Forescout
Reports
All Statistics
In segments with PoS systems, 46% include printers, 36% include VoIP, and 30% include IP cameras
There are 2,266 segments with IP cameras, representing almost 5% of all segments
Nearly half of segments with OT or IoMT devices also mix in IT and IoT assets
Nearly 90% of SSH servers remain non-PQC-capable.
Total PQC-capable SSH servers grew from 6.2% to 11.8%.
SSH servers supporting PQC increased 72% from 11.5 million to over 19 million.
All tested AI models now complete vulnerability research tasks, and 50% generate working exploits autonomously
A year ago, 55% of AI models failed basic vulnerability research and 93% failed exploit development tasks
Every model produced at least one false-positive run by hallucinating vulnerable paths in the OpenNDS real-world task
Telnet exposure in healthcare is 8%, up from 6%.
40% of the riskiest device types are new compared to last year.
75% of the riskiest device types are new compared to two years ago.
24% of devices across organizations are classified as part of the extended IoT, including IoT, OT, and IoMT.
11% of devices across organizations are classified as network equipment.
There are 3,200 unique operating system versions observed across organizations, averaging 876 versions per organization.
47% of newly exploited vulnerabilities were originally published before 2025.
51% of threat actor updates in H1 2025 were attributed to cybercriminals, such as ransomware groups.
9% of threat actor updates in H1 2025 were attributed to hacktivists.
19% of industrial organizations identify their cybersecurity maturity as evolving.
50% of industrial organizations claim that supply chain threats and cybercriminal activity are their top security concern.
8% of industrial organizations claim that nation-state actors are their top security concern.
44% of hacktivist attacks in 2024 targeted government and military entities.
18% of hacktivist groups targeted Asia, including the Middle East.
Less than 1% of hacktivist attacks impacted organizations in the Americas.
This year universal gateways and historians appeared for the first time on the list of riskiest OT devices.
Four new IT device types were added to the 2025 Forescout riskiest connected devices list: Application Delivery Controllers (ADC), Intelligent Platform Management Interfaces (IPMI), Firewalls, and Domain Controllers.
Four new IoMT device types were added this year to Forescout's riskiest connected devices list: imaging devices, lab equipment, healthcare workstations, and infusion pump controllers.
54% of network segments contain only IT devices
26% of network segments contain IT and IoT devices
4% of network segments contain IT, IoT, and IoMT devices
Of all segments containing OT devices, 13% are OT-only
Of all segments containing IoMT devices, 6% are IoMT-only
62% of analyzed network segments contain a single device category
29% of analyzed network segments contain two device categories
9% of analyzed network segments contain three or more device categories
Each network segment holds an average of 54 devices across four device types
17% of analyzed segments are micro-segments with a single device
72% of analyzed segments have between two and 50 devices
11% of analyzed segments have more than 51 devices
On average, each device is part of 1.5 segments
Out of 478 segments where a PoS was identified, only 95 (20%) are exclusive to PoS systems
Out of IP camera segments, only 51 (2%) contain only IP cameras
In IP camera segments, 60% include workstations, 47% include printers, and 37% include servers
50% of the device functions most commonly found in mixed segments rank among 2026's riskiest devices
Business and professional services, healthcare, and oil & gas have the largest average blast radius
Only 3% of identified servers running Dropbear – common in embedded devices – support PQC
50% of IT devices in enterprise networks use OpenSSH versions that support PQC
In enterprise networks, IT devices most commonly support PQC on TLS (8%), while specialized devices are again left behind (5.6% for IoT and IoMT, 0.8% for OT)
40% of OpenSSH servers on the internet now support PQC by default
Claude Opus 4.6 identified exploitable RCE vulnerabilities in 3 of 5 runs.