Two clocks are running after a breach – and defenders need to beat both
Cybersecurity teams often measure their effectiveness by how quickly they detect an attacker. But recent incident-response research shows that there is not just one clock running after a compromise.
One measures how long attackers can remain inside before anyone notices. The other measures how quickly they can achieve something damaging before detection even happens.
The latest findings from Mandiant and Palo Alto Networks illustrate why both matter – and why modern SOC operations increasingly depend on speed, context and prioritization rather than simply generating more alerts.
14 days before detection
The global median dwell time across incidents investigated in 2025 reached 14 days, up from 11 days a year earlier.
Dwell time is the period between the first evidence of compromise and detection. Fourteen days therefore does not mean that every attacker remains hidden for two weeks, but that the midpoint of Mandiant's investigated cases did.
That is a considerable operating window.
During that time, an attacker may be able to:
- explore systems and identify valuable assets;
- harvest credentials and increase privileges;
- move laterally through the environment;
- establish persistence;
- prepare data theft or another high-impact action.
The longer an intrusion remains invisible, the more opportunity the adversary has to turn an initial foothold into a much more complex incident.
Some attackers are deliberately playing an even longer game. 122-day median dwell time in both cyberespionage cases and incidents involving North Korean IT workers. These actors frequently rely on legitimate credentials, living-off-the-land techniques and activity designed to blend into normal operations.
Internal detection makes a difference
There is a more encouraging figure in the same research.
Organizations discovered 52% of compromises internally in 2025, compared with 43% in 2024. Incidents detected internally had a median dwell time of nine days, considerably below the 14-day global median.
This does not prove that any individual security technology automatically reduces dwell time. It does, however, underline the value of internal visibility and effective detection capabilities.
The challenge is therefore not simply collecting more telemetry. The SOC must be capable of turning that telemetry into something actionable while an attack is still developing.
But attackers may not need 14 days
This is where a second clock becomes important.
Palo Alto Networks measures time to exfiltration: the period between initial compromise and confirmed data theft. It is different from dwell time and the two statistics should not be directly compared.
But together they reveal an uncomfortable reality.
In a 2025 incident-response dataset:
- the fastest 25% of intrusions reached data exfiltration in just 72 minutes;
- a year earlier, the equivalent figure had been 285 minutes;
- 22% of cases reached exfiltration in less than one hour;
- across the complete dataset, median time to exfiltration was two days.
So an organization could theoretically detect an intrusion relatively quickly by traditional dwell-time standards – and still discover it after sensitive data has already left the environment.
The defensive window is not simply shrinking. Its length can vary enormously depending on the attack.
The SOC has to solve both ends of the problem
Security teams therefore face two very different adversaries at the same time.
One may move extremely quickly, progressing from access to data theft in minutes or hours. Another may remain almost invisible for months, patiently using legitimate tools and credentials.
That has several operational consequences for SOC teams:
- Prioritization becomes critical. A seemingly routine alert may represent the beginning of a rapidly developing incident.
- Context matters more than isolated alerts. Users, hosts, previous events, threat intelligence and historical activity need to be connected.
- Investigation speed matters. Detection alone is not enough if analysts still need considerable time to determine what actually happened.
- Historical visibility remains essential. Slow-moving threats require correlation across longer periods, not just attention to what happened in the last few minutes.
- Human attention is a limited resource. When analysts are overwhelmed by repetitive investigation work, the important signal can remain hidden among hundreds of less relevant alerts.
Mandiant makes a similar point in its recommendations: relying only on reactive alerts is insufficient against sophisticated, evasive attackers, and proactive threat hunting can help close visibility gaps and reduce adversary dwell time.
From alert speed to investigation speed
This is also where AI can have a meaningful role in SOC operations.
PULZARIS Analyst Agent is designed to support the investigation process after security alerts are generated. Rather than leaving analysts to manually collect and interpret every piece of evidence, the AI-assisted workflow can triage alerts, map relevant entities and context, enrich findings with threat intelligence, evaluate priority and prepare analyst-ready recommendations. The human analyst remains responsible for validation and the final decision.
The objective is not to claim that AI automatically eliminates dwell time or prevents every fast-moving exfiltration attempt. The value lies elsewhere: reducing the distance between signal, understanding and decision.
When attackers may have either 14 days to hide or only 72 minutes to cause damage, that distance increasingly determines how much time the defender really has.


