Most Factory Networks Are Not Really Segmented: Study Finds Only 13% of OT Segments Are OT-Only
Published on 09/23/2026 at 22:12 | Editorial boerse-global.de
Industrial security teams have spent years being told to wall off production systems from everything else. New data suggests most of them have not done it — and the gap is widest exactly where it matters.
An analysis by Forescout's Vedere Labs of 47,700 network segments across 209 organisations found that while 62% of segments contained devices from just one category, the separation of information technology (IT) from operational technology (OT) remains porous. Among segments holding at least one OT device, a mere 13% consisted exclusively of OT components. For medical devices the figure dropped to 6%.
IP cameras tell the same story. Of 2,266 segments where such cameras were detected, only about 2% — 51 segments — were reserved for those devices alone. Retail showed a comparable pattern: just 20% of point-of-sale segments (95 of 478) contained nothing but POS systems. Forescout's recommendation is blunt — build a complete inventory, then isolate critical systems without compromise.
Complexity fears versus 30-day rollouts
The case for microsegmentation and network-level multi-factor authentication in modern manufacturing was laid out by security firm Zero Networks in a technical paper published on 23 September 2026. The approach is designed to stop attackers moving laterally and to keep malware from spreading inside industrial networks.
Apprehension about putting it in practice runs high. In a Zero Networks survey, 50% of security decision-makers in manufacturing named implementation complexity as their top concern.
Field results point the other way. Vermeer segmented its network within 30 days without disrupting legitimate traffic, and manufacturer Mikron completed a comparable segmentation in a matter of weeks. Atlantic Constructors reported operational gains after penetration testing: not one of the tested machines could be compromised, reliability rose by 100%, and network performance was estimated to have doubled.
Exploits now the leading way in
Statistics on the threat landscape sharpen the argument for containment. Technical guidance singles out microsegmentation as a response to AI-generated exploits. According to the Mandiant M-Trends Report 2026, exploits accounted for 32% of initial infections in enterprises.
The Verizon Data Breach Investigations Report (DBIR) 2026 records a similar shift: vulnerability exploitation enabled first access in 31% of the incidents examined, a rise of 55% over the previous year.
The financial damage is growing too. IBM's "Cost of a Data Breach 2026" puts the additional cost of a breach involving AI-driven attacks at an average of USD 1 million.
Microsoft illustrated how quickly the vulnerability picture moves when it released 570 fixes in July 2026, including three zero-day flaws — more than three times the number issued in April of the same year. Against that background, 85% of companies intend to raise security spending, according to IBM.
Pharma machinery, 15-to-20-year lifespans and NIS2
Some specialised sectors are already building concrete architectures. Uhlmann, a packaging machinery maker serving the pharmaceutical industry, relies on a modular design in which remote access is granted only after the customer approves it. Because such systems often stay in service for 15 to 20 years, the company applies lifecycle vulnerability management. Supply chain security has become a heavier focus, driven by regulatory requirements such as the NIS2 Directive.
Standards work continues in parallel. PROFIBUS & PROFINET International (PI) refined the PROFIsafe specification in September 2026, tightening provisions on parameterisation, data types and response times. The research project Factory-X also concluded successfully, with industry and academic partners developing reference models for sovereign data exchange based on the Asset Administration Shell (AAS).
A Rockwell Automation report closes the circle on why this matters strategically. Surveying more than 1,500 manufacturing decision-makers, it found that 46% had been affected by a cyber incident in the previous year. While 62% had already invested in security platforms, 45% plan to deploy artificial intelligence and machine learning for protection over the next 12 months.
