Skip to Content

Dwell time: the gap that decides the size of the damage

Why the time between compromise and containment defines the cost of an incident, and how leaders can measure it
August 24, 2026 by
Dwell time: the gap that decides the size of the damage
Kleber Leal by Zamak Portal

At a mid-sized law firm, the first evidence of a problem came from a seemingly ordinary conversation. The client in a merger deal mentioned over the phone that the other side seemed to know, with uncomfortable precision, the concession limit set days earlier in an internal meeting. No system had gone down, no files were encrypted, and no security alert had been triggered in the preceding weeks. The investigation revealed that a partner's legitimate credential had been used by someone else for seven weeks, silently reading the folder that held the entire negotiation.

That gap between the initial compromise of an access and its effective containment has a technical name, dwell time (the length of time an intruder remains inside the environment), and it is almost always treated as an IT metric. It works better as a financial one, because every additional week inside the environment increases the volume of information read, copied and eventually traded outside the company, reducing in equal measure the bargaining power of whoever responds to the incident.

According to the Microsoft Digital Defense Report 2024, the median time between a user clicking a fraudulent email and the attacker beginning to move across the corporate network is approximately 72 minutes. At the other end of the timeline, the IBM Cost of a Data Breach Report points to an average of close to 258 days between the initial breach and full containment. Between those two numbers lies a void of months, and it is inside that void that the problem stops being technical and becomes commercial.

What happens inside the gap no one is measuring

What makes this gap so long is the nature of the access being used. When someone logs in with a valid password, approved authentication and a time of day consistent with that user's routine, the environment does not record an intrusion, it records work in progress. The Microsoft Digital Defense Report 2024 counts more than 600 million identity attacks per day, and most of them are after exactly that, a borrowed badge instead of a broken-down door. From that point on, the intruder's behavior is indistinguishable from that of a dedicated professional who opens a lot of documents.

That is why additional layers of prevention reduce the probability of entry without shortening dwell time. Email filters, network segmentation and multifactor authentication work like doors and locks, deciding who gets through at a specific moment, while dwell time is determined by continuous observation and by human decision after someone is already through. A company can consistently increase its investment in blocking and leave virtually unchanged the number of weeks an unauthorized access survives inside the environment.

The cost of an attack that disrupts nothing is precisely the hardest to see in the budget. At a law firm, the asset at risk does not appear on the balance sheet, since what is at stake is the confidentiality of a litigation matter, the strategy behind a due diligence (the prior audit of a company ahead of an acquisition) and the trust of clients who handed their most sensitive information to a third party. When that information circulates outside the firm's control, the loss materializes in mandates that are not renewed, in confidentiality clauses that are breached and in uncomfortable conversations with the client's legal committee.

How to treat dwell time as a business metric

The conversation changes in quality when the manager stops asking which tools are installed and starts demanding three numbers with a date and an owner. The first is MTTD (Mean Time To Detect), which measures how long it takes between the event and the realization that it exists. The second is decision time, which measures how long it takes between that realization and formal authorization to act. The third is MTTC (Mean Time To Contain), which closes the cycle and reveals the real maturity of the operation.

The second move is to require active hunting, or threat hunting (the deliberate search for signs of compromise without a prior alert), as a contracted and measurable deliverable, with a report of the hypotheses tested in each period. It is worth asking the vendor how many investigations were opened without an automated alert in the previous quarter, because that number separates those who merely operate a dashboard from those who actually search. Capabilities in threat intelligence applied to your context make that search specific, guided by how attackers have been operating against companies of your size and in your sector.

Finally, verify two conditions that underpin everything else. Activity log retention must cover a period longer than the dwell time you consider plausible, otherwise you will be investigating a window with no evidence available, and identity telemetry must track behavior over time, beyond the moment of login. A managed cybersecurity service with continuous monitoring gives that backup to the internal team, which remains the owner of the business context and the priorities.

5 questions every manager should ask

1. If a legitimate credential from my company were being used by someone else right now, how long would it take for someone to notice, and who exactly would notice?

2. What is the real cost of an attack that disrupts nothing, with no systems down and no files encrypted, just confidential client information circulating outside my control?

