Adversaries keep getting faster
According to CrowdStrike’s 2025 Global Threat Report, the average breakout time, the window between an adversary gaining initial access and pivoting to other systems in your network, shrunk to just 48 minutes. In less time than a typical meeting, a capable adversary can go from compromising a single device to moving laterally through your corporate environment, gaining privileged access, and preparing to exfiltrate data or deploy ransomware. For a security team, this creates a very small response window.
[Update: In the 2026 Global Threat Report, the breakout time dropped again, to just 29 minutes.]
I recently spoke at CrowdStrike’s annual security conference about this problem and what it means for defenders. The focus of that talk was simple. While security teams need to reduce their own detection and response times, they also need to put controls in place that increase breakout time. I walked through how one particular threat actor steals credentials, performs reconnaissance, and moves laterally, then identified the controls that would slow them down. The talk was aimed at security engineers and system administrators, but the underlying message applies to leadership as well.
Why Breakout Time Matters
Breakout time reflects both the threat actor's capabilities and the target organization's security posture. In part, breakout time has decreased because threat actors have become faster by refining their methods over years of executing attacks against organizations. Some groups even have written documentation. A few years ago, a member of the Conti ransomware group leaked the group's playbook, which contained instructions for network discovery, lateral movement, and privilege escalation. Conversely, decreasing breakout times also suggest that organizations lack the preventive controls needed to create friction and slow adversaries' progress toward their objectives.
As breakout times decrease, defenders face more pressure to detect and contain activity before threat actors can gain privileged access or pivot to other systems in the environment. A shorter window leaves less room for triage, investigation, and response, and it is especially concerning for teams that do not have 24/7 monitoring. The faster an adversary advances, the harder it becomes to interrupt the intrusion before they can exfiltrate or destroy data.
Compliance Is Not Enough
Many organizations have invested heavily in security frameworks such as NIST SP 800-171 or ISO 27001. These standards provide an excellent foundation, but they are broad by design because they must apply across different industries, technologies, and operating models. As a result, they address broad security themes, but do not always provide the specific guidance needed to harden particular applications or counter the techniques used by individual threat actors.
For example, Microsoft’s identity system (Active Directory), which most companies use to manage users, computers, and privileges, is one of the primary targets in modern attacks. Because it controls access to systems and data, it is the backbone of security in most corporate environments. However, most compliance frameworks are vendor neutral and offer little prescriptive guidance on how to secure it. This creates a major gap, because threat actors rely on specific techniques and misconfigurations that aren't directly addressed by most compliance frameworks. Passing an audit may verify compliance with high-level controls, but it does not mean the environment is secure against the specific methods threat actors will use in a real-world attack.
Closing the Gap
Stopping capable threat actors requires a mix of stronger preventive controls and faster detection and response. These approaches work together and will help to increase breakout time, create friction for the threat actor, and give defenders more room to act before the adversary causes real harm.
Leverage threat intelligence. Security companies such as CrowdStrike, Microsoft, and Palo Alto Networks collect intelligence on threat actors and document the tools, tactics, and techniques they use in real attacks. Organizations should use this intelligence to help them focus on the tactics and techniques used by the threat actors that are most likely to target them, including prevalent e-crime groups and threat actors who have previously targeted their industry.
Increase friction for lateral movement. Put stronger internal security controls in place so that even if a threat actor gains access to a system in your environment, it is difficult for them to move beyond their initial point of access. For example, prevent users from installing unapproved remote management tools and limit network access so that a threat actor cannot connect from one user workstation to another.
Harden identity systems. Strengthen the systems that manage users, access, and privileges. Most organizations do not put enough emphasis on hardening Microsoft Active Directory and other identity platforms to prevent threat actors from escalating from user-level access to administrator access.
Conduct targeted offensive testing. External penetration testing is useful, but it generally focuses on getting past the first line of defense to gain initial access to the network. Organizations should also conduct internal penetration testing to evaluate how well they can defend against an adversary once they get in. Organizations can also use "adversary emulation" to assess how well they can defend against the tactics and techniques used by specific threat actors.
Improve detection and response time. Invest in people, processes, and tools that reduce mean time to detect and mean time to respond. This helps defenders act within the shrinking window created by faster adversaries.
By putting stronger controls in place and improving detection and response, organizations can slow adversaries down and give defenders a better chance to contain an incident. This will create a more resilient environment and reduce the likelihood of business disruption.
The Role of the Board and Executive Leadership
Looking at adversary breakout time is more detailed than the way most executives and board members usually think about cybersecurity, but it represents a real strategic concern. Decreasing breakout times puts more pressure on defenders to contain an intrusion before it affects the business. Putting the right controls in place to add friction for adversaries (while minimizing friction for employees) will increase breakout time and improve the organization’s ability to withstand a real attack.
With this in mind, boards and executives should ask questions such as:
• Are we using threat intelligence to identify and focus on the real threats we are most likely to face?
• Are our investments reducing the time it takes us to detect and respond to an attack?
• Are our investments increasing the time it would take a threat actor to move through our network?
• Are we simulating real-world attacks and learning from them?
• Do we understand which improvements will have the greatest impact on breakout time and overall resilience?
Preparing for cyberattacks requires prioritizing the work that will make the biggest difference. This can mean dedicating resources to security hardening that does not map to a business project or product deployment, does not advance compliance on its own, and is easy to dismiss as non-essential maintenance. Leaders should ensure that this work receives the time, funding, and attention necessary to prevent attacks where possible and limit their impact when they occur.
Conclusion
As threat actors become faster, organizations have less time to detect and contain an intrusion before it affects the business. Improving detection and response is part of the answer, but organizations should also focus on slowing adversaries down. Leveraging threat intelligence, implementing stronger internal controls, and conducting realistic testing can create friction and give defenders more time to respond.
For boards and executives, this means ensuring that security teams have the resources to address the weaknesses that matter most, including work that may lack visibility or may not be driven by a business project or compliance requirement. The goal is to make the organization harder to compromise and better prepared to limit the impact when an intrusion occurs.