CYB-20 · Cyber security
Ransomware achieves maximum damage through lateral movement across flat networks. Key controls: network segmentation separating client-data systems from general corporate IT, disabled SMBv1, blocked lateral movement at firewall, and application whitelisting or equivalent on servers holding client data.
Trigger
Flat network with no segmentation; SMBv1 enabled on any network device; no firewall rules restricting lateral movement; client data accessible from all network segments
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Implement network segmentation separating client-facing systems from internal corporate IT. Disable SMBv1 on all devices. Restrict lateral movement at firewall layer. Consider microsegmentation for systems holding PII.
Evidence required