What Is Dwell Time?

Also called: Attacker dwell time, Breach dwell time

Related problems: Attackers could be in our network for weeks before anyone notices; No one reviews security logs regularly; Insurer or board asking how fast we'd detect a breach; Not sure whether our MDR provider catches intrusions quickly

Dwell time is the length of time an attacker is present in an environment before being detected or removed, measured from the first sign of compromise to discovery or containment. It’s a measure of how long an intruder has to explore, steal credentials, move between systems and take data before anyone stops them. Shorter dwell time generally means a smaller incident.

At a glance

  • Dwell time runs from the attacker’s first access to detection, or in some definitions to containment.
  • It is usually worked out after an incident, by investigators tracing evidence back to the start.
  • Longer dwell time gives attackers more chance for lateral movement, data theft and ransomware staging.
  • Around-the-clock monitoring, threat hunting and good logging are the main ways to shorten it.
  • Definitions vary between reports, so compare figures carefully.

What problem it solves

As a measure, dwell time puts a number on a risk that’s otherwise easy to ignore: an attacker who’s already inside and quiet. Many attacks don’t announce themselves on day one. An attacker may gain access through a phishing email or stolen password, then spend days or weeks mapping the network, escalating privileges and copying data before deploying ransomware or making demands.

Each day undetected raises the cost of the incident: more systems to clean, more data potentially exposed, more notification and legal work. Tracking dwell time, and the detection capabilities that drive it, gives buyers a way to judge whether their monitoring is working and whether a security provider is actually finding intrusions or only reacting to the obvious ones.

How it works

Start point. Investigators look for the earliest evidence of attacker activity: a first malicious login, a planted file, a suspicious process. Gaps in log retention can make the true start unknowable, which is a reason to keep logs long enough.

End point. Detection is when the organization or its provider identifies the intrusion. Some definitions instead end at containment, when the attacker’s access is cut off. Know which a report or contract uses.

Contributing factors. Dwell time tends to be longer when logs aren’t collected or reviewed, when alerts go unanswered outside business hours, when attackers use legitimate tools and valid credentials, and when a breach is discovered by an outside party rather than internal monitoring.

Reducing it. Common measures include:

When it matters for buyers

  • When choosing an MDR or SOC service. Ask how the provider detects quiet intrusions, not just loud ones, and what proactive hunting is included. Our managed detection and response overview covers what to compare.
  • When cyber insurance renews. Monitoring, logging and response capabilities affect how insurers view your risk.
  • When setting log retention. If logs only go back a few days, investigators may not be able to find the start of an intrusion.
  • When a peer is breached. Their investigation’s timeline is a useful prompt to ask how quickly you’d have spotted the same activity.

Questions to ask vendors

  • How do you detect attackers using valid credentials and legitimate admin tools?
  • Is proactive threat hunting included, how often, and what do you report from it?
  • What telemetry do you need from us to detect intrusions early, and how long do you retain it?
  • How do you measure time to detect and time to contain, and can we see those figures for our account?
  • After an incident, will you establish the timeline and dwell time as part of the investigation?

How it differs from MTTD and MTTR

Mean time to detect (MTTD) is an average across many incidents or alerts, used to track a security team’s performance over time. Dwell time usually describes a single intrusion. Mean time to recovery (MTTR) measures how long it takes to restore service after detection. Together they describe the whole timeline: how long the attacker was in, how fast you noticed, and how fast you recovered.

Frequently Asked Questions

Why does dwell time matter?
The longer an attacker goes unnoticed, the more time they have to steal credentials, move between systems, take data and prepare ransomware. Shorter dwell time generally means a smaller, cheaper incident.
How is dwell time measured?
It is usually calculated after an incident, from the earliest evidence of attacker activity to the time of detection or containment. Definitions vary, and you often only learn the start date through investigation, so it is a backward-looking measure.
What is a typical dwell time?
It varies widely by industry, attack type and how the breach was found, and published industry figures change from year to year. Compare figures from the same source and method rather than relying on a single headline number.
How do we reduce dwell time?
Collect the right logs and telemetry, have someone watching them around the clock (in-house or through MDR), hunt proactively for threats that don't trigger alerts, and practice incident response so detection leads to fast containment.
Is dwell time the same as MTTD?
They are closely related. Dwell time describes one intrusion: how long that attacker was present. Mean time to detect (MTTD) averages detection time across many incidents or alerts, and is used as an operational metric.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.