AI SOC

    Breakout in 29 Minutes, Handoff in 22 Seconds: What MTTR Still Measures

    Two clocks govern a modern intrusion. The attacker's clock now runs in seconds and minutes. The defender's clock, as most organisations actually measure it, still runs in hours and days. The gap between them is not a tuning problem, and no MTTR target written for a human shift pattern closes it.

    2026-09-1213 min readAI SOCAutonomous DefenceIncident ResponseSpharaka Sphere™

    Two clocks, moving in opposite directions

    Industry threat research published in February 2026 put the average breakout time for criminal intrusions at 29 minutes. Breakout time is the interval between an adversary landing on the first machine and moving laterally to the second. It was 48 minutes in 2024 and 98 minutes in 2021. The fastest breakout the report observed was 27 seconds, and in one case data exfiltration began within four minutes of initial access.

    In the same year, the most widely cited annual study of breach costs reported that the mean time to identify and contain a breach rose to 247 days, a small increase that reversed five consecutive years of improvement. The average breach cost reached 4.99 million dollars globally.

    Set those two findings beside each other and the picture is not a race that defenders are narrowly losing. It is two clocks running in opposite directions. The attacker's tempo improved by roughly a factor of three in four years. The defender's tempo, measured end to end, got worse.

    The attacker's tempo improved by roughly a factor of three in four years. The defender's, measured end to end, moved the other way.
    Average breakout time for criminal intrusions, in minutesFrom first compromised host to lateral movement. The fastest breakout observed in 2025 took 27 seconds.
    202198 min
    202448 min
    202529 min

    Source: annual industry threat report, published February 2026.

    Twenty-two seconds is the number that should change the conversation

    Incident response research published in 2026, drawn from well over 450,000 hours of investigations, reported a median of 22 seconds between an initial access broker obtaining access and a follow-on operator using it. That is the handoff inside an industrialised criminal supply chain: one group specialises in getting in, another in what happens next, and the interval between them has collapsed to less than half a minute.

    This matters because of an assumption buried in most triage processes. The assumption is that an alert about a suspicious login describes a situation that is still developing, and that an analyst who picks it up within the hour is picking it up early. At a 22 second handoff, the person who obtained the access is already gone and a different operator with different objectives is already working.

    The same research found the global median dwell time rising to 14 days, three days worse than the previous year, pulled up by espionage and North Korean IT worker cases where the median was 122 days. Some intrusions persisted for over a year, frequently by living on edge devices that carry no standard telemetry.

    What MTTR actually measures in most organisations

    Ask three security teams how they calculate mean time to respond and you will usually get three different answers. The most common one starts the clock when a ticket is created and stops it when the ticket is closed. That definition has a specific consequence: everything that happens before a case exists, and everything an analyst decides not to open a case for, is outside the measurement.

    An intrusion does not respect that boundary. The attacker's 29 minutes begin at initial access, not at ticket creation. If an alert sits in a queue for two hours before anyone reads it, the queue time is invisible to the metric while being the single largest contributor to the outcome.

    There are really three clocks inside what teams call MTTR. Time to detect, which telemetry and detection engineering have largely addressed. Time to understand, which is the investigation itself. Time to act, which is the containment step. The middle clock is the one almost nobody measures separately, and it is the one that consumes the window.

    • Time to detect: the alert fires. Mostly a solved problem, and the reason alert volume is what it is.
    • Time to understand: evidence is gathered, correlated and judged. Almost entirely human, almost never measured on its own.
    • Time to act: containment executes. Fast once a decision exists, which is exactly the point.
    Three clocks inside MTTR, and the one nobody measuresAn intrusion from initial access to containment. The middle clock includes the time an alert spends waiting for a person.
    Average breakout, 29 minutes. The attacker has usually moved while the alert is still in the queue.
    What ticket-based MTTR measures. The clock starts when a case is opened, after the queue, so the wait never appears in the number.

    Illustrative, not to scale. Breakout figure from 2026 industry threat research.

    Why the middle clock is the constraint

    The evidence that investigation is the bottleneck is visible in how breaches get found. The same incident response research reported a median dwell time of 26 days when an external party notified the victim, 10 days when the organisation detected the intrusion itself, and 5 days when the adversary announced their presence, typically with a ransomware note. Self-detection is roughly two and a half times faster than waiting to be told.

    That is a finding about internal telemetry and the capacity to act on it. Most organisations already collect the telemetry. What they lack is the capacity to turn a signal into an understood situation quickly enough for the difference to matter, which is a throughput problem rather than a visibility one.

    Throughput problems do not respond to better detection. Adding detections to a saturated investigation pipeline produces more alerts that nobody reaches, and the alerts nobody reaches are indistinguishable, in outcome terms, from detections that never fired.

    Median dwell time by how the intrusion was discovered, in daysOrganisations that found the intrusion themselves ended it in well under half the time of those who were told about it.
    Notified by an external party26 days
    Detected internally10 days
    Announced by the adversary5 days

    Source: incident response research published in 2026.

    The arithmetic nobody likes writing down

    Put the numbers in one line. An adversary moves laterally in an average of 29 minutes. Access changes hands in 22 seconds. In a typical enterprise queue, an alert of moderate severity waits longer than either of those intervals before a person opens it.

    The consequence is not that containment fails. It is that containment happens after lateral movement, which turns every incident into an investigation of an estate rather than the isolation of a host. That is the difference between an event and a breach, and it is decided in the first hour by whether anything competent looked at the signal.

    The pressure is increasing from both ends. Threat researchers recorded an 89 percent rise in attacks by AI-enabled adversaries, and the annual breach cost study found that one in four malicious breaches now involves AI, a 56 percent year-on-year increase, and that those breaches average around 6 million dollars, roughly a million above the global figure.

