Lateral movement is the technique attackers use after an initial compromise to navigate through an environment by exploiting trusted connections between workloads, services, and credentials. In modern cloud and microservices architectures, non-human identities with overly broad permissions create pathways for lateral movement that can span multiple systems. Workload identity policies and zero trust segmentation limit the blast radius when a credential is compromised.