A lot of teams are in the same place right now. The perimeter firewall is configured, cloud security groups exist, and every new service still seems to need one more exception, one more open port, one more urgent rule change before deploy time.
Then a different problem appears. A compromised process on one server starts reaching sideways to other systems on the same ne...