Organizations face significant cybersecurity threats not from exotic malware or zero-day vulnerabilities, but from attackers exploiting trusted internal access paths.
Research by Zero Networks highlights the imperative for companies to shift their cybersecurity strategies from merely preventing access to limiting what resources attackers can reach once they gain entry.
Cyber Resilience Strategy
According to Albert Estevez Polo, Field CTO, EMEA at Zero Networks, resilience is essential for modern cybersecurity. He stated, "What our data analysis confirms in theory—and what recent successful attacks such as those on Jaguar Land Rover, Marks & Spencer, and multiple London councils confirm in practice—is that resilience is key." He emphasized that AI-enabled attacks are likely to intensify this challenge.
Polo elaborated that modern cyber resilience involves limiting lateral movement to contain threats at their entry point, thereby protecting critical assets and ensuring operational continuity. A breach's impact can be mitigated by reducing its blast radius, making it crucial for cyber resilience planning.
Impact on Critical Infrastructure
Polo elaborated that modern cyber resilience involves limiting lateral movement
The assessment by Zero Networks, which involved analyzing 3.4 trillion activities across 400 enterprise environments over a year, indicates that lateral movement following an initial breach can compromise over 60% of an IT environment within an hour. This finding underscores the pressing need for organizations to understand and manage their blast radius effectively.
The study's release coincides with deliberations by a UK parliamentary committee on a proposed Cyber Security & Resilience Bill. Polo remarked, "Resilience must be defined as the ability to largely continue operations—not simply to survive and recover at some unknown point in the future." For critical national infrastructure, this capability is crucial, and Zero Networks has presented its research findings to the Public Bill Committee for consideration.
Technical Insights
Key insights from the report titled "One Compromised System and BOOM, Meet Your Blast Radius" reveal that many threats appear as routine administrative activities. The analysis found that 71% of threat activities utilize common management protocols like SMB, RDP, WinRM, and RPC, essential for business continuity and found in nearly every enterprise environment. These protocols are integral to Windows, Active Directory, and IT operations, making it impractical to disable them.
The study also noted that low-frequency signals could indicate high-risk impacts, such as access to Microsoft SQL Server, System Center Configuration Manager, and Active Directory Web Services, suggesting potential control over core databases and infrastructure. Importantly, the research shows that organizational vulnerabilities often stem from internal misconfigurations, with a single compromised system threatening up to 85% of internal systems in a single hop, and nearly 100% in a second hop, leaving minimal time to respond effectively.
The biggest cybersecurity risks to organizations are not zero-day vulnerabilities or exotic malware, but attackers quietly abusing the same trusted internal access paths businesses rely on every day, research from Zero Networks confirmed today.
Since such breaches are, ultimately, impossible to prevent, organizations need to fundamentally shift their cybersecurity strategies: away from focusing solely on preventing access, and towards limiting what IT assets intruders can reach and exploit once they have achieved initial access.
Cyber resilience plan
“What our data analysis confirms in theory - and what recent successful attacks such as those on Jaguar Land Rover, Marks & Spencer and multiple London councils confirm in practice - is that resilience is key,” said Albert Estevez Polo, Field CTO, EMEA at Zero Networks. “And AI-enabled attacks are only going to accelerate the scale of the issue.”
“Modern cyber resilience depends on limiting lateral movement: containing threats at their point of entry and preventing them from spreading across the environment. By reducing the blast radius of a breach, organizations protect critical assets, maintain operational continuity, and remain resilient even when defenses are bypassed. Simply put, if you don’t know your blast radius, you don’t have a cyber resilience plan.”
Critical national infrastructure
Zero Networks’ assessment is based on the analysis of 3.4 trillion activities across 400 enterprise environments over a year. The data show clearly that business impact is determined less by how attackers get in, and far more by what they can reach once they do. During a successful attack, lateral movement can compromise over 60% of an entire IT environment less than one hour after gaining initial access.
The study is timely as a committee of MPs considers the details of the UK’s proposed Cyber Security & Resilience Bill. “Resilience must be defined as the ability to largely continue operations - not simply to survive and recover at some unknown point in the future. Some may see this as prescriptive, but for critical national infrastructure in particular, this capability must be mandatory,” said Estevez Polo. Zero Networks has submitted the key findings of its research to the Public Bill Committee for consideration.
Key technical findings
Key technical findings from “One Compromised System and BOOM, Meet Your Blast Radius.”:
- Most threats sneak by defenses, appearing like legitimate activities. The most dangerous activity looks legitimate and blends into routine admin behavior.
- Attackers do not need many techniques to be effective. 71% of observed threat activity uses ubiquitous always-on management protocols like SMB, RDP, WinRM and RPC. These are standard Microsoft management protocols found in virtually every enterprise environment. These protocols are foundational to Windows, Active Directory and IT operations. They are required for business continuity and cannot simply be disabled or blocked.
- Low-frequency signals often indicate high-impact risk. Certain systems appeared less frequently in detections, including: Microsoft SQL Server (~3% of detections, ranked 9th); System Center Configuration Manager (2%, ranked 10th); Active Directory Web Services (2%, ranked 11th). While these systems generate fewer alerts, access to them signals potential control over core databases, endpoint management or identity infrastructure.
- Less about attacker skill; more about organizations engineering their own failure points. A single compromised system can reach a median of 85% of internal systems in one hop, and effectively 100% in the second hop. With average compromise within 48 minutes, the time between entry and disruption leaves little to no time to react and take effective countermeasures.