Ask a roomful of security leaders how quickly they'd catch an intruder, and most will say hours. IBM's Cost of a Data Breach study, run across hundreds of organisations every year, puts the real number at 194 days to identify a breach — and another 60 to contain it. The distance between what we believe and what the data shows is not a rounding error. It's where the entire attack happens.
That 194-day figure is dwell time: the interval between an attacker first getting in and anyone noticing. It is not passive waiting. It's a methodical kill chain, and every step is designed to stay quiet. Walk through it.
Six months, hour by hour
Step the clock forward. Each phase is what a real adversary does in an under-tested environment — drawn straight from incident-response data.
Day 1 · Initial access
One unpatched service. One reused credential. One phishing click. The attacker establishes a foothold — usually through a legitimate tool like RDP or a VPN client. No unusual activity. No alerts. Business continues as normal.
Days 2–30 · Reconnaissance & lateral movement
The adversary maps the estate from the inside. Active Directory enumeration. Service-account discovery. Credential dumping from the first machine, then quiet hops sideways using the same protocols the operations team uses. No malware to sign, no exploit to flag.
Days 30–90 · Privilege escalation
Pass-the-Hash, Kerberoasting, trust abuse. By the end of this window, an under-tested environment typically yields Domain Administrator. The attacker now owns identity, which means they own everything identity protects.
Days 90–180 · Persistence & staging
Backdoor accounts. Scheduled tasks. Cloud key material rotated to the attacker. Data is identified, compressed and staged. Ransomware payloads pre-positioned on critical hosts, dormant, waiting for the trigger.
Day 194 · The discovery
An alert fires. A vendor calls. A regulator asks a question. Whatever it is, it is rarely the security team finding the attacker first.
Notice what never appears in that sequence: a moment loud enough to trip an alarm on its own. Reconnaissance runs at low traffic volumes. Exfiltration moves in 500 MB nightly chunks to pass DLP thresholds. Ransomware is pre-positioned to detonate on a trigger no one sees coming. The whole craft is staying under the line your monitoring draws.
Why "we'd catch it fast" is the dangerous belief
Around 80% of security and IT leaders believe they could detect and contain a breach in under eight hours. The IBM data shows the actual mean is 181 days to detect, 60 to contain. That confidence gap — the distance between perceived and actual readiness — is precisely where attackers set up camp. The more certain a team is that it would know, the less it tends to test the assumption.
The honest version of the problem
Dwell time has improved — from 212 days in 2021 to 181 in 2025, a nine-year low. IBM attributes most of that gain to AI and automation in security operations, which save an average of $1.9M per breach and cut 80 days off the lifecycle. That's the single largest cost-mitigation lever the study measures. But even 181 days is six months of an attacker roaming free. Slow, incremental improvement against an adversary moving from exploit to ransomware in 48 hours is not parity.
Operate before the clock starts.
Arxiis runs a coordinated crew of AI agents through the same kill chain an attacker would — recon, credential attacks, lateral movement, privilege escalation — and reports the exploitable paths before an adversary finds them. Hours per engagement, continuously rather than annually, entirely on your own infrastructure. The mechanism IBM's data rewards, delivered by default.