Ransomware lateral movement is how attackers spread once they're inside your network — this encore episode breaks down how to stop it before it does real damage.

We're bringing this one back because it's one of our most popular episodes ever — not just in downloads, but in how much of it people actually listened to. A lot of you came back for a second listen, and that told us this one was worth putting back in front of you. This is episode four in our seven-part encore series pulling the best conversations from the archives.

W. Curtis Preston and Prasanna Malaiyandi sit down with networking expert Tom Hollingsworth to talk through exactly how ransomware crawls through a network once it's past the perimeter, and what you can actually do to stop it.

Tom walks through the basics of network segmentation — VLANs, air gaps, and why a flat network, where everything can talk to everything, is a gift to any attacker who gets in. From there the conversation moves into Zero Trust Network Architecture: what it takes to implement it at scale, and why flipping the switch from "allow everything" to "deny by default" generates a mountain of help desk tickets on day one, even though it's the right move.

There's a good stretch on how schools, stadiums, and hotels handle network isolation differently than a typical enterprise, plus a detailed walk-through of incident response — locking down external access, isolating infected segments, keeping your team communicating when the network itself is down, and why every kill switch actually has to be wired to something.

If you've ever wondered how much of this is built into your existing networking gear versus something you have to buy separately, or you just want a clearer mental model for how ransomware spreads once it's inside, this is a great one to revisit.

Chapter Markers:

00:00:00 - Intro and why ransomware lateral movement matters right now

00:01:25 - Welcome back, meet Tom Hollingsworth

00:04:06 - Why isolating the network is step one after a ransomware attack

00:06:07 - Networking basics: how ransomware exploits flat networks

00:09:31 - VLANs, air gaps, and network segmentation

00:14:12 - Zero Trust Network Architecture explained

00:19:02 - Managing zero trust at scale across teams

00:25:48 - Special cases: schools, stadiums, and hotels

00:34:31 - Blocking newly registered domains to stop command and control

00:38:01 - Incident response: locking down the network

00:42:12 - Keeping communication running during an attack

00:44:54 - A real-world story: isolating infected devices

00:50:01 - Building segmentation in from the start