Host block holding a still marked capsule beside a column of stacked segments counting days to detection.

Dwell Time

Dwell time is how many days an attacker spends inside a compromised network before anyone notices them. Right now the global median is 14 days, measured across 2025 in Mandiant's M-Trends 2026 report. That single number is where the confusion starts.

You have probably seen it quoted three ways this month: 14 days in one report, 241 in another, 200-something in a study you half-remember. They cannot all be the current figure, and they do not agree because they are not measuring the same thing. This page settles which is which: the precise definition, the full arc of the number over time, how it relates to the other clocks you will meet, and what to actually do with it.

Caliper spanning exactly two gates on a rail, with the rail past the second gate left unmeasured.

What is dwell time in cybersecurity?

Dwell time is the number of days an attacker spends inside a compromised environment before they are detected. Mandiant, whose annual M-Trends reports are where the figure usually comes from, reports it as a median, not an average, and the clock stops at detection, not at the point the attacker is removed. The current global median is 14 days.

That definition is narrower than most glossaries admit, and the two boundaries matter. The clock starts at the moment of compromise and stops the moment the intrusion is discovered, so dwell time measures the detection gap and nothing after it. Mandiant states it plainly: dwell time is "the number of days an attacker is present in an environment that has been compromised before they are detected." The reported number is a median, the midpoint of all investigated intrusions, which means half ran shorter and half ran longer. An average would be dragged upward by a handful of multi-year intrusions; the median is the more honest center.

Two footnotes keep the definition accurate:

  • No official standard: the NIST glossary carries no entry for dwell time at all, so the working definition is the one incident-response firms use, not a government-ratified one.
  • Vendor drift: some glossaries quietly move the finish line, running the clock "from the time they get in until they are eradicated," which folds in the whole cleanup phase and inflates the number.

When you compare two dwell-time figures, check where each one stops the clock.

Dwell Time Quiz

Test your knowledge about Dwell Time - maybe you already know everything about it.

EasyQuestion 1 of 3

What does dwell time measure?

Quiet house with one lit side room, an advancing calendar drum outside and an alarm plate still dark.

Explain It Like I'm 10

Imagine someone slips into your house while you are out and starts living in the spare room. Dwell time is not how long it takes to get them out. It is how many days pass between the day they got in and the day you finally notice they are there. If they moved in three weeks ago and you spot them today, that is three weeks of dwell time, whether you call the police in the next five minutes or the next five days. The whole point of the number is that noticing is the hard part.

Staircase of measuring columns falling to a low point, then two rising again with a marked cap.

What is the average dwell time in 2025?

The current global median dwell time is 14 days, covering the 2025 calendar year, published in Mandiant's M-Trends 2026 report. That is up from 11 days the year before, which was itself up from 10 the year before that. Two consecutive increases, after roughly a decade of steady decline.

The long arc is the part almost no summary shows you, and it is worth seeing in full because it reframes the current number. Every figure below is a global median from the Mandiant (formerly FireEye) M-Trends edition that reported it:

Year (data)

Global median dwell time

Reported in

2011

416 days

M-Trends 2019 (retrospective)

2014

205 days

M-Trends 2025

2017

101 days

M-Trends 2019

2018

78 days

M-Trends 2019

2020

24 days

M-Trends 2022

2021

21 days

M-Trends 2022

2022

16 days

M-Trends 2024

2023

10 days

M-Trends 2024

2024

11 days

M-Trends 2025

2025

14 days

M-Trends 2026

From 416 days in 2011 to a low of 10 in 2023, the trend ran one direction for years. The 2023 figure was the floor. Then it turned: 11 days in 2024, then 14 in 2025. (A few intermediate years, such as 2015, 2016, and 2019, are not shown because they could not be confirmed against a primary Mandiant source; the verified points above are enough to see the shape.)

That reversal is the story no stale glossary tells, and it is the next question.

Balance beam tipping toward three long sparse columns and away from a bank of short packed ones.

Why did dwell time rise after a decade of decline?

The rise is real but modest, and Mandiant is careful about the cause. It "likely reflects growing sophistication, particularly in evading defenses," the firm writes, keeping the word "likely" because a two-year uptick is a signal, not yet a settled trend.

