Skip to main content Scroll Top

Stop Attacks you didn’t see coming

The attack vector has changed. Has your defence changed with it?

For years, cybersecurity strategies focused heavily on keeping attackers out.

  • Firewalls.
  • Endpoint protection.
  • Email security.
  • MFA.
  • Vulnerability management.

All are essential.

But there is one uncomfortable reality:

Sooner or later, something gets through.

  • A stolen credential.
  • A compromised laptop.
  • A vulnerable application.
  • A malicious attachment.
  • A cloud workload exposed incorrectly.

And increasingly, the real damage starts after that first compromise.

The attacker’s objective is movement

An attacker rarely lands directly on the organisation’s most valuable system.

Instead, they explore.

They look for relationships between systems, open ports, trusted connections and credentials that allow them to move from one workload to another.

Protocols such as SMB, RDP, WinRM and NetBIOS can suddenly become highways for lateral movement.

This is exactly where traditional perimeter security becomes less effective.

The attacker is already inside.

A simple example

Imagine a company with 1,500 servers across:

  • its own data centre,
  • Azure,
  • AWS,
  • development environments,
  • production environments.

An employee account is compromised through phishing.

The attacker gains access to a relatively unimportant development server.

Nothing critical has happened yet.

But that server can communicate with several production systems over SMB and RDP.

The attacker starts scanning.

Normally, this traffic might disappear amongst millions of legitimate network connections.

But a platform such as Illumio Insights can identify that something has changed.

Suddenly:

A development system that historically had almost no SMB communication is creating connections to dozens of production systems.

That is behaviour worth investigating.

Instead of simply displaying another alert, the organisation can understand:

Which workload initiated the traffic?
Which systems can it reach?
Which attack paths exist?
Which critical assets are exposed?

This significantly reduces the time needed to identify suspicious lateral movement.

But visibility alone is not enough

Knowing that an attacker may be moving through your network is useful.

Being able to stop that movement immediately is considerably more valuable.

This is where Zero Trust Segmentation becomes important.

Instead of relying purely on network topology, VLANs or IP addresses, segmentation policies can be based on business context such as:

  • Role
  • Application
  • Environment
  • Location

For example:

Development systems may communicate with other development systems, but they cannot initiate SMB or RDP sessions toward production.

Or:

Only authorised application servers may communicate with the financial database.

Or:

PCI workloads may only communicate with explicitly approved systems.

The result is simple:

Compromise does not automatically become propagation.

Detection and containment should work together

This is where the combination of Illumio Insights + Illumio Segmentation becomes particularly interesting.

Insights helps organisations understand:

  • What is communicating?
  • What is unusual?
  • Where are the attack paths?
  • Which workloads are exposed?

Segmentation then helps answer:

How do we stop it?

Potentially isolating a compromised workload before the attacker reaches the next system.

That changes the security objective from:

“Prevent every breach.”

to:

“Assume a breach can happen — but make sure it cannot spread.”

This also changes how organisations approach Zero Trust

Zero Trust does not need to mean a massive multi-year transformation.

An organisation can start with something much more practical.

Protect the systems that matter most.

Your:

  • Crown Jewels.
  • For example:
  • intellectual property,
  • financial systems,
  • customer databases,
  • source code,
  • ERP,
  • privileged administration systems,
  • production environments.

Map their dependencies.

Understand who and what can communicate with them.

Then remove the connections that are not actually required.

From there, segmentation can gradually expand.

The security question is changing

The old question was:

“How do we stop attackers getting into our network?”

The better question today is:

“If an attacker gets in tomorrow, how far can they actually go?”

If the answer is:

“We don’t really know.”

then that is probably the first thing to fix.

Because in modern cyber defence, visibility tells you where the risk is. Segmentation determines how far an attacker can travel.

And increasingly, the organisations that can contain an attack quickly will be the organisations that turn a potential major breach into a manageable security incident.

CONTACT E3

Do you recognize your organization in our vision on breach containment ?
We would be happy to meet, learn more about your environment and explore how we can help protect your critical data.

Get in touch with e3 Benelux and let’s secure your business together.

    Hidden fields
    GET IN TOUCH
    CONTACT US

    Philitelaan 57
    5717 AK Eindhoven

    The Netherlands

    Phone: +31 (0)85 065 5254

    Email: info@e3benelux.eu

    We’re glad you find our content valuable. Please note that the material on this website is protected by copyright and may not be copied or reused without prior permission. If you’re interested in using our content, feel free to contact us—we’re happy to discuss proper use