment, sit on the same network segment without proper controls, the impact of a compromise can extend well beyond the device that was initially attacked.

network segmentation attack surface IoT security ransomware critical infrastructure

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.