Skip to main content
A weather vane stands against a bright blue sky with puffy white clouds.
Analyst Insights

Lateral Movement Update: 3 Ways to Stop the Sideways Steal of Data Across Your Network

After penetrating the perimeter, hackers can execute lateral movement—and survey network structure, identify targets, seize data—in under a half hour. Old-school defense tactics (and, yes, AI and automation) can stop cybercriminals in their tracks.

The breach started quietly, and the lateral movement was easy to miss.

When suspicious traffic flickered inside MITRE Corp., a federal research nonprofit, investigators grew alarmed. Digging deeper, they found a nation-state hacker had slipped past the network perimeter and was moving “east-west”—that is, laterally across the infrastructure—with ease. Compromised administrative credentials gave the intruder license to roam, unchecked and almost invisible.

MITRE contained the intrusion and disclosed what it knew. But that 2024 incident underscored how the fight against cybercrime often begins not at the perimeter of a computer network, where firewalls and other traditional security tools have long struggled to fend off attacks, but after hackers are already inside.

A few weeks later, the Change Healthcare cyberattack drove that point home. Hackers gained remote access to a server that lacked multifactor authentication (MFA). Once inside, they moved laterally across the network for nine days, causing months of disruptions in payments and patient care. At least 192.7 million individuals were affected by the breach.

That’s the worry with so-called “east-west” or lateral traffic—now involved in a majority of all successful breaches, which made it a key theme at this year’s RSA conference. If an organization has spent most of its time fortifying “north-south” traffic, or the data moving in and out of networks, but hasn’t applied the same rigor internally, it is leaving itself dangerously exposed.

Attackers can do serious damage in a short time. And they’re getting faster once they’ve penetrated networks, executing lateral movement in as few as 27 minutes, or 48 minutes on average, according to ReliaQuest’s 2025 Annual Threat Report.

“Time is the enemy in cybersecurity,” said Michael McPherson, ReliaQuest senior vice president of technical operations, in a statement. “Attackers are moving faster than ever, which means our defenses must speed up as well.”

Why lateral movement remains a major threat

Lateral movement is a multi-stage process involving reconnaissance, credential theft, and exploitation.

Attackers are moving faster than ever, which means our defenses must speed up as well.
Michael McPherson, senior vice president of technical operations, ReliaQuest

Cybercriminals breach a network using techniques like phishing, exploiting known vulnerabilities, or leveraging stolen credentials. Then they survey the network structure, map devices, and identify desirable targets, such as domain controllers, which authenticate users and enforce permissions, or database servers. Finally, they go to work by seizing or corrupting data, stealing credentials for future illicit activities, or planting keyloggers and other monitoring programs to eavesdrop on private communications.

[Read also: And how do intruders gain access in the first place? Lately, it’s IT workers letting them in—welcome to help desk hell]

What makes this so damaging is how it turns a single breach into a network-wide compromise, letting attackers reach more valuable systems and data while hiding in plain sight with stolen credentials. The longer they remain undetected, the more time they have to reach crown jewels, plant backdoors, and launch broader ransomware, espionage, and other campaigns.

3 key ways to prevent lateral movement

What’s particularly insidious about this form of attack is its subtle and almost silent nature. By leveraging lateral movement, attackers can blend in seamlessly with other legitimate network traffic, like a bandit camouflaged amongst pedestrians on a crowded street. Any countermeasures, if they are to be effective, must recognize the telltale signs of such movements and block the potential pathways that leave a network vulnerable.

To thwart this kind of stealth activity, many companies are embracing the old notion of defense-in-depth, blending modern security approaches, such as zero trust, with infrastructure controls, microsegmentation, and network detection and response (NDR) capabilities.

1. Zero trust, no assumptions

Because the crux of the problem involves hackers moving from location to location without having been digitally stopped along the way, zero trust offers a practical solution. A term coined by former Forrester principal analyst John Kindervag, who is now chief evangelist at Illumio, zero trust set out to reverse a decades-old misperception that there are both trusted and untrusted sides to a network.

Traditionally, once you were authenticated to get onto a network, you could go wherever you wanted…. That’s stupid. Zero trust eliminates that.
John Kindervag, chief evangelist, Illumio

“Traditionally, once you were authenticated to get onto a network, you could go wherever you wanted,” he tells Focal Point. “But every packet needs to have a policy attached to it. You should determine where it goes explicitly instead of saying, ‘Well, once you get to the trusted side, you can go anywhere.’ That’s stupid. Zero trust eliminates that assumption of trust.”

[Read also: And don’t trust your old password—the new thinking on password security might surprise you]

Zero trust takes a policy-driven approach rooted in the old “need to know” concept. Every request to access a domain, use an application, or open a file is reviewed, and if there’s no legitimate role-based reason, it’s denied. This trustless model is growing more popular with enterprise and security leaders as network threats posed by disinformation grow, and deepfakes and other AI-fueled tools make it easier than ever to impersonate employees. More than 80% of organizations plan to adopt zero trust by 2026, according to a Zscaler survey.