3. Why don't growing investments in prevention shorten the gap between the intrusion and the containment?

4. Who has formal authority to isolate a machine, revoke a session or lock a partner's account in the middle of a closing week?

5. How does an internal IT leader show a partner or the C-level that risk has come down, using time-based metrics instead of a tool count?

If a legitimate credential from my company were being used by someone else right now, how long would it take before anyone noticed, and who exactly would notice?

The question sounds technical but functions, in practice, as a test of organizational design. In most companies with 5 to 5,000 employees, the honest answer is that no one would notice spontaneously, because detection depends on comparing an account's current behavior against its historical pattern, a task no professional performs manually at scale.

The second half of the question matters as much as the first. If the answer is the IT team, confirm whether that expectation is written down somewhere or is merely a shared assumption, because responsibility that is not formally assigned tends to become no one's responsibility at the moment of an incident.

What is the real cost of an attack that disrupts nothing, just confidential client information circulating outside my control?

The cost shows up displaced in time and under line items rarely associated with security, such as legal fees, insurance premiums, discounts granted to retain an unsettled client, and future revenue that simply never materializes. In a firm that lives on confidentiality, a single leak of litigation strategy can end a relationship built over a decade.

There is also the regulatory and contractual cost. Contracts with large clients typically require notification within short deadlines and subsequent audits, and the inability to demonstrate when the access began turns a manageable event into a negotiation from a position of weakness.

Why don't growing investments in prevention shorten the interval between the breach and containment?

Prevention acts on the probability of an event happening, while dwell time acts on the consequence of an event that has already happened. These are two distinct dimensions of the same risk, and buying more blocking layers improves only the first, leaving the second dependent on qualified human observation and fast decision-making.

When someone starts actively looking for weak signals, the logic reverses. The operation stops waiting for a behavior to cross a threshold and starts forming hypotheses about how an attacker would act in that specific environment, testing each one against the available data.

Who has the formal authority to isolate a machine, revoke a session, or lock a partner's account in the middle of closing week?

This is the question that causes the most discomfort in executive committees, and also the one that most reduces containment time when answered in writing. Without defined authority, the technician who spots the problem hesitates in the face of hierarchy, and that hesitation costs hours of additional access to whoever is inside the environment.

The practical recommendation is to create a matrix with three levels of action, defining what can be executed immediately, what requires approval from a named owner, and what requires a collective decision, with a maximum deadline for each level. Test that design in a simulated exercise before you need it.

How do you demonstrate to a partner or the C-level that risk has gone down, using time metrics instead of a tool count?

Present a historical series with three curves, time to detection, time to decision, and time to containment, measured quarter by quarter. A consistent drop in those curves communicates reduced exposure in a way leadership understands, because it speaks the same language as any operational indicator tracked by the board.

Complement it with two pieces of context, the number of investigations started without an automated alert and the log retention window relative to the dwell time considered plausible. That set turns security into a management conversation, with a trend, a target, and a defined owner.

Frequently asked questions

What is dwell time in information security?

Dwell time is the interval between the initial compromise of an access and the effective containment of that access by the organization. The longer that interval, the greater the volume of information read and copied by whoever is inside the environment. That is why it works as a business metric, not just as a technical indicator.

Why doesn't prevention reduce an intruder's dwell time?

Preventive controls decide who gets in at a specific moment, acting on the probability of the event. Dwell time depends on continuous observation of account behavior and on defined authority to act after someone is already in. They are complementary layers that answer different questions.

What metrics should a manager demand from their detection and response provider?

Three numbers with history and an owner, the average time to detection, the time between detection and authorization to act, and the average time to containment. It is worth adding the number of investigations opened without an automated alert in the period, which indicates whether active hunting exists. These metrics reveal real maturity better than any list of installed tools.

If you want to know the plausible dwell time of your operation before an incident measures it for you, talk to Zamak Technologies in a Strategic IT Assessment, with no obligation.

Dwell time: the gap that decides the size of the damage
Kleber Leal by Zamak Portal August 24, 2026
Share this post
Tags
Archive