Two numbers from 2026 tell the story better than any argument. Mandiant's M-Trends 2026, built on more than 500,000 hours of incident response work in 2025, found that the median time between initial access and handing that access to a second threat group fell to 22 seconds. In 2022 the same figure was more than eight hours.

The second number is from IBM. The global mean time to identify and contain a breach is now 247 days, which reverses roughly five years of steady improvement.

Twenty two seconds on one side. Two hundred and forty seven days on the other. That is not a small gap to be tightened with better process. It is a different unit of time.

How fast attackers actually move now

There are three different metrics in play and they measure different things. Conflating them is a common mistake, so it is worth being precise.

Breakout time is how long an attacker takes to move from the first compromised machine to a second one. CrowdStrike's 2026 Global Threat Report puts the average at 29 minutes for 2025, down from 48 minutes the year before and 84 minutes in 2022. The fastest single case they observed was 27 seconds. ReliaQuest, working from a separate incident dataset, landed at 34 minutes. Two independent sources, roughly the same answer.

29 min
Average eCrime breakout time, 2025 (CrowdStrike)
22 sec
Median time to hand off access to a second threat group (Mandiant)
247 days
Global mean time to identify and contain a breach (IBM 2026)

Hand off time is Mandiant's 22 seconds. Initial access brokers now sell and transfer access almost instantly. That is a market maturing, not a single hacker typing faster.

Time to real damage is Sophos's contribution. Their 2026 Active Adversary Report, covering 661 incident response and managed detection cases, found a median of 3.4 hours from attack start to Active Directory. That is a 70 percent acceleration year on year. They also found 88.1 percent of ransomware was deployed outside business hours, and 37.1 percent between 11pm and 3am. Attackers are not just fast. They are deliberately arriving when nobody is watching.

Speed is not the attacker's advantage. Your calendar is.

What the gap is worth in money

IBM's 2026 report puts the global average breach cost at 4.99 million dollars, a record and up 12 percent year on year. The detail that matters more is the split. Breaches that ran longer than 200 days cost 5.65 million. Breaches contained faster cost 4.32 million. Time is roughly 1.3 million dollars of difference.

For Indian organisations the picture is sharper. The average cost hit INR 25.5 crore, a record and up 15.9 percent from 22 crore the year before. Organisations with no AI or security automation took 236 days to identify a breach and another 75 to contain it. Only 32 percent of Indian organisations use extensive automation, which means roughly two thirds are running the slow version.

The cost of slow detection. Breaches running longer than 200 days cost 5.65 million dollars on average. Faster containment costs 4.32 million. Security AI and automation saves 1.93 million and cuts 65 days off the timeline. The math is clear: speed of detection is a financial decision.

AI is speeding this up, but not the way the headlines say

CrowdStrike reported AI enabled adversary operations rose 89 percent year on year. ReliaQuest found 80 percent of ransomware groups used automation or AI in some form. In June 2026 Sysdig documented an agentic ransomware campaign that executed over 600 distinct payloads and redeployed a corrected one 31 seconds after hitting an error.

That last detail is the one worth sitting with. Not the encryption speed. The recovery speed. A human operator who hits an error takes a coffee break. An agent takes 31 seconds. Reporting on that same case notes a human was still in the loop, so this is not yet a fully autonomous attacker. It is close enough to plan for.

Mandiant is refreshingly blunt about the balance: 2025 was not the year AI directly caused breaches. Most intrusions still come from human and systemic failures, unpatched edge devices, missing MFA, stolen credentials. AI is not inventing new categories of failure. It is removing the delay between finding one and using it.

Match the clock speed

You cannot make detection instant. You can make the window between tests small enough that a change never sits unexamined for a quarter.

Every framework already hints at this. PCI DSS requires penetration testing at least every 12 months and after any significant change. RBI requires vulnerability assessment at least half yearly and penetration testing at least annually, throughout the system lifecycle and after major changes. The calendar was always the floor. The event trigger was always the real rule. Most teams only ever implemented the floor.

Continuous validation is what implementing the second half looks like. Arxiis runs an autonomous AI red team across 26 modules and 6 attack vectors and re-earns a known-secure state every 24 hours. Not because 24 hours is magic, but because it is the same order of magnitude as the thing you are defending against.

Twenty two seconds is the attacker's clock. Do not answer it with a calendar.

You will not stop every intrusion. Nobody does. But the difference between a bad week and a 25 crore year is almost entirely a function of how long the thing ran before someone noticed. That number is not fate. It is a design choice, and right now most organisations are choosing 247 days by default.

Close your security gaps — continuously.

Arxiis is an autonomous AI penetration-testing platform that runs a coordinated crew of specialist agents through a full engagement in hours, not weeks — continuously, not annually. Every finding is CVSS-scored, MITRE ATT&CK-tagged, and auto-mapped to RBI CSF, CERT-In and nine more frameworks. It runs entirely on your own infrastructure. Nothing leaves the perimeter.