R11 — Lateral Movement
Detection finds it; prevention (segmentation) limits it; identity contains it.
What is Lateral Movement?
Detection finds it; prevention (segmentation) limits it; identity contains it. CISO Game tracks this as R11 in the live risk register, severity 8 (Major), category Insider.
How does CISO Game model Lateral Movement?
Exposure for R11 runs from 0 to 100, recomputed live as you buy, cancel, or reassign products. How the exposure model works →
Real-world parallel
Lateral movement is what turns a single compromised endpoint into an enterprise-wide incident. Network segmentation, micro-segmentation (Zero Trust), and credential hygiene (no shared local admin passwords, LAPS, no domain admin reuse) are the structural mitigations. EDR with strong behavioral detection is the alarm system that catches it in flight.
How do security teams mitigate Lateral Movement?
The dominant subscore levers for this risk are:
- Detection subscore — weight 40%
- Prevention subscore — weight 30%
- Identity subscore — weight 30%
Which investments mitigate Lateral Movement?
Products in CISO Game that reduce exposure to R11:
- Mid-Tier EDR (industry standard)EDR
- Premium XDR (full endpoint+identity)EDR
- Open-Source SIEM (self-hosted)SIEM
- Commercial SIEM (mid-market)SIEM
- Enterprise SIEM (heavy/full-featured)SIEM
- Next-Gen Firewall (NGFW)Network
- Network Detection & Response (NDR)Network
- Zero Trust Network Access (ZTNA)Network
Which related risks should you also watch?
Risks with similar dominant subscores or shared category — addressing one often helps the others:
- R09 Insider ThreatInsider · severity 8
- R06 Supply Chain CompromiseExternal · severity 9
- R07 Zero-Day ExploitationExternal · severity 9
- R23 Prompt Injection / JailbreakingAI · severity 8
Why does Lateral Movement matter to a CISO?
Insider risk is uncomfortable but persistent — every employee with access can be the threat. Lateral Movement is mitigated by both technical controls (DLP, behavioral analytics) and program design (offboarding rigor, morale).
How can you test your mitigation strategy?
Click Play CISO Game free to see R11 appear live in your risk register and watch each purchase move the exposure number in real time. No signup required.
Stress-test Lateral Movement in the Post-incident recovery scenario →