Only Thirteen Percent Was Real
An analysis of operational technology networks this week found that only 13% of network segments are fully isolated, meaning nearly all the rest lean on trust, leaky firewall rules, or hope rather than a real boundary. In the same week a UK official told The Record that AI is set to help attackers much more than defenders, and separate reporting described AI agents rewriting the rules of lateral movement, which is exactly the stage segmentation exists to stop. More than a third of industrial organisations now list cybersecurity risk as a top obstacle to growth. When a vendor or an agency writes "secure by design" into a contract or a pitch deck, this is the actual gap between that phrase and what an attacker finds once they're inside: not a vault, but a corridor with most of the doors left unlocked.
Security teams have a phrase they use in sales decks and a phrase they use to each other, and this week the gap between them got a number attached. An analysis of operational technology networks found that only 13% of network segments are fully isolated. That leaves nearly all the rest connected in ways that let one compromised device become a path to everything else on the network. "Secure by design" as a line item usually means someone drew boundaries on a diagram. It rarely means those boundaries hold.
The label and the wall
Segmentation is the thing that turns "we got breached" into "we lost one machine" instead of "we lost the network." It's not glamorous and it doesn't show up well in a pitch, which is probably why it's the gap that persists. The 13% figure isn't about one careless company, it's an analysis across OT environments, the kind of infrastructure that increasingly touches marketing and business operations too, from connected retail hardware to industrial clients running campaigns alongside production systems.
More than a third of industrial organisations now say cybersecurity risk is a top obstacle to growth. Risk has stopped being a line item the SOC handles quietly. It's now sitting in growth planning meetings, which means it's sitting in the conversations agencies have with clients about what can actually get built, and how fast, before someone in procurement asks an uncomfortable question about segmentation.
This matters for agencies specifically because so much client work now runs through infrastructure the agency doesn't own and rarely audits: connected devices in retail environments, industrial clients' operational networks, third-party platforms bolted onto a campaign. A pitch deck can promise isolation. Only a test can prove it.
Attackers are getting faster, not smarter
A UK official told The Record that AI is set to help attackers much more than defenders. That's a direct claim from inside government about where the current advantage sits, not a hedge. Separate reporting on AI agents describes them rewriting the rules of lateral movement, which is precisely the stage where segmentation is supposed to stop an intruder cold. If the wall was already mostly theoretical, an attacker with a faster way to find the gaps doesn't need to be clever. Just quick.
The rest of this week's reporting reads like a demonstration of that speed. A CVSS 10.0 flaw in VeloCloud Orchestrator is being actively exploited in certificate-based setups. A SharePoint flaw that Microsoft initially listed as mere spoofing turns out to enable authenticated remote code execution, which is a much bigger deal than the original label suggested. Zyxel switches are being exploited by Chinese state-linked hackers. D-Link has warned of a max severity zero-day bug in its DIR-822A routers. A Microsoft Defender exploit dropped shortly after its author's identity was revealed, which tells you something about how fast the window between disclosure and weaponisation is closing.
None of these are exotic. They're the ordinary, everyday infrastructure that sits behind marketing stacks, client portals, and agency networks, and each one is a door that doesn't care how good your segmentation diagram looks on a slide. A new Linux kernel flaw is also reported to give ARM64 KVM guests read-write access to host memory, which matters for anyone running client workloads on shared cloud infrastructure, which by now is most agencies.
Even the more abstract capability news points the same direction. GPT-6 Astra reportedly broke an old Enigma message. On its own that's a research curiosity, a party trick for cryptography nerds. But it's also a small, concrete proof that AI systems are getting faster at exactly the kind of pattern-breaking work that underlies both cryptanalysis and, further down the stack, credential and configuration guessing against the same real networks the 13% figure describes.
What this costs the business side, not just the SOC
DORA's second year is now asking a blunter question of regulated firms: can your SOC actually see the attack, not just log that one happened after the fact. That's a visibility standard, and it's the same standard a client should be applying to any vendor or agency claiming "secure by design." A diagram is not visibility. A contract clause is not isolation. If a regulator is now asking financial firms to prove they can watch an attack unfold in real time, that's a reasonable bar to hold anyone else to as well.
There's also a supply chain angle that agencies building on modern web stacks can't wave off. A malicious NPM package, distributed under the name B-tree, has accumulated millions of downloads. If any part of a client's stack pulls dependencies the way most JavaScript projects do, that risk isn't sitting in someone else's industry. It's sitting in the same package manager most build pipelines already use, quietly, until someone finally checks the download count.
None of this is theoretical for people running workspace tools either. There's a webinar this week specifically on real-world Google Workspace breaches, which suggests the gap between "we use Workspace, it's secure" and what actually happens when it's breached is common enough to fill an hour of case studies.
What to actually ask before you sign
None of this requires becoming a security team. It requires asking sharper questions of the vendors and platforms already in the stack, before the contract gets signed rather than after the breach report.
- Ask for evidence of segmentation, not a diagram. A diagram shows intent. A test shows whether a compromised device can actually reach anything else on the network.
- Ask who audits dependencies in the build pipeline, given that a single malicious package can sit in a supply chain accumulating millions of downloads before anyone notices.
- Ask whether the SOC, yours or a vendor's, can demonstrate visibility into an attack while it's happening, not just produce a report afterwards. That's the DORA Year Two question, and it applies well outside regulated finance.
- If Workspace or a similar tool sits in the stack, ask what a real-world breach of that environment actually looks like in practice, not in theory. That's a solvable question if someone bothers to ask it before signing.
- Ask whether shared cloud infrastructure has been checked against recent kernel-level flaws, rather than assuming the hosting provider has already handled it.
"Secure by design" is a fine phrase. It just needs to survive contact with a number. This week's number is 13%.