← All terms

Dwell Time

Dwell time is how long an attacker operates inside a network before being detected — the window in which a foothold becomes a full breach.

Dwell time is the period between an attacker's initial compromise of an environment and the moment defenders detect them. It is the breach inside the breach: everything that makes an intrusion expensive — credential harvesting, lateral movement, data exfiltration, ransomware staging — happens during this window. A phishing email that is clicked and detected the same hour is an incident; the same email detected eight months later is a headline. IBM's Cost of a Data Breach research puts the average time to identify and contain a breach at 247 days, which is a measure of just how long that window stays open in practice.

How it works

Dwell time is usually counted from the first evidence of attacker activity (a malicious login, malware execution, a successful phish) to the first detection by the defender, whether through internal telemetry, an employee report, or — worst of all — notification by an outsider such as law enforcement or the attacker's own ransom note. Attackers actively work to extend it: they use legitimate credentials and built-in tools so that their activity blends into normal administration, establish quiet command-and-control channels, and time noisy actions for weekends and holidays. The longer they remain, the more accounts, systems, and data they touch, and the harder eviction becomes: a one-day intrusion means resetting one account, while a six-month intrusion means assuming every credential and backup in scope is suspect.

How to defend against it

Reducing dwell time is mostly about multiplying chances of early detection. Instrument identity: impossible-travel logins, new MFA device enrollments, and unusual privilege use are the earliest reliable signals. Give your security operations function the log coverage to see endpoints, identity, and email in one place. And treat employees as sensors: the person who receives the phish sees it minutes before any analyst, so a one-click report path and a no-blame reporting culture routinely produce the earliest detection an organization gets — our guide to building a phishing reporting culture shows how to make that reflex reliable, and our incident response guide for social engineering covers what to do in the minutes after the report lands.

Related terms

Lateral MovementLateral movement is how attackers spread from their first compromised account or device to the systems they actually want, reusing stolen credentials and trust.Command and Control (C2)Command and control (C2) is the covert channel malware uses to receive an attacker's instructions and send stolen data out — the remote hand on the compromised device.Data ExfiltrationData exfiltration is the unauthorized transfer of data out of an organization — by external attackers, malicious insiders, or careless employees.Security Operations Center (SOC)A security operations center (SOC) is the team that monitors, detects and responds to security events — including the ones people report.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo