What this diagram shows
Attack paths rarely stop at the firewall. They move from the public internet through exposed services, into internal VLANs, workstations, and business systems.
- Internet-facing exposure and weak remote access
- Internal lateral movement opportunities
- Hosts and services that raise portfolio risk
- Where Protect / Detect / Respond / Recover apply