Lesson 1 of 1 in Lateral Movement
One Laptop, The Whole Organisation
The reason a single infected machine is a company-wide crisis: attackers move sideways. Reused local passwords, stolen credentials and flat networks let a foothold on one unremarkable computer become control of everything it can reach.
3 min read
Not yet reviewed
If they land on one reception laptop, that is contained, isn't it? It is just the one machine.
It is never just the one machine. From that laptop I can see the others. If the local administrator password is the same everywhere — and it so often is — then one is all of them. I do not re-break in. I walk.
That walk is the difference between an incident and a catastrophe. And the thing that stops the walk is a wall the attacker cannot see through or a credential that does not fit the next lock.
Legal
Moving from a machine you are authorised to use to one you are not — even inside the same network — is unauthorised access. Lateral movement is taught here so you understand why internal walls matter and where to build them, not so you cross them on a network that is not yours.
Why sideways is so easy
Lateral movement thrives on sameness and trust. Networks are often flat — once you are inside, everything can talk to everything — and credentials are often shared, so the key that opened one machine opens the next. The attacker rarely needs a new exploit to move; they need a reused password and a path that was never blocked.
Reused local admin password one password, every machine, one fall
Stolen credentials reused the key from box A fits box B
Flat network inside is inside; nothing stops east-west
Trust relationships this server is allowed to reach that one
- Line 1The classic. Image every laptop from the same template with the same local administrator password, and compromising one hands over all of them.
- Line 3A flat network treats "inside the perimeter" as "trusted". The perimeter is one phished click thick, and then there are no more walls.
In 2017 the NotPetya malware turned a single foothold into worldwide damage in hours, crippling shipping, logistics and manufacturing companies. It used a known exploit and stolen credentials to spread from machine to machine automatically. What made it so devastating was not how it got in — so what was it?
Building internal walls
The defences all make the inside less uniform and less trusting: segment the network so a machine can only reach what it genuinely needs, give every machine a unique local administrator password so one fall is not all of them, require a second factor on internal services and not just the perimeter, and watch east-west traffic — machine talking to machine — for the patterns that only an intruder makes.
Flat and uniform
Same local admin password everywhere.
Inside the perimeter is fully trusted.
Any machine can reach any other.Segmented and unique
A different local password per machine.
Internal services still ask for proof.
Machines reach only what their job needs.The left column is one bad click away from total loss; the right turns the same click into a contained mess. The attacker's walk only works while the floor is flat.
One thing you can do this week: at home, put the devices you trust least — the smart TV, the random gadgets — on your router's guest network, away from your computers and phones. It is network segmentation at the smallest scale, and it is the same idea that stops a walk becoming a catastrophe.