Two clocks after a breach – why detection speed is not enough
Expert of the InfoSec division
2026.09.10
A breach starts two clocks: time until detection and time until damage. Mandiant and Palo Alto Networks research shows why SOCs must address both, combining visibility with fast, contextual investigation.
Two weeks under the radar: the window before detection
Mandiant recorded a 14-day global median dwell time for incidents investigated in 2025, compared with 11 days in 2024. This measures the interval between the first evidence of compromise and detection. It is the midpoint of the investigated cases, not a two-week timeline for every intrusion.
While unnoticed, attackers can:
- identify valuable systems;
- steal credentials and escalate privileges;
- move laterally;
- establish persistence;
- prepare data theft.
Cyberespionage and North Korean IT worker cases each had a 122-day median, with legitimate credentials and living-off-the-land techniques helping activity blend in.
Why internal detection matters
Organizations identified 52% of compromises internally in 2025, up from 43% in 2024. These incidents had a nine-day median dwell time. The findings highlight the value of internal visibility, without proving that any particular technology reduces dwell time.
The operational challenge is turning telemetry into action while attacks are still unfolding.
Data theft can happen in minutes
Palo Alto Networks measures time to exfiltration, from initial compromise to confirmed data theft. This differs from dwell time; the figures are not directly comparable.
Its 2025 incident-response dataset showed:
- the fastest quarter reached exfiltration in 72 minutes;
- the previous year’s equivalent was 285 minutes;
- 22% of cases reached exfiltration in less than one hour;
- median time across the dataset was two days.
Detection that appears fast by dwell-time standards may therefore arrive after data theft.
Why SOCs need both speed and long-term visibility
Rapid intrusions and months-long concealment demand:
- Prioritization: recognize urgent signals within routine alerts.
- Context: connect users, hosts, events and threat intelligence.
- Investigation speed: establish what happened without unnecessary delay.
- Historical visibility: correlate activity across longer periods.
- Analyst capacity: reduce repetitive work that obscures important signals.
Mandiant also recommends proactive threat hunting to close visibility gaps and reduce adversary dwell time, rather than relying solely on reactive alerts.
Shortening the path from alert to decision
PULZARIS Analyst Agent supports post-alert investigations through triage, entity and context mapping, threat-intelligence enrichment, prioritization and analyst-ready recommendations. Human analysts retain responsibility for validation and final decisions.
AI cannot promise to eliminate dwell time or prevent every exfiltration attempt. Its role is to shorten the path from signal to understanding and decision, helping defenders use their available time more effectively.
Read the full article on our International subsidiary’s website by clicking on the logo:
