Common signs include unusual east-west traffic, unexpected communication between workloads, and ransomware or malware reaching systems that should not be reachable. If an attacker can move beyond the initial entry point, segmentation rules are either too permissive, incomplete, or not enforced consistently. That usually means the environment still allows trusted internal paths that should be restricted.
What network segmentation should be preventing during an active attack
network segmentation is supposed to limit where an attacker can go after initial access. When it is working, compromise should stay contained to a small part of the environment, with no easy path to adjacent systems, shared services, or sensitive workloads. Signs of failure usually show up as movement that should have been blocked, delayed, or isolated.
In practice, containment is not just about one firewall rule. It depends on routing, policy enforcement, identity-aware access, and whether internal trust assumptions have been reduced enough that compromise in one zone does not automatically expose others.
How to read east-west traffic as a containment signal
Unusual east-west traffic is one of the clearest indicators that segmentation is not containing an intrusion. The key question is not whether internal traffic exists, but whether the traffic pattern matches normal application dependencies. If a workstation starts talking to database hosts, file servers, admin tools, or other segments it never normally touches, that is a containment failure signal.
Unexpected communication between workloads can also mean an attacker has found a path around the intended control plane. That may happen through permissive rules, overly broad subnets, shared credentials, forgotten exceptions, or protocols that were allowed for convenience and never revisited. This is where segmentation stops being a design feature and becomes an assumption that needs verification.
Watch for lateral movement patterns that chain together multiple internal systems, especially where the destination is outside the original blast radius. If the traffic looks more like discovery, remote execution, or credential harvesting than business application use, the segmentation boundary is not doing enough work.
When malware reaches systems it should never reach
Another strong sign of failed containment is malware or ransomware reaching assets that should be unreachable from the initial foothold. If the attacker can touch backup systems, management planes, jump hosts, identity infrastructure, or other privileged segments, then the segmentation model has already been bypassed in a material way.
That usually means one of three things: the policy is too permissive, the enforcement points are inconsistent, or the architecture still trusts internal placement too much. In all three cases, the practical result is the same, the attack can spread farther than the design intended.
Segmentation also fails when exceptions pile up over time. A rule that once supported a short-term project can become a permanent bridge for attackers. The more unmanaged exceptions, shared services, and overlapping trust zones you have, the harder it becomes to prove that containment still exists when an incident starts.
Risk and Threat Considerations
When segmentation is not containing an active attack, the main risk is blast radius expansion. What should have been a local compromise can become credential theft, privileged lateral movement, ransomware propagation, or access to systems that hold business-critical or recovery data.
Failure mechanism: The attacker uses allowed internal paths, excessive trust between zones, or inconsistent enforcement to move laterally and reach assets that were supposed to be isolated.
Impact: Containment breaks down, recovery becomes harder, and the incident can spread into backup, management, or sensitive production environments before defenders realize the boundary failed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | PR.AA-01 — Identity Management and Access Control | Segmentation failures often hinge on internal trust and access paths. |
| Recommendation — Apply least-privilege access so internal paths do not become lateral-movement routes. | ||
| NIST CSF 2.0 | PR.AA-05 — Network Integrity and Segmentation | Directly addresses segmented network boundaries and containment of internal traffic. |
| Recommendation — Validate segmentation rules and enforce separation between trust zones. | ||
| NIST SP 800-53 Rev 5 | SC-7 — Boundary Protection | Boundary controls are central when an attack crosses from one internal zone to another. |
| Recommendation — Enforce boundary controls that restrict unauthorized internal connectivity. | ||
| CIS Controls v8 | CIS-12 — Network Infrastructure Management | Segmentation depends on managed, reviewed network configuration and routing paths. |
| Recommendation — Review network configurations and remove unintended internal communication paths. | ||
| MITRE ATT&CK | T1021 — Remote Services | Unexpected internal service use is a common sign of post-compromise lateral movement. |
| Recommendation — Hunt for unauthorized remote service use across internal segments. | ||
Practitioner Guidance
What to verify: Compare observed east-west flows against the intended application dependency map, not against a static network diagram. If you cannot explain why a connection exists, treat it as a containment question before treating it as a tuning issue.
Decision rule: If the attacker can move from a low-trust segment into a higher-value segment, prioritize isolation and rule correction over deep malware cleanup alone. Containment first, eradication second.
Practitioner takeaway: Segmentation is only effective if it blocks the attack path that actually exists, so the real test is whether an intruder can cross boundaries without creating a clearly abnormal internal traffic pattern.
Related resources from NHI Mgmt Group
- What are the signs that healthcare segmentation is not containing an attack effectively?
- What are the signs that an advanced persistent threat may be active in a network?
- What are the signs that network segmentation is failing against east west attacks?
- What are the signs that network segmentation is too weak to stop an attacker from moving through an environment?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org