Desk live·
ForensicPost
Ransomware/Verification/File 25-1223b

Two Incident Response Practices Reported Dwell Times of 14 Days and Two Days

One incident response practice reports a 14-day median dwell time for 2025. Another reports two days across its combined caseload. Both are correct and they are not comparable.

Constructed geometry · not a chart of case data
TargetDwell time measurement
ActorMultiple
S. Rosler12 min readConfidence: medium2 sources reviewed

One major incident response practice reports a median dwell time of 14 days for 2025, falling to nine days where detection was internal. Another reports a median of two days across combined incident response and managed detection cases — seven days for incident response alone, four days for ransomware within that, and one to three days where managed detection was in place.

The Gap Is The Service Model, Not The Threat

A managed detection service watches continuously and finds things in hours. An incident response practice is called after somebody notices, and the median it reports is partly a measure of how long noticing took.

Blending the two produces a low figure that describes neither. Separating them, as the second source does, is the more honest presentation and it is why its incident-response-only number is closer to the first source’s.

The Corpus Has Made This Mistake In The Other Direction

This database records dwell times of 102 days at Nevada, ten months in an unwatched ERP at 26-0620, five months at 25-0820. Against those, both medians look implausibly short.

They are not. The corpus records the incidents that became public, and an incident that ran for months is far more likely to become public than one caught in two days — the selection problem at 25-0807 and 25-1218b. This database is a sample of long dwell times.

Princeton ejecting an intruder within 24 hours at 25-1026 was described here as an outlier by two orders of magnitude. Against a two-day median it is unremarkable.

Which Is The More Useful Correction

The corpus should stop treating fast detection as exceptional. It is exceptional in this database because this database is built from disclosures, and it is apparently ordinary among organisations with continuous monitoring.

Graded medium: two vendor populations, neither representative, and the comparison above is this desk’s reading of why they differ.

This is an analysis file

Built on published vendor research, listed below. The two sources measure different populations and their medians should not be compared directly. Corrections: corrections@forensicpost.com.

Sources
  1. Attackers are handing off access in 22 seconds, Mandiant findsHelp Net Security
  2. Detection at dusk: why dwell times collapsed in 2025Black Hat MEA Insights
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary