Desk live·
ForensicPost
Nation-state/Edge devices/File 26-0630

Adversary Breakout Time Falls to 72 Minutes, Research Finds

Research puts the 2026 benchmark for adversary breakout time at 72 minutes, a fourfold reduction on prior-year averages. Every response process built around a next-business-day assumption is now mistimed.

Constructed geometry · not a chart of case data
TargetEnterprise networks, multiple
ActorMultiple
D. Kennedy10 min readConfidence: medium2 sources reviewed

Published research places the 2026 benchmark for adversary breakout time — the interval from initial foothold to active exfiltration — at around 72 minutes, described as a fourfold reduction on prior-year averages.

Treat the precise figure with the caution any vendor benchmark deserves. The direction is what matters, and it invalidates an assumption embedded in a great many response processes.

What 72 Minutes Excludes

Consider what typically happens in the first 72 minutes after a detection fires in a mid-sized organisation. The alert queues. An analyst picks it up. They check whether it is a known false positive. They look for a second signal. They decide whether to escalate. If it is outside working hours, some of that waits.

On this timeline, the human triage step has already been overtaken before it concludes. That is not a criticism of the analyst; it is an argument that any control depending on a person deciding is now positioned after the event it was meant to prevent.

The Uncomfortable Implication

The honest conclusion is that containment at this speed has to be automatic, and automatic containment means accepting that some legitimate activity will be interrupted by a machine with no judgement.

Most organisations have decided that trade is unacceptable, usually after one bad automated action. The arithmetic behind that decision changes when the alternative is an intruder finishing the job during triage.

It also raises the value of controls that do not require detection at all — short-lived credentials, egress restrictions, and permission scoping — because they bound the outcome without anyone having to notice in time.

How we reported this

This is an analysis file built on published research, listed below. Benchmark figures are vendor-derived and methodology varies; we treat the trend as the finding rather than the number. Corrections: corrections@forensicpost.com.

Sources
  1. Edge under siege: how state-sponsored actors exploit your perimeterTrend Micro
  2. TrendAI reports nation-state activity in H1 2026 APT activity roundupTrend Micro
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary