Malik Haidar is a veteran in the cybersecurity arena, known for his pragmatic approach to bridging the gap between high-level business goals and the gritty reality of industrial defense. Having spent years analyzing the intersections of intelligence and network architecture within multinational corporations, he offers a unique perspective on the increasing convergence of operational technology and traditional IT infrastructures. Today, we explore the precarious state of network segmentation, examining why industrial and medical environments remain dangerously interconnected and how organizations can better contain the inevitable “blast radius” of a breach.
In this discussion, we delve into the findings of recent research involving over two million devices to understand why true isolation remains elusive for most organizations. We examine the specific vulnerabilities found in medical and retail environments, the hidden risks posed by common peripherals like IP cameras, and the strategic shift toward visibility-driven containment.
With only 13% of industrial network segments being fully isolated, what does this tell us about the current state of risk in facilities where operational technology is critical?
It tells us that the “air gap” is essentially a myth in the modern industrial landscape. When we looked at the data across 209 organizations, it was startling to see that while 62% of segments seemed solid because they contained a single category of device, that logic fell apart the moment we looked specifically at OT. In reality, the vast majority of these systems are sharing digital air with IT or IoT equipment, creating a tangled web that hackers can easily navigate. For a facility manager, seeing that 87% of OT segments are exposed to non-industrial traffic is nerve-wracking because it means a compromised laptop in the office could theoretically shut down a production line. This lack of isolation turns a localized glitch into a potential site-wide catastrophe, especially when you consider the average segment now holds about 54 different devices.
The research highlights that medical devices are even less isolated than industrial ones, with only 6% in dedicated segments; how does this vulnerability impact the security of healthcare environments?
The situation in healthcare is even more precarious because the stakes involve human lives, not just manufacturing uptime. Seeing only 6% of IoMT devices in dedicated segments is a red flag, particularly when the average device in these environments often belongs to 1.5 segments rather than just one. This overlapping connectivity means that life-critical systems are frequently sitting on the same subnets as guest Wi-Fi or administrative printers. When a segment exceeds 51 devices—which happens in about 11% of the cases we’ve seen—the “blast radius” of a single infection becomes massive. In a hospital setting, this interconnectedness allows malware to jump from a staff member’s tablet directly to an infusion pump or a heart monitor, making containment nearly impossible during a live breach.
IP cameras emerged as one of the least isolated device types, appearing alongside sensitive equipment in thousands of segments—why is this specific oversight so dangerous for modern infrastructure?
IP cameras are the “invisible” backdoors of the modern network; they are ubiquitous yet almost never properly walled off. Out of the 2,266 segments where cameras were detected, a staggering 98% of them were sharing space with other device types, leaving only about 2% of those cameras in exclusive segments. These devices are notorious for having weak default credentials and unpatched firmware, yet they are sitting in the same segments as Point-of-Sale systems or industrial controllers. This creates a perfect jumping-off point for an attacker to gain a foothold and then move laterally into high-value zones. It is a classic example of how a low-cost, peripheral device can compromise a multi-million dollar infrastructure simply because it wasn’t partitioned correctly.
In sectors like retail and oil and gas, the study notes a high risk to specific systems despite industry-wide averages; how should leaders in these sectors rethink their containment strategies?
Leaders need to stop looking at industry averages and start looking at their high-value assets, like Point-of-Sale systems or utility controllers. In retail, for instance, we found that only 20% of segments containing POS systems were dedicated solely to those devices, while the rest were cluttered with VoIP equipment and printers. The goal shouldn’t be a total, expensive network redesign from scratch, but rather a focus on granular visibility and strict containment. From 2026 and through the next few years, the priority must be building a complete inventory and flagging those risky convergences where a printer and a fuel-regulation sensor share the same space. By breaking up oversized segments and restricting unnecessary traffic, you can shrink that “blast radius” significantly without needing to overhaul the entire physical wiring of the plant or store.
What is your forecast for the future of industrial network segmentation?
I expect we will see a decisive shift away from the traditional “perimeter” mindset toward a model of continuous, automated micro-segmentation. As we move from 2026 toward the end of the decade, organizations will stop trying to build one giant wall and instead focus on isolating every high-risk device into its own “cell.” We are already seeing the growth of single-device micro-segments, which currently make up about 17% of the landscape, and I predict that number will double as companies realize that visibility is the best form of defense. Eventually, the network itself will become “self-healing,” where any device that deviates from its expected traffic pattern—like a camera trying to talk to a PLC—is instantly quarantined. The future isn’t about preventing every intrusion, but about ensuring that when an intrusion happens, it has absolutely nowhere to go.

