Many firms don’t even track dwell time metrics.
One of the main challenges facing cybersecurity professionals is reducing hacker dwell time, according to a new report from Attivo Networks.
Dwell time is described as the incubation period between the moment hackers compromise a network and when an attack is conducted – be it ransomware, malware, data theft, espionage or any other malicious activity.
Hackers usually use dwell time to map out the network, identify key devices, the most important data sets and cybersecurity solutions.
The report, based on a poll of 1,249 respondents across the globe, states that almost two thirds (64 percent) consider 100 days of dwell time either accurate or too low. Last year, that figure stood at 61 percent, representing marginal growth.
Attivo Networks also highlighted an “alarming trend”: 22 percent of businesses do not track dwell time statistics, up 7 percent year-on-year. The firm believes this trend demonstrates a continued need for more efficient tools to detect and track in-network threat activity and lateral movement.