Breakout time has become one of cybersecurity’s most uncomfortable clocks according to CrowdStrike’s 2026 Global Threat Report. The average eCrime breakout time, the period between initial access and lateral movement, fell to just 29 minutes in 2025.
The fastest observed breakout took 27 seconds.
Source: CrowdStrike 2026 Global Threat Report
That is not merely faster hacking; it is a shrinking window for human-led defence.
The bigger story is that adversaries are no longer waiting for malware to do the heavy lifting. CrowdStrike says 82% of detections in 2025 were malware-free, while attacks by AI-enabled adversaries rose 89% year on year.
Instead of dropping obvious payloads, attackers are increasingly using valid identities, SaaS access, cloud infrastructure and trusted workflows to look like normal business activity.
That is why “breakout time” matters. If an attacker can move from one system to another in under half an hour, SOC teams cannot afford investigation queues measured in hours.
Triage, identity telemetry, session risk, privilege escalation and automated containment all need to happen at machine speed, with analysts brought in to make judgement calls rather than manually stitch together the first facts.
Identity is now the intrusion path
Attackers are now “blending into legitimate access paths” and relying less on malware. That should change how defenders prioritise controls. Static secrets, long-lived tokens and loosely governed service accounts are no longer hygiene issues. They are breakout accelerators.
The practical response is not to buy another dashboard. SOC teams should tune playbooks around identity-first detection: impossible travel, unusual token use, abnormal SaaS access, privilege changes, suspicious OAuth grants and lateral movement from non-human identities. Endpoint telemetry still matters, but it is no longer enough when the attacker’s first move looks like a successful login.
The uncomfortable takeaway is this: defenders are not just racing malware anymore. They are racing authorised-looking activity. In that environment, the best teams will be those that can detect intent before a valid session becomes a full-blown breach.
Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.