2. Microsegmentation in focus

Microsegmentation is another common solution organizations are applying to the east-west traffic problem. Supporting zero trust, it divides networks into smaller zones so intruders can’t roam freely once they are inside. Conversely, traditional segmentation divides networks into broader zones, utilizing devices such as firewalls and VLANs. As such, it doesn’t reach the granularity needed to enforce zero trust policies.

“Microsegmentation, if done correctly, can be the foundation of really good security,” says Chase Cunningham, Ph.D., chief strategy officer at Demo Force and widely known as Dr. ZeroTrust. “Even if there is a breach, they’re stopped from going further and making it more catastrophic. Microsegmentation basically helps eliminate mega-breaches.”

Cunningham says microsegmentation is especially valuable in operational technology (OT) and Internet of Things (IoT)—heavy industries, like healthcare or oil and gas, where systems support clear and specific use cases. It makes it possible to logically separate devices, so, for example, a controller can only talk to the machine it was built to operate.

It’s also gaining traction right now because the tools enabling it have finally matured, he says.

“Microsegmentation as a technology field in the market wasn’t really available until maybe three years ago,” Cunningham says. “Now, if I was chief security officer at a company, I’d microsegment the hell out of everything and then work my way toward other problems.”

Still, the work isn’t easy. Cunningham says organizations often stumble when they take on too much at once.

“The complexity comes when folks say, ‘Cool, we’re going to do microsegmentation,’” he says. “Then they go, ‘Well, microsegment what?’ It has to be a project and a plan. You can’t just turn the button on and say, microsegment. Something’s going to go wrong.”

3. NDR—your eyes on the inside

Even when segmentation is done right, intruders may still find ways to operate laterally. That’s why many organizations are turning to NDR tools. While zero trust and microsegmentation set the rules of engagement, these solutions act like a watchtower. They don’t enforce segmentation. But they do monitor traffic across and within zones, using analytics and AI to flag suspicious east-west movement that would otherwise slip past firewalls and endpoint tools.

Intruders aren’t busting down the front door. They’re using your hallways, your doors, your stairwells—and… they look like they belong there.
Chase Cunningham, Ph.D., chief strategy officer at Demo Force

This visibility is critical, Cunningham explains, because intruders often resemble legitimate users once inside the network.

“Intruders aren’t busting down the front door,” he says. “They’re using your hallways, your doors, your stairwells—and unless you’ve got the right sensors in place, they look like they belong there.”

To strengthen visibility, organizations also use identity and access management (IAM) systems to verify users and machines. IAM reduces the attack surface by enforcing least privilege, removing excessive or outdated access, and limiting lateral movement across systems. IAM helps enable zero trust by authenticating and authorizing users and endpoints, enforcing granular access policies, and monitoring activity.

[Read also: What is cybersecurity exposure management? Learn the proactive strategy that spots and assesses risk across an org’s entire attack surface]

Newer identity-threat detection tools add another layer by spotting when stolen credentials are being abused inside the network. Policy-orchestration platforms help provide the maps and controls needed to apply zero trust and microsegmentation consistently. Together, these technologies give defenders a chance to spot attackers moving east-west and shut them down before they escalate into a full-blown breach.

AI and automation: Taking lateral movement to the next level

While effective, these defenses are no silver bullet. Attackers are already experimenting with ways to automate lateral movement using AI, which could accelerate reconnaissance and credential abuse once they get inside. Cunningham believes defenders can keep pace—but only if they stop treating east-west visibility as optional.

“The adversaries don’t wait for you to get your budget sorted,” he says. “They’re innovating whether you are or not.”

Proactive security teams are already testing out the ways AI and automation can be used to defend against such attacks. Machine learning can be effective at detecting anomalies in user behavior and overall network activity, isolating threats automatically and devising rapid, precise responses that can thwart attackers mid step.

[Read also: Here’s how to map lateral movement, anticipate potential attack paths, and assign impact ratings to assets—all in one solution]

Kindervag advises enterprise leaders that any shift or upgrade in security solutions or protocols has to be strategic, not piecemeal. Zero trust, microsegmentation, and detection tools are only effective if they’re tied to a clear understanding of what needs to be protected and why.

“All significant cybersecurity events are the result of an allow rule,” he says. “Everything comes down to policy. What am I allowing? What am I denying? That’s how you stop attackers from moving around once they’re in.”

The reality is that breaches will happen. What matters is whether they remain contained or metastasize into a MITRE- or Change Healthcare-style incident. The enterprises that embrace a defense-in-depth model, verify every connection, and watch their networks closely are the ones most likely to keep east-west movement from becoming front-page news.