Glossary

Lateral Movement

Once hackers get into one computer on your network, they don't stop there. Lateral movement is how they jump from computer to computer, looking for the good stuff - your financial data, customer records, or admin passwords. One compromised laptop can lead to your entire network being owned.

What is Lateral Movement?

Techniques that attackers use to move through a network after gaining initial access, pivoting from one compromised system to others in search of valuable data or additional access.

Why Should You Care?

Lateral movement transforms a single compromised system into a full network breach, allowing attackers to escalate privileges and reach high-value targets like databases and admin accounts. Once inside, attackers can pivot from one system to the next to gain broad access, multiplying both the attack surface and remediation costs. Organizations face not just immediate incident response expenses, but extended downtime, regulatory penalties, and reputational damage when lateral movement goes undetected—which can persist for months.

Is your business exposed?

Real-World Example

In the WannaCry ransomware outbreak of 2017, attackers used the EternalBlue exploit to gain initial access, then moved laterally across vulnerable systems within corporate networks, ultimately encrypting thousands of computers across hospitals, government agencies, and enterprises worldwide. Healthcare networks are especially affected: a ransomware intruder who moves laterally into clinical systems can force hospitals to divert patients and revert to paper records, showing how lateral movement directly impacts patient care delivery.

How to Protect Against Lateral Movement

  1. 1.

    Implement network segmentation

  2. 2.

    Use different passwords for different systems

  3. 3.

    Deploy endpoint detection and response

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required