Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network
A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

Key points
- More than 80% of enterprise servers were reachable from any point inside their own network, according to Zero Networks' 2026 Lateral Movement Exposure Report.
- The report analysed 54 trillion network events across 312 live enterprise environments.
- 87% of enterprise servers accepted remote-access connections from broad internal sources as of the report's publication date.
- 43% of internal login traffic still used NTLM, an outdated authentication protocol that attackers routinely abuse to impersonate legitimate users.
- 12% of organisations allowed a single employee device to connect directly to the most sensitive servers on the network.
Most people picture a company's network like a fortress: hard walls on the outside, safe on the inside. New research suggests the inside is nowhere near as safe as companies assume.
Zero Networks, a network-security firm, published its 2026 Lateral Movement Exposure Report after studying 54 trillion recorded network events across 312 live corporate environments. Over 80% of corporate servers, the powerful machines that hold company data and run business applications, could be reached from any other device already inside the same network.
How does that put ordinary people at risk?
Once a criminal gets one foot inside a corporate network, perhaps by tricking a single employee into clicking a bad link, that broad internal access means they can roam freely. No exotic tools are required. The same everyday remote-access utilities IT staff rely on do the job: RDP (Remote Desktop Protocol, software that lets someone control a computer from across the office), SSH (Secure Shell, a similar tool used on server systems), and SMB (Server Message Block, the protocol Windows computers use to share files). The report found 87% of servers accepted RDP or SSH connections from wide internal sources, and 78% were reachable via SMB or WinRM (Windows Remote Management).
Free movement across a network is the key ingredient in most ransomware attacks, where criminals lock every file until a ransom is paid. Our 7 July story on the Gentlemen ransomware gang showed exactly this playbook: get in once, then use trusted IT tools to reach everything else.
Dray Agha, senior manager of security operations at Huntress, a firm that monitors networks for threats, told CSO Online the findings match what his team sees daily. "Most network perimeters are hard on the outside but lose that hostility and become flat on the inside," he said.
The report also found that 43% of internal login traffic relied on NTLM, an older authentication protocol that attackers have exploited for years to steal credentials and climb to higher access levels. Retiring it is technically awkward in large organisations, but leaving it running is a standing invitation for abuse.
Robby Winchester, chief of professional services at SpecterOps, told CSO Online his teams achieve internal movement on nearly every test engagement. The paths exist, they're hard to spot, and most organisations have no automated way to close them. David Sancho, a senior threat researcher at Trend Micro, added a caveat worth keeping: reachability shows potential blast radius, not a certainty of compromise.
Should you worry?
If you're a customer or employee of a large organisation, this is a prompt, not a panic. The practical risk from any single breach depends on how quickly the organisation detects unusual movement inside its own network. Ask your employer whether it runs regular internal security tests and whether it limits which computers can talk to which.
The countermeasures researchers point to: divide networks into smaller isolated zones (micro-segmentation), enforce strict rules about which accounts reach which systems, retire legacy protocols like NTLM, and run red-team exercises where a friendly team tries to break in and reports what they found. None of that is simple in environments built over decades, but the alternative is leaving the inside of the fortress unguarded.



