Fejléc

Two clocks after a breach – why detection speed is not enough

Szerző ikon Expert of the InfoSec division

Dátum ikon 2026.09.10

A breach starts two clocks: time until detection and time until damage. Mandiant and Palo Alto Networks research shows why SOCs must address both, combining visibility with fast, contextual investigation.

Two weeks under the radar: the window before detection

Mandiant recorded a 14-day global median dwell time for incidents investigated in 2025, compared with 11 days in 2024. This measures the interval between the first evidence of compromise and detection. It is the midpoint of the investigated cases, not a two-week timeline for every intrusion.

While unnoticed, attackers can:

  • identify valuable systems;
  • steal credentials and escalate privileges;
  • move laterally;
  • establish persistence;
  • prepare data theft.


Cyberespionage and North Korean IT worker cases each had a 122-day median, with legitimate credentials and living-off-the-land techniques helping activity blend in.

Why internal detection matters

Organizations identified 52% of compromises internally in 2025, up from 43% in 2024. These incidents had a nine-day median dwell time. The findings highlight the value of internal visibility, without proving that any particular technology reduces dwell time.

The operational challenge is turning telemetry into action while attacks are still unfolding.

Data theft can happen in minutes

Palo Alto Networks measures time to exfiltration, from initial compromise to confirmed data theft. This differs from dwell time; the figures are not directly comparable.

Its 2025 incident-response dataset showed:

  • the fastest quarter reached exfiltration in 72 minutes;
  • the previous year’s equivalent was 285 minutes;
  • 22% of cases reached exfiltration in less than one hour;
  • median time across the dataset was two days.


Detection that appears fast by dwell-time standards may therefore arrive after data theft.

Why SOCs need both speed and long-term visibility

Rapid intrusions and months-long concealment demand:

  • Prioritization: recognize urgent signals within routine alerts.
  • Context: connect users, hosts, events and threat intelligence.
  • Investigation speed: establish what happened without unnecessary delay.
  • Historical visibility: correlate activity across longer periods.
  • Analyst capacity: reduce repetitive work that obscures important signals.


Mandiant also recommends proactive threat hunting to close visibility gaps and reduce adversary dwell time, rather than relying solely on reactive alerts.

Shortening the path from alert to decision

PULZARIS Analyst Agent supports post-alert investigations through triage, entity and context mapping, threat-intelligence enrichment, prioritization and analyst-ready recommendations. Human analysts retain responsibility for validation and final decisions.

AI cannot promise to eliminate dwell time or prevent every exfiltration attempt. Its role is to shorten the path from signal to understanding and decision, helping defenders use their available time more effectively.

Read the full article on our International subsidiary’s website by clicking on the logo:

Do you have a question? Are you interested in the solution? Contact our colleagues!