Reining in lateral movement across cloud-hybrid estates
When a finance team in Sydney signs into a SaaS workload at 8am local time and a sysadmin in Perth rotates a token for a Kubernetes cluster a few minutes later, both events look routine on their own. In a cloud-hybrid estate, however, that handshake between an identity provider, a federated SaaS tenant and an on-premises Active Directory forest is exactly the seam an adversary loves. Once a single credential or session token is compromised, attackers no longer need to come back through the front door. They pivot east-west across cloud control planes, ride federation trusts back into corporate directories, and land on workloads that were assumed to be safely tucked behind the firewall.
Lateral movement is rarely the dramatic part of a breach. It is the quiet middle stretch between initial access and the moment ransomware detonates or data is siphoned out. The dwell time in Australian incidents reported to the Australian Cyber Security Centre routinely runs into weeks because defenders see the first indicator, fail to recognise the pivot, and lose the thread as the attacker re-authenticates through legitimate channels. Remediation, then, is less about chasing one-off indicators and more about collapsing the pathways that let a stolen identity move from an Azure subscription to a SharePoint site to an on-prem file share in Brisbane.
Local context shapes how this plays out. Many organisations operate under the Notifiable Data Breaches scheme and APRA CPS 234, which means a slow, identity-driven breach quickly turns into a regulatory headache with mandatory reporting windows. The Essential Eight maturity model from the Australian Signals Directorate further pushes entities toward application control, patching and, crucially for this topic, multi-factor authentication that genuinely resists session replay. None of that matters, though, if an attacker can walk sideways once they are in.
This article walks through how lateral movement unfolds in cloud-hybrid setups, where telemetry gaps let it hide, and what concrete remediation looks like when the goal is not just containment but a faster, cleaner return to a known-good state.
How attackers actually move once they're inside
A modern intrusion rarely starts with a privilege escalation exploit. It usually begins with a phishing email that yields a session cookie, a service principal key lifted from a misconfigured CI pipeline, or a federated identity in a SaaS platform that happens to share a trust with on-premises directories. From there the playbook is predictable: enumerate accessible subscriptions, harvest additional credentials with tools designed to map Active Directory attack paths, abuse Kerberos delegation, and pivot.
In hybrid estates the pivot is often invisible because two systems trust each other by default. An attacker who compromises an Azure AD-joined laptop in Parramatta can use the same cached credential to reach an on-prem file server through Azure AD Connect, then jump back to AWS access keys left in a developer's profile in Pyrmont. Federation amplifies the problem. A single misconfigured SAML trust between an identity provider and a SaaS vendor can let an attacker claim any role they want without ever touching the source directory.
Detection tools frequently miss this hop. Endpoint detection sees a user authenticating to a system they have legitimate rights to. Cloud-native logging shows role assumption that looks like business as usual. Identity providers log sign-ins that appear normal because the attacker is reusing a real, valid session. The result is a flat-looking activity graph with no obvious spike, no obvious anomaly, and plenty of room for the operator to keep moving.
Identity has become the real control plane
The perimeter dissolved somewhere around the time most Australian enterprises embraced remote work, and identity quietly took its place. In cloud-hybrid environments, every workload, API and service account is now an authenticated subject. That makes the identity layer both the most valuable asset and the most fragile.
Remediation has to start with workload identities, not just human ones. Service principals, managed identities and federated service accounts each carry tokens that, once stolen, are equivalent to a domain admin badge. Treating these as second-class citizens is a recipe for the kind of incident where a build pipeline in a Sydney development shop becomes the beachhead for an entire tenant compromise. Conditional access policies need to extend beyond interactive sign-ins. They should govern workload-to-workload calls, restrict token lifetimes, and flag impossible travel between regions like Sydney and Frankfurt.
Multi-factor is necessary but not sufficient. Attackers bypass SMS-based MFA with SIM swaps, which have been a recurring feature of Australian cybercrime reporting. Number matching, FIDO2 keys and certificate-based authentication raise the bar, but only when paired with session binding that ties a token to its originating device and network. Without that binding, an attacker who has phished a session can replay it from anywhere, including a server in another jurisdiction that does not trip conventional geolocation rules.