What pulled the median up

The clearest driver is the mix of intrusions. Mandiant attributes the increase "largely to long-term espionage and DPRK IT worker operations" in its executive edition. Cyber-espionage and North Korean IT-worker incidents run far longer than the typical case: their category median was 122 days in 2025, and when more of the year's investigations fall into that bucket, the overall median is pulled upward. The distribution shifted the same direction, with a marginal drop in intrusions caught within a week and a move toward longer stays between one week and six months. The long tail is longer still: the BRICKSTORM backdoor reached dwell times of nearly 400 days, which is a direct problem for the standard 90-day log retention window, since the evidence of initial access is gone before anyone goes looking for it.

The catch: a falling number was never a clean win

Now the part that undercuts a triumphant reading of the earlier decline. Falling dwell time was never pure defender victory. Mandiant itself names ransomware as a downward force on the metric, noting that "various factors (such as ransomware) help drive down dwell time." The mechanism is close to circular: in a ransomware attack, the "detection" is often the ransom note itself. In 2025, adversaries notified the target in 44% of ransomware cases, which means the attacker's own extortion demand is what ends the clock.

The 2024 numbers show how much this compresses the figure. Median dwell time that year split sharply by who noticed the intrusion first:

  • 5 days when the adversary notified the victim, typically the ransom note.
  • 10 days when the organization found the intrusion internally.
  • 26 days when an external party raised the alarm.

A wave of fast, self-announcing ransomware makes the median look excellent without a single detection improving.

So read the number in both directions. The decade of decline was partly defenders getting faster and partly the ransomware business model detecting itself; the 2025 rise is partly a shift toward stealthy, long-dwell espionage rather than defenses broadly failing. The metric moves with attacker economics and detection sources, not just with defender skill. Two up-years is the most the data will support saying, and it is not a scoreboard.

Four calipers of different spans clamped over different segments of one shared rail.

Is dwell time the same as MTTD or MTTR?

No. Dwell time is one of five clocks that get quoted interchangeably and measure genuinely different things, which is why a 14-day figure and a 241-day figure can both be correct. The table sorts them out.

Metric

What it measures

Clock: start to stop

Median or mean

Current figure

Dwell time

Attacker present before detection

Compromise to detection

Median

14 days (M-Trends 2026)

MTTD (mean time to detect)

A SOC's per-incident detection speed

Incident start to detection

Mean

Varies by org

MTTR (mean time to respond)

Response after detection

Detection to containment/remediation

Mean

Varies by org

Breakout time

Speed of lateral movement

Initial access to second host

Average

29 minutes (CrowdStrike 2026)

Breach lifecycle

Full breach duration

Compromise to contain and restore

Mean

241 days (IBM 2025)

The two that trip people up most are MTTD and the IBM number. MTTD sounds identical to dwell time and is closely related, but it is a per-incident operational average a security team tracks over its own alerts, whereas dwell time measures one attacker's presence across a dataset of investigated intrusions. IBM's Cost of a Data Breach 2025 reports its own headline as a mean of 241 days to "identify and contain a breach, including restore services." That is a different clock (it runs well past detection through containment), a different measure (a mean, not a median), and a different population (a survey of 600 breached organizations across all breach types, versus Mandiant's frontline incident-response engagements). Neither number is wrong. They are answers to different questions, and quoting one where the other belongs is the fastest way to lose an expert reader.

Breakout time, the clock that moves the other way

Breakout time is the fourth clock, and it is worth knowing because it moves in the opposite direction from dwell. CrowdStrike defines it as the time from compromising the first machine to moving laterally onto a second, and its 2026 Global Threat Report puts the average eCrime breakout at 29 minutes, with the fastest observed case at 27 seconds. Dwell time is measured in days; breakout time in minutes. They describe different stages of the same intrusion.

One honesty note on measurement: there is no standard formula you plug your own logs into. Dwell time is a metric derived from an incident-response dataset. What a SOC actually tracks operationally is MTTD and MTTR plus the detection source. And the older figures still circulating, the 193 days, the 56 days, the "roughly six months," are dead numbers with no current primary behind them. Every dwell figure worth quoting carries its year and its report edition.

Marked core climbing three platforms, tapping a key module, then reaching a second host far away.

What do attackers actually do while they dwell?

During those days or weeks, an attacker is rarely idle. The typical progression is privilege escalation, then credential theft, then lateral movement to reach more valuable systems, then persistence so access survives a reboot or a password reset. Much of it uses living-off-the-land techniques, meaning built-in system tools rather than obvious malware, which is exactly why the activity blends into normal administration and the dwell clock keeps running.

