Lateral movement drives most breaches and can cross a flat network in under an hour. Segmentation is what turns one compromised host into a contained incident.
Draft outline · Security / reliability lens2025 breach data (Verizon DBIR and the Illumio segmentation research) puts lateral movement in 60 to 70% of successful breaches, with observed propagation as fast as 18 to 48 minutes. A flat network is the amplifier; hub-spoke with enforced segmentation is the containment.
Industry breach data quantifying how often lateral movement features and how fast it is.
Named incident reporting where a lack of segmentation turned a foothold into an enterprise event.
Leads with containment and reliability, with security as the driver rather than a scare. It shows the landing zone is designed for the bad day, and reinforces that we deploy an opinionated topology rather than hand over a diagram.