    What to measure instead

    Metrics shape behaviour, and a metric that starts at ticket creation rewards closing tickets. These are the measurements that describe whether an operation can actually beat an attacker's clock, and every one of them is available from data a platform already holds.

    None of these require a new product to measure. They require the willingness to look at the numbers that make the current architecture look slow, which is the same reason they are rarely reported to a board.

    • Time to first evidence: from signal arrival to an assembled, reviewable case with the surrounding context attached.
    • Time to decision: from evidence to a containment call. The only interval where human judgement genuinely belongs.
    • Proportion investigated: how many alerts were actually examined, as distinct from how many were closed.
    • Containment before breakout: the share of intrusions contained inside the first 30 minutes of initial access.
    • Dwell by detection source: internal, external and adversary-announced, tracked separately rather than averaged into one number.

    What autonomy changes, and what it does not

    The middle clock is mechanical work. Pulling the process tree, resolving the identity, checking the asset's history, correlating the login against travel and device posture, retrieving what threat intelligence says about the infrastructure: none of that is judgement. It is assembly, and assembly is what a platform should absorb.

    That is the design of Spharaka Sphere. AuraXP, the agentic engine, runs the investigation as a team of agents rather than as a queue of alerts, and SAGE, a cybersecurity-specific model rather than a general-purpose one, does the reasoning inside the customer's own boundary. The analyst arrives to a case that is already assembled and makes the decision the evidence supports.

    What autonomy does not do is remove people from the operation. AirWatch governs what the platform is permitted to do on its own, validates every action before it executes, records it afterwards, and runs supervised or unsupervised according to a policy the customer sets. Machine speed without a governance envelope is not an improvement, it is a different category of risk.

    The 2026 breach cost figures are consistent with this: organisations using AI extensively in their own defence saved 1.93 million dollars per incident against those that did not. The saving is not produced by the presence of a model. It is produced by removing the queue in front of the judgement.

    How to test any of this before you buy it

    Vendor claims about autonomy are cheap and largely interchangeable. These four tests are not, because each produces an artefact you can inspect rather than a number in a slide.

    If a platform passes all four, its effect on the middle clock is real. If it passes none, what is on offer is a faster way to read alerts, which is a different purchase and should be priced like one.

    • Give it an alert nobody wrote a playbook for and read the investigation it produces. A system that only executes prewritten branches will produce nothing for a situation nobody anticipated.
    • Ask what it decided not to escalate, and why. A platform that cannot explain a negative decision is not investigating, it is filtering.
    • Measure time to first evidence, not time to alert. The first is the thing you are buying.
    • Check where the reasoning runs. If telemetry leaves your boundary to be understood, that is an architectural fact with regulatory consequences, whatever the contract says.

    The honest conclusion

    Breakout time will keep falling. Access handoffs will keep getting faster, because specialisation in a criminal economy works the same way it works in a legitimate one. No hiring plan available to a normal enterprise closes a gap measured in seconds by adding people who work in shifts.

    The only variable a defender genuinely controls is how long the middle clock runs, which is decided by architecture rather than by effort. An operation where investigation happens at machine speed, with humans on the decisions that carry consequence, has a chance of containing an intrusion inside its breakout window. An operation where investigation waits for a person to reach the queue does not, however good that person is.

    That is the case for autonomy, and it is a narrow one. Not that AI improves security operations in the abstract, but that the specific interval between a signal arriving and a situation being understood is the interval that decides outcomes, and it is the one interval that human-speed process cannot compress.

    Questions

    Frequently asked questions

    What is breakout time, and why does it matter more than dwell time?

    Breakout time is the interval between an adversary compromising the first machine and moving laterally to a second. Threat research published in 2026 put the average for criminal intrusions at 29 minutes, with the fastest observed at 27 seconds. It matters because containment inside that window isolates one host, while containment after it means investigating an estate. Dwell time describes how long an intrusion lasted; breakout time describes how long you had to prevent it from spreading.

    Why is MTTR a misleading metric for security operations?

    Because most teams start the clock at ticket creation rather than at initial access, which makes queue time invisible while it is often the largest contributor to the outcome. It also merges three separate intervals: time to detect, time to understand and time to act. The middle one is where the time actually goes, and averaging it into a single number hides that.

    What should a SOC measure instead of MTTR?

    Time to first evidence, which is the interval from signal arrival to an assembled case; time to decision, which is the only interval where human judgement genuinely belongs; the proportion of alerts actually investigated rather than closed; the share of intrusions contained within 30 minutes of initial access; and dwell time separated by detection source rather than averaged.

    Does automation fix the investigation bottleneck?

    Scripted automation executes a response somebody wrote in advance, which helps for situations that were anticipated and does nothing for the ones that were not. What compresses the investigation interval is a system that reasons about evidence and reaches a decision, then acts inside a governance policy. That is a different capability from a playbook engine, and worth testing separately.

    How much faster is detecting an intrusion yourself?

    Incident response research published in 2026 reported a median dwell time of 10 days when an organisation detected the intrusion itself, against 26 days when an external party notified it, and 5 days when the adversary announced their own presence, usually with a ransomware note. Internal telemetry, and the capacity to act on it, is the single biggest accelerant on detection.

    Does using AI in defence actually reduce breach cost?

    The 2026 annual study of breach costs found that organisations using AI extensively in their own defences saved 1.93 million dollars per incident relative to those that did not. The same report found that one in four malicious breaches now involves AI on the attacker's side, averaging around 6 million dollars, so the effect runs in both directions.

    Next step

    See it running on your environment

    A walkthrough on your own estate, with your own detections, rather than a canned demo.