The biggest cybersecurity risks to organizations are not zero-day vulnerabilities or exotic malware, but attackers quietly abusing the same trusted internal access paths that businesses rely on every day, according to research from Zero Networks. Since such breaches are almost impossible to prevent, organizations need to fundamentally shift their cybersecurity strategies: away from focusing solely on preventing access and towards limiting what IT assets intruders can reach and exploit once they have achieved initial access.
“What our data analysis confirms in theory – and what recent successful attacks such as those on Jaguar Land Rover, Marks & Spencer and multiple London councils confirm in practice – is that resilience is key,” said Albert Estevez Polo, Field CTO, EMEA at Zero Networks. “And AI-enabled attacks are only going to accelerate the scale of the issue.
“Modern cyber resilience depends on limiting lateral movement: containing threats at their point of entry and preventing them from spreading across the environment. By reducing the blast radius of a breach, organizations protect critical assets, maintain operational continuity, and remain resilient even when defences are bypassed. Simply put, if you don’t know your blast radius, you don’t have a cyber resilience plan.”
Zero Networks’ assessment is based on the analysis of 3.4 trillion activities across 400 enterprise environments over a year. The data show clearly that business impact is determined less by how attackers get in, and far more by what they can reach once they do. During a successful attack, lateral movement can compromise over 60% of an entire IT environment less than one hour after gaining initial access.
Other key findings from the research include:
Attackers do not need many techniques to be effective. 71% of observed threat activity uses ubiquitous always-on management protocols like SMB, RDP, WinRM, and RPC. These are standard Microsoft management protocols found in virtually every enterprise environment. These protocols are foundational to Windows, Active Directory, and IT operations. They are required for business continuity and cannot simply be disabled or blocked.
Low-frequency signals often indicate high-impact risk. Certain systems appeared less frequently in detections, including Microsoft SQL Server (~3% of detections, ranked 9th); System Center Configuration Manager (2%, ranked 10th); Active Directory Web Services (2%, ranked 11th). While these systems generate fewer alerts, access to them signals potential control over core databases, endpoint management, or identity infrastructure.
Breaches are Less about attacker skill; more about organizations engineering their own failure points. A single compromised system can reach a median of 85% of internal systems in one hop, and effectively 100% in the second hop. With average compromise within 48 minutes, the time between entry and disruption leaves little to no time to react and take effective countermeasures.
About the research Zero Networks conducted the research between December 2024 and December 2025 across customer environments and verified penetration testing engagements. It analysed approximately 3.4 trillion activities across 400 enterprise environments.






