"Flat networks allow breaches to spread to critical systems that should not be reachable," Forescout warned.
What 47,700 segments reveal about device mixing
Forescout analyzed 47,700 real-world network segments across multiple industries in its report, What 47,700 Segments Reveal About Network Segmentation. The vendor found the average segment holds 54 devices across four device types: IT, OT, IoT and IoMT. While 62% of segments contained a single device category, 29% contained two categories and nearly 9% contained three or more.
That mixing is not evenly distributed. A quarter (26%) of segments contained IT and IoT together. Only 13% of segments that included OT devices were OT-only, and just 6% of segments with IoMT devices were restricted to IoMT alone. The upshot: many segments mix operational devices with enterprise systems rather than isolating them.
IP cameras and the broader attack surface
Forescout highlighted specific device types to show the practical risk of mixed segments. Only 2% of segments that included IP cameras contained just those cameras, meaning the vast majority of camera deployments sit alongside other devices. Cameras commonly share a segment with workstations and servers, the report said, so a single compromised camera could become a pathway into the corporate network.
The vendor also noted that half of the device types most commonly found in mixed segments rank among 2026's riskiest devices, underscoring that device mixing is not merely an architectural concern but a measurable elevation of risk.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleReal-world breaches and observed exploitation
Forescout framed the segmentation problem as operationally consequential, not theoretical. The report recalled an instance in early 2025 when the Akira group used poorly segmented IP cameras to bypass endpoint detection and response (EDR). That demonstration, it argued, has practical echoes: "By 2026, we routinely see hacktivist groups gaining control over exposed IP cameras in targeted organizations."
In 2026 alone Forescout said it tracked over 300 instances of groups gaining control of exposed cameras, citing as examples attacks by the pro‑Russian group NoName057(16) in late August and early September against Estonian and Canadian targets.
Forescout's prescribed fixes for segmentation failures
The report lays out a set of specific actions for security teams. Forescout urges organizations to:
- Establish and maintain continuous visibility of all connected assets, including an accurate inventory and insight into what is connected, where devices are located and how they communicate.
- Identify and prioritize “device convergence zones,” starting with segments that contain multiple device categories with risky combinations.
- Separate critical operational assets from enterprise IT networks.
- Reduce oversized network segments with dozens of devices and break them into smaller, purpose-built segments.
- Implement policy-based access controls between segments so devices communicate only with the systems required for their function.
- Use asset intelligence on device types, roles and behaviors to validate segmentation decisions.
- Continuously monitor for segmentation drift, because networks change over time as new devices are added and business requirements evolve.
How security teams, enterprises, and adversaries are positioned
Security teams and technologists: The report directs them to gain continuous visibility, identify convergence zones, apply policy‑based access controls and monitor for segmentation drift — concrete steps tied to Forescout’s device- and behavior-focused prescriptions.
Enterprises and procurement leaders: Organizations that broker OT, IoMT, IT and IoT purchases will face pressure to separate critical operational assets from enterprise IT, shrink oversized segments and demand asset intelligence from vendors and integrators.
Adversaries and threat actors: The documented history — the Akira group’s early‑2025 technique and more than 300 2026 camera‑control instances tracked by Forescout — indicates attackers are exploiting mixed segments and exposed IP cameras as practical avenues for lateral movement and broader compromise.
Forescout’s diagnosis is unambiguous: when diverse device types are grouped without appropriate segmentation, compromising one asset "can have consequences far beyond its original scope." The choices organizations make next — whether to adopt continuous asset visibility, shrink and harden segments, and enforce policy‑based controls — will determine how often that sentence proves true.




