Dwell Time Is Falling. That Is Not the Same as Winning.
One detection metric hit a nine-year low in 2025. Two related measures moved the other way, and the gap that actually determines loss is widening.
In its 2025 Cost of a Data Breach study, IBM reported the shortest breach lifecycle in nine years: a mean 181 days to identify a breach plus 60 days to contain it, 241 days in total, down from a 2021 peak of 287. The natural reading is that detection and response are improving. That reading is comfortable, and the data only partly supports it.
The other two lines
Mandiant’s M-Trends, working from frontline incident-response cases rather than a survey, put median dwell time for 2025 at 14 days, up from 11 the year before. The two figures are not in conflict. IBM measures a mean across organizations of all sizes and detection maturity; Mandiant measures a median across higher-severity engagements where an IR firm is already involved. But the direction matters, and Mandiant’s moved up, pulled by long-term espionage operations and IT-worker infiltration schemes built to stay resident.
Palo Alto’s Unit 42 supplied the third line. The fastest data exfiltration it observed in 2025 completed in 72 minutes, down from 285 minutes the year before. In some cases the hand-off from an initial-access broker to a ransomware operator took under 30 seconds. Attacker time-to-objective is collapsing.
The number that matters is a difference
Put the series next to each other. Defender mean time to identify: 181 days. Attacker time to complete exfiltration: a little over an hour. When those two numbers describe the same incident, the loss event is finished long before anyone knows it began. The breach lifecycle got shorter, but the part that shrank is the part that happens after the damage is done. The part before detection, which is the part that sets Loss Magnitude, did not move.
What this means for calibration
In quantitative risk terms this argues for two adjustments. First, in any scenario where exfiltration is fast and detection is slow, Loss Magnitude should be calibrated to a complete exfiltration, not a partial one. There is no realistic containment path that limits the data lost when the theft finishes in 72 minutes and detection takes months. Second, it shifts the value case from detective controls toward preventive ones. Monitoring that shaves days off a 181-day mean does not help if the loss was complete on day zero. Raising Resistance Strength, so the attempt fails or stalls at the point of contact, does.
Environment matters too
The IBM data also shows where the lifecycle runs long. Breaches spanning multiple environments took 276 days to identify and contain; purely on-premises breaches took 217. That 59-day spread traces mostly to visibility gaps across cloud and hybrid estates. For an organization modelling its own exposure, that is a concrete input rather than a vague concern: environmental complexity is a Loss Magnitude multiplier, working through response cost and prolonged exposure.
The 241-day figure is real, and it is the best in nearly a decade. It is also the wrong number to celebrate. The one to watch is the distance between how fast an attacker reaches its objective and how long it takes to notice, and that distance grew in 2025.