What does dwell time actually mean?
Dwell time is the interval between the first evidenced unauthorized presence in an environment and the moment the intrusion is detected. It is a measure of detection, not of harm: an intruder who is present for six months and reaches nothing has a long dwell time, and an intruder who encrypts a network within a day of entry has a short one.
Two boundaries have to be fixed before the number means anything, and both are contestable. The start is not the date the attacker first probed the perimeter or bought a credential; it is the earliest point at which the forensic record shows unauthorized access. The end is the point of detection, which is itself ambiguous — an alert that fired into an unread queue, a help desk ticket, a call from a bank or a law enforcement agency, and a ransom note are four different events, and different analysts will select different ones.
Dwell time also has to be kept separate from the other intervals in an incident, which are frequently conflated in briefing decks and then repeated in pleadings. Time to containment, time to eradication, time to notification and time to remediation all start at detection and measure the response rather than the intrusion. The Institute treats the response intervals separately, in how incident response adequacy is judged.
How is dwell time reconstructed from logs and forensic artifacts?
By anchoring the earliest and latest evidenced attacker actions in independent sources and working outward from there. Nobody measures dwell time directly; it is an inference built from authentication records, endpoint telemetry, network flow and proxy records, file system metadata, and whatever the intruder left behind in the form of tooling, scheduled tasks, service installations and registry or configuration changes.
The strongest reconstructions do not rest on one artifact class. A single authentication event from an unfamiliar address is suggestive; the same event corroborated by an endpoint process record, a firewall session and the creation timestamp of a file dropped on the host is a finding. This is also why the order of operations in the first hours matters so much — volatile memory is gone at reboot, and a host that has been reimaged no longer holds the artifacts that would anchor the early end of the timeline. That problem is set out in what disappears first after a breach and in does reimaging destroy the forensic evidence.
Timestamps themselves are evidence that has to be validated rather than read. Sources record in different time zones, clocks drift, some systems record local time and others record Coordinated Universal Time, and several categories of artifact can be modified by an intruder who wants the record to say something else. An expert report that presents a dwell time figure without saying how timestamps were normalized across sources has skipped the step that the other side will start with.
Why do log retention windows and gaps bound what dwell time can show?
Because the earliest evidence of intrusion can only be as early as the oldest surviving log, so a retention window that is shorter than the intrusion converts the true dwell time into an unknown with a floor. Retention runs from the moment the event was recorded, not from the moment anyone knew to look, so the clock on the evidence has usually been running for weeks before the investigation opens.
This is a recognized problem in public guidance rather than a litigation talking point. Best practices for event logging and threat detection, developed by the Australian Signals Directorate’s Australian Cyber Security Centre in cooperation with the US Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, the National Security Agency and partner agencies in the United Kingdom, Canada, New Zealand, Japan, the Republic of Korea, Singapore and the Netherlands, and released in August 2024, states plainly that “Default log retention periods are often insufficient.” It tells organizations to set retention by reference to risk, and to consider that in some cases it can take up to 18 months to discover a cyber security incident and that some malware can dwell on a network from 70 to 200 days before causing overt harm. It also notes that insufficient storage is a common obstacle and that many systems overwrite old logs once their allocation is exhausted.
The practical consequence for a matter is a sentence that both sides should be able to agree on and rarely do: the evidenced dwell time is at least X days, and the record does not permit a statement about the period before the retention boundary. That is a weaker claim than a number, and it is the honest one wherever the intrusion predates the logs. Where coverage is partial rather than absent — some sources retained, others expired — the analysis has to say which conclusions rest on which surviving sources.
What do the published dwell time measurements say, and who publishes them?
They say different things, because they count different populations, and every figure has to be read with its publisher, its population and its period attached. The two most frequently cited are published by firms that sell incident response services and measure their own casework, which is a real limitation and not a reason to disregard them.
Mandiant publishes M-Trends annually. M-Trends 2026, published March 23, 2026, reported that global median dwell time rose to 14 days from 11 days, grounded in over 500,000 hours of frontline incident investigations conducted by Mandiant globally in 2025, and attributed much of the increase to the two categories it breaks out on this point, cyber espionage incidents and IT worker incidents as the report defines them, for which it reported a median of 122 days. It also reported that in 52 percent of 2025 investigations the organization first detected evidence of malicious activity internally, up from 43 percent in 2024. M-Trends 2025, published April 23, 2025, reported an 11-day global median for 2024 based on more than 450,000 hours of Mandiant Consulting investigations of targeted attack activity conducted between Jan. 1, 2024 and Dec. 31, 2024, and broke the figure out by how the intrusion came to light: 10 days on internal detection, 26 days where an external entity gave notice, and 5 days where the adversary made the organization aware.
