Summary is AI-generated, newsdesk-reviewed
  • Zero Networks: Shift to limiting asset exposure post-initial access to enhance cybersecurity strategies.
  • Cyber resilience requires containing threats, reducing breach blast radius, and limiting lateral movement.
  • Attackers exploit common protocols like SMB, RDP; resilience needed for national infrastructure protection.

Organizations face significant cybersecurity threats not from exotic malware or zero-day vulnerabilities, but from attackers exploiting trusted internal access paths.

Research by Zero Networks highlights the imperative for companies to shift their cybersecurity strategies from merely preventing access to limiting what resources attackers can reach once they gain entry.

Cyber Resilience Strategy

According to Albert Estevez Polo, Field CTO, EMEA at Zero Networks, resilience is essential for modern cybersecurity. He stated, "What our data analysis confirms in theory—and what recent successful attacks such as those on Jaguar Land Rover, Marks & Spencer, and multiple London councils confirm in practice—is that resilience is key." He emphasized that AI-enabled attacks are likely to intensify this challenge.

Polo elaborated that modern cyber resilience involves limiting lateral movement to contain threats at their entry point, thereby protecting critical assets and ensuring operational continuity. A breach's impact can be mitigated by reducing its blast radius, making it crucial for cyber resilience planning.

Impact on Critical Infrastructure

Polo elaborated that modern cyber resilience involves limiting lateral movement

The assessment by Zero Networks, which involved analyzing 3.4 trillion activities across 400 enterprise environments over a year, indicates that lateral movement following an initial breach can compromise over 60% of an IT environment within an hour. This finding underscores the pressing need for organizations to understand and manage their blast radius effectively.

The study's release coincides with deliberations by a UK parliamentary committee on a proposed Cyber Security & Resilience Bill. Polo remarked, "Resilience must be defined as the ability to largely continue operations—not simply to survive and recover at some unknown point in the future." For critical national infrastructure, this capability is crucial, and Zero Networks has presented its research findings to the Public Bill Committee for consideration.

Technical Insights

Key insights from the report titled "One Compromised System and BOOM, Meet Your Blast Radius" reveal that many threats appear as routine administrative activities. The analysis found that 71% of threat activities utilize common management protocols like SMB, RDP, WinRM, and RPC, essential for business continuity and found in nearly every enterprise environment. These protocols are integral to Windows, Active Directory, and IT operations, making it impractical to disable them.

The study also noted that low-frequency signals could indicate high-risk impacts, such as access to Microsoft SQL Server, System Center Configuration Manager, and Active Directory Web Services, suggesting potential control over core databases and infrastructure. Importantly, the research shows that organizational vulnerabilities often stem from internal misconfigurations, with a single compromised system threatening up to 85% of internal systems in a single hop, and nearly 100% in a second hop, leaving minimal time to respond effectively.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...