Lateral Movement
Lateral movement is when an attacker moves from one compromised system to others inside a network.
Updated: 2026-03-06
Definition
After initial access, attackers often move laterally to reach high-value systems or data.
Segmentation, least privilege, and monitoring help reduce and detect lateral movement.
Key points
- Common after initial compromise
- Goal: reach valuable systems/accounts
- Defend with segmentation and strong IAM
Common mistakes
- Flat networks with broad access between segments.
- Shared admin credentials across many systems.
Related exams
Related terms
Want to practice this in exam-style questions?
Use the mini tests on each exam page, then continue in the app for offline packs and detailed explanations.
Go to exams