Skip to main content
HomeTopicsLateral Movement

Lateral Movement

Cybersecurity statistics about lateral movement

Showing 1-15 of 15 results

80% of enterprise servers are reachable from anywhere inside the network, creating greenfield conditions for ransomware, operational disruption, and full-environment compromise.

Zero Networks6/15/2026
Network SecurityRansomware

6.5% of the 832 malicious accounts banned between March 2025 and March 2026 used AI to assist with lateral movement.

Anthropic6/6/2026
AI in Cybercrime

57% of healthcare and manufacturing security leaders rank microsegmentation as their top initiative to stop lateral movement.

Elisity & Omdia5/27/2026
MicrosegmentationHealthcare

Nearly half of healthcare and manufacturing security leaders experienced a lateral movement attack in the past year.

Elisity & Omdia5/27/2026
HealthcareManufacturing

52% of healthcare leaders cite lack of continuous monitoring for lateral movement and segmentation failures as a critical or significant limitation.

Elisity5/27/2026
HealthcareNetwork Monitoring

37.5% of organizations report Lateral Movement

Lumos5/27/2026
Internal Vulnerabilities

Threat actors utilizing AI and automation tools can achieve lateral movement within an organization in as little as 4 minutes, 85% faster than the previous year.

ReliaQuest5/27/2026
AI in CybercrimeAutomation

On average, lateral movement within an organization takes 34 minutes, 29% quicker than the 48 minutes recorded in 2024.

ReliaQuest5/27/2026
Threat Actor Tactics

96% of incidents involving lateral movement end with the release of ransomware.

Barracuda2/22/2026
Ransomware

67% of security leaders lack visibility into access behaviour and lateral movement.

Gurucul8/21/2025
Access behaviorLateral movement

76% of organizations have at least one public-facing asset that enables lateral movement.

Orca Security6/5/2025
CloudLateral movement

47% say that a challenge in securing and managing hybrid cloud is the lack of comprehensive insight and visibility across their environments, including lateral movement in East-West traffic.

Gigamon5/21/2025
CloudHybrid cloud

DirectDefense mapped alerts to the MITRE ATT&CK® framework to identify the top five tactics. The top five tactics identified are: Initial Access, Persistence, Lateral Movement, Execution, and Credential Access.

DirectDefense4/15/2025
MITRE ATT&CKInitial access

For Lateral Movement, the most observed technique by DirectDefense is Valid Accounts, using stolen credentials to escalate privileges. Alerts triggered for Lateral Movement include: Lateral Movement – Local Credentials.

DirectDefense4/15/2025
MITRE ATT&CKLateral movement

96% of attackers targeting energy and utilities sector relied on remote services to move laterally.

Trustwave1/1/2025
EnergyUtilities