Cyber attacks on universities and hospitals are on the rise, and an essential link in the chain of nearly every one of them is "lateral movement."
The initial breach is rarely the goal. Once an attacker has a foothold on one machine, the damage comes from what happens next: moving sideways, host to host, towards the systems that actually matter. Large, heterogeneous campus networks (flat, shared, full of devices nobody fully owns) make that movement easy. Stopping it is one of the most effective things a defender can do.
What the study asks
Lateral movement is usually treated as a technical problem. This qualitative study takes a different angle. Its goal is to better understand the drivers and barriers of lateral movement from an organisational perspective: why campus networks stay flat, and what makes segmenting them hard in practice.
Because the answer is rarely purely technical. A campus network is flat partly because of how the organisation around it works: many semi-autonomous units, shared infrastructure, and responsibilities that do not line up neatly with network boundaries. To get at that, the study is built on qualitative interviews with representatives from universities and hospitals, asking the people who run these networks rather than just measuring the networks.