Segmentation Isn’t Security: The OT/IoT Myth That Won’t Die

If Mythbusters took aim at OT/IoT security they would probably start with network segmentation.  With OT/IoT security there are many ways that organizations will delude themselves by thinking they are safe-by-design when the reality is way different, but probably the biggest is around segmentation.  The leading example of this is when someone says “we’re good – all our OT and IoT systems are on segmented networks”, yet they inevitably end up being exploited because an OT device never had its firmware updated or the device is using a default password, and the attacker was able to use that foothold to move laterally within the organization.  Thanks to our partners at Forescout’s Vedere Labs and their report on September 22 on network segmentation we have data to put to rest the falsehood that network segmentation is a substitute for effective cyber hygiene. 

Empirical research from Forescout’s Vedere Labs analyzed more than 47,700 network segments across 209 enterprise environments. While surface-level metrics suggest segmentation is widespread—with 62% of segments containing devices from a single category—the reality fractures when looking closer at operational environments.  Only 13% of network segments containing OT devices consist solely of OT assets (and in healthcare environments, merely 6% of segments containing medical devices are dedicated exclusively to medical equipment).  IP cameras, building controllers, VoIP endpoints, and networked printers routinely share the exact same broadcast domains as high-value operational assets. In fact, out of more than 2,200 segments containing IP cameras, just 2% housed cameras exclusively.

The takeaway is clear: the enterprise “air gap” and pristine OT/IoT segmentation are largely architectural myths. In today’s interconnected enterprise, OT/IoT devices have become the persistently unlocked side door into operational environments.  Modern threat actors rarely waste advanced zero-day exploits attempting to breach hardened programmable logic controllers (PLCs), distributed control systems (DCS), or SCADA servers directly. They don’t have to.  Instead, attackers follow the path of least resistance: compromising an unmanaged, peripheral OT/IoT device sharing the same subnet.

Consider a typical facility: a smart HVAC sensor installed in an equipment bay, environmental monitoring for smart lighting, or an IP security camera mounted outside a control room. These devices are frequently deployed with factory-default passwords, outdated firmware harboring known CVEs, or missing 802.1X certificates. Once an adversary establishes a foothold on that peripheral device, they are already past the perimeter firewall.

From there, because the device resides on an un-isolated or poorly partitioned segment, the blast radius encompasses every critical controller and workstation sharing that broadcast domain. With the emergence of autonomous, AI-driven reconnaissance scripts and agentic tools, threat actors can scan internal subnets, map interconnected endpoints, and execute lateral movement in a matter of seconds.

If organizations believe they have implemented effective segmentation, why does this exposure persist?  It boils down to a few basic concepts that are typically controlled for in IT but not in OT/IoT, such as acknowledging that configuration drift happens, operator error happens, or that VLANs don’t prevent internal packet sniffing, spoofing, or lateral infection within the segment.   A recent example has been the breaching of small water utilities where the network originally was setup to be fully segmented; yet to remotely service them technicians will add a cellular modem so they can be monitored and managed remotely and therefore break the segmentation. 

Network controls only govern where packets are permitted to flow; they do nothing to address the underlying vulnerabilities on the endpoints themselves. When an unauthorized path or misconfiguration arises, an unhardened endpoint immediately becomes an entry point.

Getting to Active Cyber Hygiene

Treating segmentation as a static, set-it-and-forget-it security project was never a viable strategy and is less so in the era of AI-driven threats. Network containment must be paired with continuous, active cyber hygiene across every connected device. Security and operational leaders must focus on four foundational pillars:

1. Automate Fleet-Wide Hygiene and Remediation at Scale

The traditional operational model—waiting for an IT scan, filing a ticket, and scheduling manual field technicians to patch devices—is too slow and cost-prohibitive. Manual truckrolls cost an estimated $150 or more per truckroll and leave known vulnerabilities open for months.

Enterprises must deploy agentless, autonomous remediation capable of rotating credentials, updating firmware, and renewing certificates across heterogeneous IoT/OT fleets at machine speed, dropping remediation costs to pennies per endpoint while keeping humans in the loop for critical control.

2. Manage Certificates on OT/IoT Devices (802.1X & TLS)

Static IP addresses and MAC filtering provide virtually no defense against motivated adversaries. Every device attempting to communicate on an operational or facilities network must authenticate cryptographically using automated 802.1X certificate provisioning and TLS certificates. If a device cannot authenticate, it should be immediately isolated and quarantined.

3. Detect and Correct Configuration Drift

As organizations scale their deployments of smart devices, building management, access control systems, and industrial gateways, maintaining consistent operational baselines and security postures across thousands of heterogeneous endpoints has become an immense challenge. Unmonitored changes—whether triggered by unauthorized local adjustments, improper field maintenance, or malicious tampering—introduce dangerous cyber vulnerabilities and operational outages.  Monitoring and managing configuration drift is a key element of overall OT/IoT security. 

4. Bridge the IT-OT Governance Divide

Operational and IoT assets can no longer exist in an IT blind spot. Device posture, configuration state, and compliance tracking must be unified within standard enterprise IT Service Management (ITSM) workflows, such as ServiceNow or others. When physical assets are managed with the same rigorous governance as corporate servers, gaps are caught before they becomes an incident.

Segmentation Plus Cyber Hygiene

Network segmentation is an indispensable architectural strategy, but it is not full protection against cyber breaches. Segmentation is a fire door. It won’t help if every room is full of kindling.  A fire door will not prevent damage if every room is connected to the other and allows the fire to spread at AI speed.

As long as peripheral OT/IoT endpoints remain vulnerable and co-mingled with mission-critical machinery, operational networks will remain exposed to rapid lateral compromise. True OT/IoT cyber-physical resilience requires eliminating the side door altogether—combining strict micro-segmentation with continuous, automated device hygiene.  Viakoo can help – click here to setup a 30 minute call with one of our OT/IoT security experts and learn how to autonomously manage cyber hygiene across the entire enterprise. 

Share this