IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand

Network segmentation - you can't attack what you can't see

Mon, 17th Aug 2026 (Today)
Anthony Caruana
ANTHONY CARUANA Interview Editor

Threat actors are exploiting weaknesses and vulnerabilities in physical infrastructure to infiltrate networks to steal data and infect systems with ransomware and other malicious payloads. Since 2013, when Target USA's point-of-sale systems were compromised through an attack chain that started at an air conditioning system, organisations have been on notice to harden and protect infrastructure.

Any device that is connected to a network that has access to the internet is a potential target. That can be anything from a router to a security camera used to monitor a sensitive area.

Many of those devices are not designed to be hardened with endpoint protection software. That puts the network at the heart of a robust defensive strategy.
Chuck Davis, Vice President for Global Information Security at Hikvision, said it wasn't that long ago that these devices were analogue. But as those devices moved to being connected to IP networks, there's been a significant shift in how they are managed.

"These devices shouldn't be treated any differently than a laptop or a server. In today's environments, a security camera is no longer just a camera. It's a network-connected device running software and communicating across the broader IT environment. That means it needs the same attention to hardening, patching, monitoring, and network segmentation as any other IT asset."

Today's facilities managers operate in a far more connected environment than they did just a few years ago. As physical security systems become increasingly IP-based, they need a working understanding of network fundamentals and cybersecurity best practices to help maintain secure operations.
Davis' view on network security is simple, "If you can't reach it, you can't compromise it."

He adds: "Securing devices on a network means ensuring they sit behind a firewall or inside a secure network segment. Insider threats are real, so we want to make sure devices are segmented properly so a compromised endpoint cannot be used to pivot to a security camera or other physical device. Role-based access control is important from a user perspective, but from a network perspective, making sure devices are isolated from parts of the network they do not need to access is critical."

One of the challenges the managers of physical infrastructure face is patching. Davis said the onset of frontier AI models with cybersecurity capabilities and the ability to find vulnerabilities or even chain together a bunch of vulnerabilities to gain access to devices has changed the security industry. That's leading companies to use AI models to help build more secure products to find vulnerabilities before they go to production.

While it may be possible to patch some devices, others may be hard to access or may have their warranties or support contracts voided if their software is altered. Medical devices, for example, may be running older versions of operating systems. If the operating system is patched, the device may lose regulatory approval. This is why understanding vulnerabilities and risk are critical.

"If you have a critical vulnerability on a device that is accessible from the Internet you need to patch it urgently. If it's sitting behind a firewall with restricted access, the immediate risk is likely much lower. Organisations need a risk management plan to ensure they patch the most exposed and highest-risk systems promptly," said Davis.

Being on the front foot is becoming increasingly important. The time between security patches being released and threat actors reverse engineering them to produce exploits has drastically reduced.

According to data published by Zero Day Clock, the average time between public disclosure and observed exploitation fell from 21.5 days in 2025 to roughly one day in 2026.

The site projects that the window could fall to one hour and eventually to less than a minute. Under those circumstances, organisations cannot rely on patching alone. Network security is one of the most important defenses we have right now," he said.

Perhaps the most popular defensive strategy being used today is zero trust. The idea that every interaction is verified is not new, but it can be difficult to execute on embedded devices. Applying traditional zero-trust controls to embedded devices can be more challenging because those devices often do not support the same endpoint security agents, monitoring tools, and validation capabilities commonly used on laptops, desktops, and servers.

Davis says the question you need to ask is whether you trust those devices to be on the same network as your sensitive data. If the answer is no, the best approach is to isolate that onto a separate network.

The importance of robust isolation was highlighted when an AI program being run by OpenAI escaped a sandboxed environment and attacked systems at Hugging Face.

Every network connected device can become a potential entry point that can be weaponised by a malicious party. Robust segmentation, timely patch management, and zero trust principles are no longer optional. They are essential defences against fast evolving AI driven exploits. By isolating critical assets, enforcing role based controls, and prioritising high risk systems, organisations can close gaps before attackers turn an otherwise ordinary device into a weapon.