In its inaugural 2026 Lateral Movement Exposure Report, Zero Networks states that 80% of enterprise servers are reachable from anywhere inside the network – creating ‘greenfield conditions’ for ransomware, operational disruption, and full-environment compromise. This internal traffic, known as East West traffic, represents more than 70% of a company’s communications – yet it remains unprotected.
The report has been produced after analysing 54 trillion activities across 312 enterprise environments over a period of one month.
Key findings include:
- Roughly 80% of enterprises have already deployed internal AI agents, yet two-thirds lack governance policies for them – creating rapidly expanding unmanaged attack surfaces.
- 87% of enterprise servers accept inbound RDP or SSH connections from broad internal sources, giving attackers wide access pathways once inside the network.
- 78% of enterprise servers are reachable over SMB or WinRM, the same administrative protocols attackers commonly exploit for ransomware spread and lateral movement.
- 43% of internal authentication traffic still relies on NTLM, a legacy protocol frequently abused for credential replay and privilege escalation attacks.
- 12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.