Sophos publishes the Active Adversary Report from a different population. The 2026 edition, Nowhere, man: The 2026 Active Adversary Report, announced on February 24, 2026, says its data “was captured over the course of individual investigations undertaken by Sophos’ X-Ops Incident Response and MDR teams,” focused on “661 cases that could be meaningfully parsed for information on the state of the adversary landscape between Nov. 1, 2024 and Oct. 31, 2025,” across 70 nations and other locations, and reported that “Dwell time has also stabilized at a median of three days,” with all-cause incident response cases at 5.00 days, all-cause managed detection and response cases at 2.00 days, and non-ransomware incident response cases generating the longest dwell times at 6.00 days. The gap between three days and fourteen is mostly a difference in what is in the dataset: a caseload weighted toward monitored environments and ransomware will be faster to detect than a caseload weighted toward quiet, long-running intrusions.
The Verizon Data Breach Investigations Report is the largest of the general-purpose sources and is structured differently again. The 2026 edition, the 19th, examined more than 31,000 security incidents of which more than 22,000 were confirmed breaches, involving organizations in 145 countries, normalized through the VERIS framework and contributed by almost a hundred organizations including incident response firms, forensics boutiques, law enforcement and cyber insurers. Verizon distinguishes an incident, which compromises integrity, confidentiality or availability, from a breach, which requires confirmed disclosure of data — a distinction the Institute treats at length in exposure is not misuse. None of these datasets is a census. Every one of them counts incidents that were investigated, by organizations that engaged an investigator or reported to a contributor, which systematically excludes the incidents nobody found.
What can dwell time establish about notice, negligence or causation — and what can it not?
Dwell time is good evidence of opportunity and of detection capability, and poor evidence of everything else. A long evidenced dwell time expands the set of systems the intruder had the opportunity to reach, which is why it drives the scope of a notification analysis; and it is a finding about monitoring, because an intrusion that ran for months without an alert says something about what the detection controls were doing, independent of anything the intruder did.
What it does not do is establish access or exfiltration. Opportunity is not acquisition, and demonstrating that data left the environment requires egress evidence for the period in question — the very evidence that retention windows most often fail to preserve. It also does not establish causation. Connecting a specific control deficiency to a specific intrusion is a separate chain of proof, each step of which has to be evidenced on its own; that is the subject of proving a control failure caused the breach.
Nor does dwell time settle the standard of care, in either direction. Neither the Institute nor any published median can tell you whether a given organization’s security was reasonable or its response adequate — that is the expert opinion counsel retains someone to form on a full record, and it is assessed on what was knowable before the incident rather than on the number the forensics produced afterward. And dwell time does not measure loss. What an incident cost, what a claim is worth and what a class might recover are damages questions that belong to the Economic Damages Institute at economicdamagesinstitute.com, which covers the class-wide models and the measures of loss properly.
How should a stated dwell time figure be tested?
By asking what fixed each end of the interval, what evidence supports it, and what the record would have looked like if the true interval were longer. A dwell time figure is a conclusion, and like any conclusion it can be tested at its inputs rather than argued about at its output.
The questions that do the work are short. What artifact establishes the start, and in which log source does it live? What was the retention period of that source, and had it already expired in part when collection began? What event was treated as detection, and were there earlier alerts, tickets or notifications that were not selected? How were timestamps normalized across sources, and were any artifact classes excluded as unreliable? Which hosts were imaged before remediation, and which were rebuilt without imaging? If the environment had retained ninety days instead of thirty, what would have been recoverable?
Expect the honest answer to be a range with an explicit floor rather than a single figure, and treat a confident single figure over a partial record as the thing to examine first. The same discipline applies to attribution claims that ride alongside a timeline, which are load-bearing far less often than they feel; the Institute sets out those limits in what attribution proves and what it does not and in attribution and scope. Where a matter is live, none of this displaces the first task, which is preserving what is still there; see evidence preservation.