TB-9768 · REV D · Technical newsheet
Test & MeasurementDevice profile
Forescout 2025 Report Documents Rising Device Vulnerabilities
Forescout's 2025 report logs a year-over-year rise in device vulnerabilities across IT, IoT, OT and IoMT estates, pushing firmware lifecycle data into the asset-management record.
By Amara Osei2 min read455 words
Features
- Forescout's 2025 report documents a surge in device vulnerabilities across IT, IoT, OT and IoMT domains
- The four-domain framing covers enterprise IT, embedded IoT, long-lived OT equipment and connected medical devices
- The report series relies on passive device fingerprinting, the non-intrusive discovery method suited to OT and clinical networks

Forescout's 2025 risk report, summarized by Industrial Cyber, records a year-over-year surge in device vulnerabilities spanning four distinct network domains: conventional IT, Internet of Things (IoT), operational technology (OT) and the Internet of Medical Things (IoMT).
The finding matters to test and measurement readers for a straightforward reason: vulnerability density is now a measurable property of the installed base, not a property of software alone. Bench instruments, protocol gateways, building sensors and bedside medical monitors all ship with network stacks, and each stack adds attack surface that a calibration program does not cover. A multimeter's accuracy class tells you nothing about the firmware image running on its Ethernet option card.
The four-domain framing reflects how enterprise networks actually operate. IT assets — servers, workstations, printers — receive routine patching on defined cycles. IoT devices, often deployed by business units outside engineering control, frequently run unpatched embedded Linux for their entire service life. OT equipment, including PLCs, RTUs and industrial protocol converters, may sit in production for fifteen to twenty years, with vendor support windows that long outlast the security assumptions of the era in which the hardware was designed. IoMT compounds the problem: infusion pumps, imaging peripherals and patient monitors mix life-critical availability requirements with consumer-grade operating systems.
Forescout's report series builds on passive network discovery — fingerprinting devices from traffic rather than authenticated scans — which is the standard non-intrusive method for OT and clinical environments where an active scan can interrupt a process or a patient. The 2025 edition's headline conclusion, as reported, is directional rather than numeric in the available summary: vulnerability counts are rising across all four categories.
For engineering teams, the report's signal is procedural. Device inventory, firmware versions and end-of-support dates now belong in the same configuration record as calibration due dates and accuracy traceability. A vulnerability assessment that ignores the instrument fleet is incomplete in the same way a calibration program that ignores drift is incomplete.
The report also implicitly raises a procurement question. When two instruments offer equivalent measurement performance, the one with a committed firmware patch cadence, a signed image chain and a stated end-of-security-support date carries lower lifetime risk. Datasheets rarely state these terms; they increasingly should be contract line items.
The open question the report leaves with asset owners is one of scope and cadence: how often must an organization re-enumerate its device population to keep vulnerability posture current, and who owns that task for devices that sit physically inside the plant or the clinic but logically outside the patching infrastructure? Until asset inventories reconcile with network reality at a defined interval, the vulnerability curve Forescout describes is unlikely to bend.
via Google News: Sensors and industrial IoT (Source)
Filed under
- device-vulnerabilities
- ot-security
- iot-security
- firmware-management
- calibration
More from Amara Osei
Show full bio
Senior reporter covering industry trends and analytics at Testbench Report.
22 articles
Application notes
- FBG Wins RM40 Million Contract for Miros Crash Test Equipment
- Machine Vision's Post-IMTS 2026 Question: System, Not Sensor
- Tracing as a Firmware Oscilloscope for Zephyr RTOS Designs
- Camtek Posts Q1 2026 Earnings Beat on Semiconductor Test Demand
- AI Chip Demand Drives Record Profits for Taiwan Test Equipment Makers