There was a time when cybersecurity teams could think of response as a sequence: detect an alert, investigate what happened, decide whether it mattered, and then contain the threat before it spread. That model depended on time. It assumed defenders had enough room to separate signal from noise, escalate the right incidents, and bring people into the loop before an intrusion became a business problem.
That assumption is breaking down. Today’s adversaries are moving faster, blending in better, and using AI to scale work that once required more time, more manual effort, and more specialized skill. The result is not simply a higher volume of attacks—it is a shorter window to recognize what is happening and respond before the attacker has already moved on.
Breakout Time Is Now Measured in Minutes
According to CrowdStrike’s 2026 Global Threat Report, the average eCrime breakout time fell to 29 minutes in 2025. That is the time between initial access and lateral movement—essentially, the point at which an intrusion begins to expand beyond the first compromised system. The fastest observed breakout happened in just 27 seconds. In one intrusion, data exfiltration began within four minutes of initial access.
Those numbers change the conversation. A 29-minute average does not leave much room for a ticket queue, a manual handoff, or a wait-and-see investigation. A 27-second breakout leaves almost none. If an attacker can move from entry to expansion while a team is still determining whether an alert deserves attention, then a reactive security posture is already behind.
The trend line makes the point even more clearly. CrowdStrike reported average eCrime breakout time fell to just 29 minutes in 2025—a 65 percent increase in breakout speed from the previous year. The fastest observed breakout took only 27 seconds.
Modern Attacks Are Harder to See
Speed is only part of the problem. The other challenge is that attackers are becoming harder to see. CrowdStrike found that 82 percent of detections in 2025 were malware-free. That matters because many organizations still think about attacks in terms of malicious files, suspicious payloads, or tools that can be identified and blocked. But modern intrusions often move through valid credentials, trusted applications, cloud services, and approved workflows. They do not always look like malware. Sometimes they look like normal activity until enough context reveals otherwise.
That shift creates a visibility problem. If defenders are looking primarily for malicious files, but attackers are using legitimate access paths, the organization may be watching the wrong places.
Endpoint telemetry still matters, but it cannot be the only source of truth. Identity behavior, SaaS activity, cloud configuration, privileged access, and unusual data movement all become part of the same detection picture. The question is no longer simply, “Did a malicious file execute?” It is, “Does this activity make sense for this user, this system, this privilege level, and this moment?”
AI Is Changing Both the Speed and Shape of Attacks
AI is accelerating that shift. CrowdStrike reported an 89 percent year-over-year increase in operations by AI-enabled adversaries, with attackers weaponizing AI across reconnaissance, credential theft, and evasion. Those are not abstract risks. Reconnaissance is how attackers find the right doorway. Credential theft is how they turn access into movement. Evasion is how they stay in the environment long enough to accomplish their objective. When AI shortens or scales each of those steps, the entire intrusion lifecycle gets faster.
AI also expands the attack surface because enterprise AI systems themselves are becoming targets. According to the CrowdStrike report, adversaries injected malicious prompts into legitimate GenAI tools at more than 90 organizations and abused AI development platforms. That is a concrete example of what AI-enabled attack activity can look like in practice. Not only are bad actors using AI to move faster, AI also powers the tools organizations are adopting for productivity, software development, analysis, and automation. These new tools that are being incorporated into your organization can become part of the path attack surface.
“AI gives attackers speed, and it gives them new doors. Every GenAI tool and development platform an organization adopts becomes part of the attack surface, and adversaries already probe them. Teams that inventory those systems, govern the identities behind them, and monitor how they behave turn AI adoption from an exposure into a controlled advantage.” –Rob Di Girolamo, Sr. Solution Architect at Connection
Defenders Need Preparation Before the Threat Lands
For security teams, the practical takeaway is uncomfortable but important: waiting to respond is becoming a losing strategy. That does not mean every organization needs to chase every new tool or automate every decision. It means the foundation has to be built before the threat lands. Visibility, preparation, and practiced response have to come first, because the window for improvisation is shrinking.
Building that foundation starts with knowing where attackers are most likely to move and what normal looks like across the environment. Identity should be treated as a primary control plane, not an administrative afterthought. Privileged accounts, service accounts, tokens, and third-party access deserve the same scrutiny organizations have historically applied to endpoints. If attackers are using trusted access paths, defenders need to understand those paths before they are abused.
It also means reducing fragmentation. When endpoint, identity, cloud, SaaS, and data signals live in separate systems with separate owners and separate workflows, attackers benefit from the gaps between them. A fast-moving intrusion may touch several parts of the environment before any single alert looks decisive. Defenders need the ability to correlate activity quickly enough to see the pattern while there is still time to act.
The accelerating adversary is not a future problem. It is already visible in the speed of breakout, the rise of malware-free activity, the scale of AI-enabled operations, and the emergence of prompts and AI platforms as attack surfaces. The lesson is not that defenders should panic. It is that they should stop planning around yesterday’s response window.
As part of our month-long discussion of AI and cybersecurity for Cybersecurity Awareness Month, keep an eye out for our upcoming webinar, AI + Quantum: The Security Threats You Can’t Afford to Ignore. Our Security Center of Excellence team will walk through the AI attack surface already sitting inside most enterprise environments, from AI-enabled applications and security tools to models, agents, and how people are actually using AI day to day, and how to tell whether what’s deployed lines up with your security policies.