I have been at several security conferences over the past few months. Between the sessions on AI-driven threats and agentic insider risk, I keep noticing something. People or slides quoting an average attacker dwell time of around 200 days. I have been seeing that figure for years, and it never gets questioned. The conversations that follow about detection and investment are built on it like it’s a known fact.
But when I talk to incident responders or read vendor threat reports, I hear a very different number, with times measured in minutes rather than months. I wanted to know which was right.
The 200-day figure traces to Mandiant’s M-Trends report. In 2014, global median dwell time, which measures the gap between initial compromise and detection, was 205 days, by 2020 it was 24 days, and by 2024 just 11 days. In the most recent report, covering 2025, it’s increased slightly to 14 days.
But 200 days also maps roughly onto a different metric from another source. IBM’s Cost of a Data Breach Report 2025 measures the full breach lifecycle: the mean time to identify a breach plus the mean time to contain it, that figure is 241 days. For breaches involving compromised credentials, it’s 246, for healthcare organisations it’s 279. These are not the older dwell time numbers. They measure the time from initial compromise through to containment, excluding post-breach recovery. But they are large and they come from credible sources, so they sound like the same kind of claim.
That conflation is part of how the 200-day figure is still professional legend despite being contradicted by a decade of primary data. People hear a big number from a report they trust and do not ask exactly which question it answers.
However, Mandiant’s 14-day median is itself misleading, though not in the way you might expect. It went up from 11 days the prior year, the first consecutive increase in the report’s history. Does that mean that defenders are losing ground?
The increase was driven by the volume of cyber espionage and North Korean IT worker operations in Mandiant’s 2025 caseload. Both categories had a median dwell time of 122 days, with some intrusions persisting undetected for over a year. These are threat actors optimising for persistence, not speed. They embed themselves in edge devices that lack standard endpoint detection and mimic legitimate administrative behaviour.
For financially motivated threat actors at the other end of the scale, the operational speed is completely different. Mandiant found that the median time between an initial access broker gaining a foothold and handing it off to a ransomware operator collapsed to 22 seconds in 2025, down from over eight hours in 2022. Instead of advertising on forums or Telegram like a lot of people still imagine, threat actors are now using automated pre-staged pipelines. Once that handoff is complete, CrowdStrike’s data shows the average time to first lateral movement is 29 minutes, with the fastest observed case at 27 seconds. Sophos reports that the median time from there to reaching Active Directory fell to 3.4 hours, down from 11 hours the year before, and that data was leaving compromised networks within three days of initial access.
Threat actors behave very differently depending on their objectives, and some of the figures the industry traditionally relies on fail to take this into account. Attacks by financially motivated threat actors are measured in minutes, whereas espionage actors’ attacks are measured in months. Quoting a single dwell time figure describes neither accurately, and that single number, which many organisations use to plan their detection strategy, now sits in a gap between two groups that are moving further apart.
Dwell time is not the only assumption that has broken.
Mandiant tracks the mean time to exploit newly disclosed vulnerabilities. In 2018, that window was 63 days and by 2023 it had fallen to 5 days. In 2025, the estimated figure fell below zero and now sits at negative 7 days. That figure comes with a caveat, it changes significantly depending on how the outliers are handled, so while the exact number is debatable, the direction is not. Exploitation is now routinely occurring before a patch is publicly available.
The patching window did not just shrink, it collapsed. AI-assisted discovery is now finding vulnerabilities faster than human researchers ever could. In May 2026, a single AI pipeline surfaced over 300 WordPress plugin zero-days in three days, overwhelming disclosure programmes designed for a human-paced discovery rate. Verizon’s 2026 DBIR shows the median time to fully resolve a critical vulnerability increased to 43 days. Remediation is not keeping up with discovery.
Look at those timelines next to a quarterly review cycle and the governance speed stops looking slow, and starts looking structurally irrelevant to the threat it is supposed to address.
Board reporting on cybersecurity typically runs quarterly. Penetration testing is typically annual, with PCI DSS mandating testing at least once a year plus after significant change. Even those cadences overstate what happens in practice. Horizon3.ai found that 84% of organisations suffered a cyberattack in 2024, yet only 26% test more than once a year. Nearly 20% of CISOs admitted they only test to satisfy compliance requirements, and over 40% said their results are already invalid by the time they arrive because environments move faster than the testing cycle.
The board oversight picture is no better. Gartner’s 2026 Board of Directors Survey found that 90% of non-executive directors lack a measure of confidence in cybersecurity value. The 2024 survey found that 67% rate current board practices as inadequate to oversee cyber risk. The UK government’s Cyber Security Breaches Survey 2025/2026 found that only 31% of businesses have a board member with explicit cyber security responsibility, and only 25% have a formal incident response plan.