A documented case: Volt Typhoon

The clearest documented case is Volt Typhoon, a state-sponsored group that US agencies described in a joint CISA advisory. In some victim environments, the actors maintained access "for at least five years." The advisory records the in-dwell cadence concretely: in one compromise the group extracted the Active Directory database (NTDS.dit) from three domain controllers over a four-year period, and in another it pulled the same database twice within nine months. The playbook it lists is the standard one made explicit, including obtaining administrator credentials through privilege-escalation flaws, moving laterally to domain controllers with valid credentials, establishing persistence, and using targeted log deletion to erase the trail as it went.

Fast and slow: the two ends of the range

Not every intrusion is slow. The two ends of the range coexist, and it matters to label which figure is which. The fastest observed breakout in CrowdStrike's 2026 data was 27 seconds; in one intrusion, data exfiltration began four minutes after initial access, though that is a single case, not an average. Palo Alto Networks Unit 42 reports that in the fastest cases it investigated, attackers moved from initial access to data exfiltration in 72 minutes, four times faster than the year before, and it notes that encryption-based extortion is declining as more attackers skip encryption and go straight to quiet data theft. A fast attacker can do real damage inside a low dwell-time number; the median describes the middle of the distribution, not the worst case you should plan for.

Scanning gantry and archive spool beside a caliper clamped in a short span near the entry gate.

How do defenders actually shorten dwell time?

The lever that moves the number is detection, and one trend line shows it working. The share of intrusions organizations caught themselves, rather than being told by an outside party, rose from 43% in 2024 to 52% in 2025, continuing a climb from 46% back in 2023. Internal detection matters because internally discovered intrusions tend to carry shorter dwell than externally notified ones, so improving your own detection directly compresses the gap.

A few practices back that up, stated at the strength the evidence supports:

  • Threat hunting turns things automation missed into permanent detections. In one published example, a hunting team "put twelve new automated detections into production this quarter that find cloud exfiltration activity that we previously missed." That is the mechanism, hunt finds a gap, a new detection closes it for good, though no primary study puts a clean "hunting cuts dwell by N days" figure on it, so treat vendor claims of a specific number with caution.
  • Behavioral detection earns its place because attackers live off the land. A SANS threat-hunting survey found living-off-the-land techniques in 76% of nation-state attacks, and signature-based tools do not flag a legitimate admin utility; detecting the behavior is what catches it.
  • Closing the visibility gap: Unit 42 makes a blunt observation from its investigations: the signals were usually there. "The evidence is in the logs," but during the attack teams had to stitch it together from disconnected sources, which slowed detection in the critical early window. Consolidating that telemetry is dwell-time work.
  • Sizing log retention to real dwell times: If BRICKSTORM can sit for nearly 400 days and your logs roll off at 90, the record of how the attacker got in is gone before the investigation starts. Retention should be set against the dwell times actually seen, not a default.

Category tools such as NDR, EDR, and MDR can shorten these detection paths, but whether a platform or a managed service fits your team is a separate decision with its own trade-offs, and not one a dwell-time page should pretend to settle.

Small rack of three glass cartridges, each holding exactly one settled capsule.

Quick answers

What is the shortest dwell time recorded by an APT? There is no single canonical "shortest dwell" figure, and be wary of any source that quotes one. The verified speed records measure different clocks: the fastest observed breakout was 27 seconds, exfiltration began four minutes after access in one documented intrusion, and the fastest full access-to-exfiltration chain Unit 42 investigated was 72 minutes. Each is a different stage, and none is a "dwell time."

What was the average dwell time in a given year? Use the arc table above, and always cite the M-Trends edition for the year you mean: the global median was 10 days for 2023, 11 for 2024, and 14 for 2025. Quoting a year's figure without its report edition is how stale numbers stay in circulation.

One measuring capsule in a cradle carrying three engraved plates on separate brackets.

Date the stat, name the clock

The three numbers from the top were never in conflict. Fourteen days is the current global median attacker dwell time, measured to detection (Mandiant M-Trends 2026). Two hundred forty-one days is IBM's mean breach lifecycle, measured through containment. And "200-something" was a real dwell figure, from about a decade ago. Different clocks, different years, all quotable once you know which is which.

The discipline is small and it is the whole point: a dwell-time number without its year, its report edition, and the clock it measures is folklore, not data. Name all three when you quote one. Then turn the metric on your own environment: does your log retention outlast the dwell times attackers actually achieve, and who detects first in your org, your team, an outsider, or the attacker holding the door open? You do not want the ransom note to be your detection strategy. The number moves every report cycle, so the durable skill is not memorizing 14 days; it is knowing what it counts.