Forescout

103 stats9 reports

All Statistics

In segments with PoS systems, 46% include printers, 36% include VoIP, and 30% include IP cameras

RetailIoTPoint Of Sale

There are 2,266 segments with IP cameras, representing almost 5% of all segments

IP CamerasIoTNetwork Segmentation

Nearly half of segments with OT or IoMT devices also mix in IT and IoT assets

Operational TechnologyMedical DevicesNetwork Segmentation

Nearly 90% of SSH servers remain non-PQC-capable.

PQCSSH Servers

Total PQC-capable SSH servers grew from 6.2% to 11.8%.

PQCSSH Servers

SSH servers supporting PQC increased 72% from 11.5 million to over 19 million.

PQCSSH Servers

All tested AI models now complete vulnerability research tasks, and 50% generate working exploits autonomously

Vulnerability ResearchExploit DevelopmentAI SecurityAI Models

A year ago, 55% of AI models failed basic vulnerability research and 93% failed exploit development tasks

Vulnerability ResearchExploit DevelopmentAI SecurityAI Models

Every model produced at least one false-positive run by hallucinating vulnerable paths in the OpenNDS real-world task

False PositivesVulnerability ResearchOpenNDS

Telnet exposure in healthcare is 8%, up from 6%.

TelnetHealthcareLegacy Protocols

40% of the riskiest device types are new compared to last year.

Device RiskEnterprise

75% of the riskiest device types are new compared to two years ago.

Device RiskEnterprise

24% of devices across organizations are classified as part of the extended IoT, including IoT, OT, and IoMT.

Device DiversityIoTOTIoMT

11% of devices across organizations are classified as network equipment.

Device DiversityNetwork Equipment

There are 3,200 unique operating system versions observed across organizations, averaging 876 versions per organization.

Operating Systems

47% of newly exploited vulnerabilities were originally published before 2025.

Forescout2025H1 Threat Review·1y ago
ThreatsVulnerabilities

51% of threat actor updates in H1 2025 were attributed to cybercriminals, such as ransomware groups.

Forescout2025H1 Threat Review·1y ago
ThreatsThreat actors

9% of threat actor updates in H1 2025 were attributed to hacktivists.

Forescout2025H1 Threat Review·1y ago
ThreatsThreat actorsHacktivists

19% of industrial organizations identify their cybersecurity maturity as evolving.

Industrial OTMaturity

50% of industrial organizations claim that supply chain threats and cybercriminal activity are their top security concern.

Industrial OTSupply chain

8% of industrial organizations claim that nation-state actors are their top security concern.

Industrial OTNation stateAPTs

44% of hacktivist attacks in 2024 targeted government and military entities.

HacktivismGovernmentMilitary

18% of hacktivist groups targeted Asia, including the Middle East.

HacktivismAsiaMiddle East

Less than 1% of hacktivist attacks impacted organizations in the Americas.

HacktivismAmericas

This year universal gateways and historians appeared for the first time on the list of riskiest OT devices.

OT devices

Four new IT device types were added to the 2025 Forescout riskiest connected devices list: Application Delivery Controllers (ADC), Intelligent Platform Management Interfaces (IPMI), Firewalls, and Domain Controllers.

Connected devicesIoT devices

Four new IoMT device types were added this year to Forescout's riskiest connected devices list: imaging devices, lab equipment, healthcare workstations, and infusion pump controllers.

IoMT devices

54% of network segments contain only IT devices

IT InfrastructureNetwork Segmentation

26% of network segments contain IT and IoT devices

IoTNetwork Segmentation

4% of network segments contain IT, IoT, and IoMT devices

IoMTNetwork Segmentation

Of all segments containing OT devices, 13% are OT-only

Operational TechnologyNetwork Segmentation

Of all segments containing IoMT devices, 6% are IoMT-only

Medical DevicesNetwork Segmentation

62% of analyzed network segments contain a single device category

Network SegmentationIT Infrastructure

29% of analyzed network segments contain two device categories

Network SegmentationIT Infrastructure

9% of analyzed network segments contain three or more device categories

Network SegmentationIT Infrastructure

Each network segment holds an average of 54 devices across four device types

Blast RadiusNetwork Segmentation

17% of analyzed segments are micro-segments with a single device

Network SegmentationIT Infrastructure

72% of analyzed segments have between two and 50 devices

Network SegmentationBlast Radius

11% of analyzed segments have more than 51 devices

Network SegmentationBlast Radius

On average, each device is part of 1.5 segments

Network OverlapDevice Management

Out of 478 segments where a PoS was identified, only 95 (20%) are exclusive to PoS systems

RetailPoint Of SaleNetwork Segmentation

Out of IP camera segments, only 51 (2%) contain only IP cameras

IP CamerasNetwork Segmentation

In IP camera segments, 60% include workstations, 47% include printers, and 37% include servers

IP CamerasWorkstationsServers

50% of the device functions most commonly found in mixed segments rank among 2026's riskiest devices

Device RiskIoTOperational Technology

Business and professional services, healthcare, and oil & gas have the largest average blast radius

Industry RiskBlast Radius

Only 3% of identified servers running Dropbear – common in embedded devices – support PQC

PQCSSH ServersDropbear

50% of IT devices in enterprise networks use OpenSSH versions that support PQC

PQCOpenSSHEnterprise

In enterprise networks, IT devices most commonly support PQC on TLS (8%), while specialized devices are again left behind (5.6% for IoT and IoMT, 0.8% for OT)

PQCTLSEnterprise

40% of OpenSSH servers on the internet now support PQC by default

PQCSSH Servers

Claude Opus 4.6 identified exploitable RCE vulnerabilities in 3 of 5 runs.

Vulnerability ResearchClaude OpusRCE VulnerabilitiesExploitable Vulnerabilities