Common cyber security testing and reporting timelines exist to make security fit into governance structures that operate on quarterly and annual cycles. When the dwell time was 205 days and the patching window was 63 days, quarterly governance was roughly proportionate. The approach bore some relationship to the speed of the problem, but it does not any more, and the governance framework has not adjusted because the thing it was designed to do, make security reportable and auditable, does not require it to.
A peer-reviewed study in Management Science examining how boards oversee cybersecurity found that for many non-expert directors, oversight is largely motivated by and limited to compliance concerns, potentially at the expense of understanding the firm’s specific risks. Whether current controls match the firm’s actual risks is a question the governance structure does not force anyone to answer.
The reporting cycle is not failing at its job. But it is doing a job that no longer corresponds to the problem.
All of these numbers describe the attacker. Mandiant’s M-Trends 2026 data contains one that describes the defender.
Organisations that detected intrusions internally did so in a median of 9 days. Where the breach was identified by an external party, the median was 25 days, and fifty-two per cent of organisations found it themselves. For the other forty-eight per cent, someone else found it first, whether that was law enforcement, a security vendor, or the attacker delivering a ransom note.
IBM’s data attaches a cost to both. For breaches detected internally, the average cost was $4.18 million. For breaches disclosed by the attacker, it was $5.08 million. The difference is nearly a million dollars and is driven by a single organisational capability: whether you can find your own breaches or not.
Sophos’s data suggests what separates the two groups. In environments with managed monitoring services, non-ransomware intrusions were detected in a median of 1 day compared with 11.5 days in incident-response-only cases. Continuous monitoring, not tooling sophistication, appears to be the primary differentiator. The gap is tenfold, and it suggests that having someone watching around the clock matters more than most people give it credit for.
The question this metric answers is not “how fast are attackers?” It is “are you an organisation that finds its own breaches, or one that waits to be told?” A board can govern against that question. It is measurable, comparable across quarters, and tied directly to cost. It replaces a broken single number with ones that actually drive a decision.
The 200-day number persists because it fits the reporting structure. Boards need a benchmark they can track year on year, and a single dwell time figure has served that purpose for a decade. Nobody has offered them anything better.
Faster patching and better tooling help, but they are improvements to operations, not the core issue. The framework itself needs to change. A quarterly report that tells the board the median dwell time is 14 days gives them nothing to act on. One that tells them 60% of incidents were detected internally, up from 45% last quarter, gives them a decision about where the next pound goes.
The threat landscape now operates on two completely different clocks simultaneously depending on who’s attacking and why. The governance framework operates on a third that matches neither.
Next time someone puts 200 days on a slide at one of these events, I have a better question. What percentage of your incidents did your team find before someone else told you about them?
I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.
Sources & Further Reading
Mandiant (Google Cloud). M-Trends 2026 Report. March 2026. cloud.google.com/security/resources/m-trends
Mandiant (Google Cloud). M-Trends 2026: Data, Insights, and Strategies From the Frontlines. cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
IBM Security / Ponemon Institute. Cost of a Data Breach Report 2025. ibm.com
CrowdStrike. 2026 Global Threat Report. February 2026. crowdstrike.com
Sophos. Active Adversary Report 2026. February 2026. sophos.com
Sophos. Active Adversary Report 2025 (“It Takes Two”). April 2025. sophos.com
Verizon. 2026 Data Breach Investigations Report. May 2026. verizon.com
Mandiant / Google Threat Intelligence. Analysis of Time-to-Exploit Trends: 2021-2022. September 2023. cloud.google.com
Help Net Security / TrendAI & CHT Security. “$20 per zero-day is already the WordPress plugin reality.” May 22, 2026. helpnetsecurity.com
Department for Science, Innovation and Technology (DSIT) / Home Office. Cyber Security Breaches Survey 2025/2026. April 2026. gov.uk
Gartner. 2026 Board of Directors Survey. November 2025. gartner.com
Gartner. 2024 Board of Directors Survey. gartner.com
NACD. Guide: Cybersecurity Risk Measurement and Reporting. 2026 Cyber Risk Oversight Handbook. nacdonline.org
Horizon3.ai. How Often Should You Pentest? September 2025. horizon3.ai
Hartmann, R. & Carmenate, J. et al. “Inexpert Supervision: Field Evidence on Boards’ Oversight of Cybersecurity.” Management Science. pubsonline.informs.org
Financial Reporting Council. UK Corporate Governance Code 2024. Provision 29. frc.org.uk