Telemetry gaps that hide the pivot
Even skilled security teams operate with a partial picture. East-west traffic between cloud workloads is often unmonitored because the underlying virtual networks were built for availability, not observability. Logs from control planes sit in different tenants, with different retention rules, and are queried through different consoles. An analyst investigating a suspicious sign-in in Microsoft Entra might never think to pull VPC flow logs from an AWS account in the same business unit.
A practical remediation programme closes those seams. Centralised log pipelines that ingest Entra sign-in logs, AWS CloudTrail, EKS audit logs and on-prem Domain Controller events into a single searchable store give responders a fighting chance. So does identity-aware network logging that tags traffic with the principal making the call, not just the IP address. Where telemetry cannot be collected, segmentation should at least make movement produce a visible boundary crossing.
The CARM approach treats these gaps as integration problems. Rather than expecting one product to see everything, the platform pulls signals from multiple vendors across endpoint, identity, network and cloud, correlates them, and presents the chain of pivots in a way that a responder in Melbourne or Adelaide can triage during a business-day incident. The point is not to add another dashboard but to remove the manual stitching that slows response and lets adversaries dwell.
Containment that actually works in a hybrid setup
Containment is often where hybrid breaches get messy. Pulling a user account is straightforward. Disabling a service principal that turns out to be running a legitimate payroll integration in five minutes is not. Disconnecting a whole VPC to stop lateral spread can knock over a contact centre in Parramatta. Good remediation balances speed with surgical precision.
The most effective plays share three traits. They identify the trust relationship that was abused, not just the asset that was touched. They revoke or rotate the specific credential or token that enabled the hop. They verify that the same path cannot be retraced before declaring the incident contained. In practical terms, that means revoking refresh tokens, invalidating federation assertions, rotating access keys, and forcing re-authentication across every tenant that shares the compromised identity.
Microsegmentation makes this far easier. When workloads in Sydney, Melbourne and Singapore operate in separate trust zones with explicit ingress and egress rules, an attacker cannot pivot from one to another without producing a logged boundary event. The cost of retrofitting segmentation into a sprawling hybrid estate is real, but it pays off the first time a responder has to contain a breach in a hurry.
Australian compliance and reporting realities
Remediation does not happen in a regulatory vacuum. Under the Notifiable Data Breaches scheme, an organisation that suspects unauthorised access to personal information has thirty days to assess and, if serious harm is likely, seventy-two hours once an assessment is complete to notify affected individuals and the Office of the Australian Information Commissioner. Lateral movement incidents complicate that timeline because by the time the breach is contained, multiple datasets may already be involved, each triggering its own assessment.
APRA-regulated entities face CPS 234 obligations to maintain information security capability commensurate with the size and extent of threats. The Australian Signals Directorate's Essential Eight pushes further, urging application control, restricted admin privileges and, importantly for hybrid cloud-hybrid estates, multi-factor authentication across all privileged access and internet-facing services. These are not abstract benchmarks. They map directly onto the controls that determine whether a lateral movement incident becomes a contained event or a front-page one.
Reporting also shapes the technical response. When a regulator expects a timeline of events, responders need logs that can be reconstructed after the fact. Immutable, centrally stored logs are not just a SOC tool. They are the evidence base that determines whether an organisation's account of the breach holds up to scrutiny from a regulator, a board and, in some cases, the courts.
Hardening what comes next
Once the immediate fire is out, remediation turns into a quieter exercise in reducing the next attacker's options. That is the work that actually changes the trajectory of an organisation's exposure.
Telltale indicators worth watching closely:
- Sign-ins from cloud workloads authenticating to on-prem resources they have never reached before
- Refresh token abuse followed by sudden enumeration of subscriptions, projects or directories
- Federation assertions originating from identity providers that have no known users in a region
- Service principal credentials used outside their expected pipeline or schedule
Practical hardening controls:
- Bind session tokens to device posture and revoke them on suspicious boundary crossings
- Treat every workload identity as a privileged subject, with its own MFA-equivalent control
- Route east-west cloud traffic through identity-aware proxies that log principal context
- Rotate federation signing certificates and audit trust paths on a defined cadence
The practical takeaway is uncomfortable but honest. In a cloud-hybrid estate, the path between an Office 365 mailbox and an operational technology environment in Gladstone is shorter than most security architectures acknowledge. Closing that path is not a single product decision. It is a steady programme of identity discipline, telemetry integration and segmentation that turns quiet, identity-driven movement into something an Australian security team can see, contain and, when the time comes, prove they handled properly.