Two numbers define the modern breach. The first comes from IBM's Cost of a Data Breach Report: the average organisation takes 181 days to identify that a breach has occurred. The second comes from CrowdStrike's Global Threat Report: once an attacker has an initial foothold, the median time to move laterally to another system is 29 minutes.
Put those together and the picture becomes clear. The attacker needs 29 minutes to expand. You take 181 days to notice. The mismatch is not a gap in tooling — it is a structural gap between how fast threats move and how slowly most detection programmes respond.
What happens inside 181 days
The breach lifecycle has three phases that the IBM data tracks separately: identification, containment, and remediation. The 181-day figure covers identification alone — the time from initial compromise to the moment the organisation first knows something is wrong. Containment adds another 60 days on average, bringing the full breach lifecycle to 241 days from first entry to resolved incident.
During those 181 days, the attacker is not static. CrowdStrike's breakout time data shows that lateral movement begins within the first hour in most intrusions. The 29-minute median means that by the time many organisations finish their morning stand-up, an attacker who slipped in the night before has already reached a second system.
The cost of detection speed
IBM's data connects detection speed directly to breach cost. Organisations that identify a breach in under 200 days pay an average of $3.61 million. Those that take longer pay $5.49 million. That $1.9 million difference is the direct financial value of faster detection — and it is larger than the annual security budget of most mid-market organisations.
Why 29 minutes changes the calculus
CrowdStrike defines breakout time as the time from initial access on one system to the first lateral movement to a second. The 29-minute median is calculated across intrusions tracked by CrowdStrike's incident response teams. The fastest observed breakout time in recent reporting was under two minutes.
This matters because most incident response plans assume time. They assume that an alert fires, a human reviews it, a ticket is created, and a responder begins investigating — a process that, in practice, takes hours to days after the initial signal. By the time that process completes, an attacker with a 29-minute breakout speed has already established persistence across multiple systems and may have exfiltrated the first batch of data.
The continuous validation response
The structural answer to the detection time problem is not to buy another SIEM add-on. It is to eliminate the conditions that allow an attacker to move undetected for 181 days in the first place. That means continuous security validation — running attack simulations against your live environment on an ongoing basis so that exploitable paths are found and closed before an attacker finds them.
When a vulnerability exists for hours instead of months, the 181-day detection window becomes irrelevant. The attacker cannot build a path through a gap that is no longer there. Continuous testing shifts the asymmetry: instead of the attacker having months to operate while you wait for a detection, the validation system finds the exposure before the attacker does.
This is the logic behind the shift from annual VAPT to continuous penetration testing. The test cadence directly determines how long an exploitable condition can exist. Annual testing means a condition can exist for up to 365 days. Continuous testing collapses that window to hours.
Close your security gaps — continuously.
Arxiis runs autonomous AI-driven penetration testing against your live environment on a continuous basis, finding exploitable paths before attackers do. Every finding is CVSS-scored, MITRE ATT&CK-tagged, and mapped to RBI CSF, CERT-In, and nine more frameworks. Entirely on-premise — nothing leaves your perimeter.