The Economics of Machine Speed
Dwell time, breakout time, and why minutes became the unit that matters.
- Dwell time (compromise → detection) and breakout time (compromise → lateral movement) define the defender's real window.
- Industry measurement has pushed average breakout times under an hour, with fastest cases under three minutes.
- Cost of an incident scales with how far the attacker spread before containment.
- Machine-speed offense makes the first containment actions a machine-speed problem.
Two clocks govern every intrusion. Dwell time runs from initial compromise until the defender detects it. Breakout time runs from initial compromise until the attacker begins lateral movement — the moment one infected laptop becomes a network problem. The entire economics of incident response lives in the gap between those clocks: catch the intruder before breakout and you clean one machine; catch them after and you are scoping, containing, and rebuilding across an environment.
Both clocks have been collapsing. Industry threat reports across recent years have measured average eCrime breakout times falling from hours to well under one hour, with the fastest observed cases under three minutes. Ransomware crews have compressed the full arc — access to encryption — from weeks to days to, in some intrusions, a single shift. The compression is partly professionalization (initial-access brokers selling footholds, affiliates running rehearsed playbooks) and increasingly automation: scripted discovery, automated credential abuse, and now AI-assisted operations that remove the human pauses from the attacker's side.
Run the math from the defender's chair. If breakout can happen in twenty minutes, then a pipeline of alert → queue → analyst pickup → investigation → approval → containment that averages four hours does not just respond slowly — it responds to a different, much larger incident than the one that was detectable at minute one. Every additional hour of dwell time is more credentials harvested, more systems touched, more data staged for exfiltration, and a higher final invoice in recovery cost, downtime, and notification obligations.
This is the argument for AIDR stated plainly: it is not that machines judge better than analysts — they often do not — but that the first, reversible containment moves (isolate the host, suspend the session, block the hash) are worth taking at machine speed precisely because waiting is the most expensive choice. Speed is a security control. The next lesson examines the machinery that makes automated speed safe enough to use.
Keep reading — it's free
Register once to unlock every lesson in the Vijilan Cybersecurity Academy, track your progress, and earn domain badges toward the certification. No cost, no sales pitch.
- Every lesson, free
- Progress tracking
- Domain badges
- No credit card
