According to recent findings by Forescout’s Vedere Labs, a significant number of organizations operating operational technology (OT) or connected medical devices have not segregated these systems onto dedicated network segments. This research is crucial for understanding the current landscape of network security in sectors relying on these technologies.
Comprehensive Examination of Network Segments
The study reviewed 47,700 network segments comprising over 2.5 million devices within 209 organizations. These devices were categorized into four distinct groups: IT, OT, IoT, and medical (IoMT). The initial data presented a seemingly positive picture, with 62% of segments consisting of devices from a single category. Predominantly, these were IT devices alone or coupled with IoT equipment.
However, the scenario shifts dramatically when focusing on OT and IoMT devices. The research reveals that a mere 13% of segments containing OT devices were exclusively dedicated to them. The situation for segments with medical devices was even less favorable, with only 6% being solely for IoMT.
Device Isolation and Network Security
IP cameras emerged as the least segregated device type, appearing in 2,266 segments but being isolated in only 51 instances. On average, each network segment contained 54 devices from four different categories, with devices appearing in 1.5 segments on average. Single-device micro-segments made up 17% of the total, while 11% of segments housed over 51 devices.
Industries such as business and professional services, healthcare, and oil and gas exhibited larger average blast radii, contrasting with the lower figures in utilities, financial services, and retail. However, the presence of specific high-value systems can still present significant risks, as seen in retail where only 20% of segments with point-of-sale systems were exclusively dedicated to them.
Recommendations for Enhanced Security
Forescout’s recommendations emphasize the importance of visibility and containment rather than a complete overhaul of network infrastructure. Key suggestions include maintaining a comprehensive inventory of connected devices, identifying and flagging segments where risky devices converge, relocating critical OT and IoMT systems away from general IT networks, breaking down oversized segments, and minimizing unnecessary inter-segment traffic.
The complete report is available on Forescout’s website, offering a detailed examination of the study’s findings and recommendations for organizations seeking to fortify their network security strategies.
Related reports indicate increasing cyber threats in various sectors, highlighting the urgency for improved cybersecurity measures. As the digital landscape evolves, robust network segmentation and device management remain pivotal for safeguarding critical infrastructure.
