All work
Research · Study

Lateral movement in heterogeneous networks

Qualitative studyUniversities & hospitalsOrganisational perspective

Cyber attacks on universities and hospitals are on the rise, and an essential link in the chain of nearly every one of them is "lateral movement."

The initial breach is rarely the goal. Once an attacker has a foothold on one machine, the damage comes from what happens next: moving sideways, host to host, towards the systems that actually matter. Large, heterogeneous campus networks (flat, shared, full of devices nobody fully owns) make that movement easy. Stopping it is one of the most effective things a defender can do.

What the study asks

Lateral movement is usually treated as a technical problem. This qualitative study takes a different angle. Its goal is to better understand the drivers and barriers of lateral movement from an organisational perspective: why campus networks stay flat, and what makes segmenting them hard in practice.

Because the answer is rarely purely technical. A campus network is flat partly because of how the organisation around it works: many semi-autonomous units, shared infrastructure, and responsibilities that do not line up neatly with network boundaries. To get at that, the study is built on qualitative interviews with representatives from universities and hospitals, asking the people who run these networks rather than just measuring the networks.

A campus network environment — the setting for the lateral-movement study
Heterogeneous campus networks: where an attacker's sideways movement is hardest to see and hardest to stop

A two-page summary

A short summary of the study is available as a two-pager.

Download the study summary (PDF, German)

Take part

If you would like to participate in the study, or are interested in its results, get in touch at info@narrowin.com.

← All work