Network segmentation is the most effective control to prevent lateral movement. In ransomware attacks, attackers often breach one endpoint and move laterally across the network to reach critical assets. Segmentation limits this movement by isolating systems into different zones or subnets, thereby reducing the attack surface and preventing unauthorized internal traversal. DLP and encryption are primarily focused on data protection, not internal network movement. IDS can detect intrusions but does not prevent movement like segmentation does. "Network segmentation limits the scope of access for compromised systems and is a key strategy in preventing lateral movement in an attack." - CISM Review Manual 15th Edition, Chapter 3: Information Security Architecture, Section: Network Security* Real-world example: "In the NotPetya and WannaCry incidents, poor internal segmentation allowed malware to propagate rapidly."