RackTop Systems
Cyberstorage Explainer

How long do data breaches go undetected? What dwell time measures, and what it leaves out

Mandiant puts the median dwell time at 14 days. IBM puts the average time to identify a breach at 183. Both are right, and neither says how long it takes to learn what an attacker took.

RackTop Systems•October 2, 2026•6 min read

Key takeaways

  • Mandiant’s M-Trends 2026 report, based on its incident investigations from January 1 to December 31, 2025, puts the global median dwell time at 14 days, up from 11 days in 2024. Cyber espionage and North Korean IT worker intrusions had a median dwell time of 122 days.
  • IBM’s 2026 Cost of a Data Breach Report, covering 602 breaches between March 2025 and February 2026, found organizations took an average of 183 days to identify a breach and 64 more to contain it, 247 days in all. Breaches with lifecycles longer than 200 days cost an average of $5.65 million, against $4.32 million for shorter ones.
  • Who finds an intrusion shapes how long it lasts. In Mandiant’s 2025 investigations, organizations detected the activity themselves 52% of the time, outside parties notified them 34% of the time, and attackers announced it 14% of the time. In ransomware cases, the attacker was the first to say so 44% of the time.
  • Dwell time stops at detection, while the question regulators and customers ask is what was taken. An immutable, per-operation record of reads kept by the storage itself turns that answer into a query.

How long do data breaches go undetected? The answer depends on who is counting, and how. Mandiant’s M-Trends 2026 report, built on its 2025 incident investigations, puts the global median dwell time, the stretch between an attacker’s arrival and its discovery, at 14 days, up from 11 the year before. IBM’s 2026 Cost of a Data Breach Report, covering 602 breaches between March 2025 and February 2026, found that organizations took an average of 183 days to identify a breach and another 64 days to contain it, according to coverage of the report by Security Boulevard, eSecurity Planet, and Baker Donelson.

The figures only look contradictory. They measure different populations in different ways, and the gap between them says a lot about which intrusions stay hidden and why. It also points to a second interval that neither headline captures: the time between detecting an intrusion and knowing what it took.

Why one report says 14 days and another says 183

Part of the gap is statistical. Mandiant reports a median, the midpoint of its cases, while IBM reports a mean, which a minority of very long intrusions can pull far upward. The populations differ as well: Mandiant counts the targeted intrusions its own responders investigated, while IBM’s study covers a broad set of breached organizations across 17 industries. And the intervals are not identical. Mandiant counts the days until an intrusion was detected, while IBM’s 247-day figure runs all the way through containment.

The shape of Mandiant’s distribution matters more than its midpoint. Mandiant attributes the rise from 11 to 14 days largely to cyber espionage and North Korean IT worker operations, both of which had a median dwell time of 122 days, and it reports a shift in 2025 toward intrusions lasting between one week and six months. In cases involving one stealthy backdoor that runs on appliances without endpoint detection, it measured an average dwell time of 393 days.

The cost follows the clock. IBM found that breaches with a lifecycle longer than 200 days cost an average of $5.65 million, against $4.32 million for those resolved sooner.

The intrusions that announce themselves end fastest

Who discovers an intrusion shapes how long it lasts. Across Mandiant’s 2025 investigations, organizations first detected the malicious activity themselves 52% of the time, up from 43% in 2024. An outside party notified them 34% of the time, and the attacker did so 14% of the time. In ransomware cases the attacker spoke first 44% of the time, which Mandiant notes is consistent with the ransomware business model. An encryptor ends its own dwell time with a ransom note.

Data theft has no such ending. An intruder copying files has every reason to stay quiet, and when notice comes it often comes from outside. In RackTop’s running list of 2026 government breaches, the City of Suffolk, Virginia learned from CISA that data may have been exfiltrated, and the Pentagon’s Defense Manpower Data Center established a nine-month access window only after it found a vulnerability in its file-sharing system. Japan’s Digital Agency is the counterexample: it caught its intrusion because a large volume of files was accessed with a single maintenance staff account.

The second clock: knowing what was taken

Dwell time ends when someone notices. The obligations that follow, notifying regulators, customers, and the people whose data was exposed, depend on a different answer: which data the intruder actually read. That interval has no industry benchmark, and it is often the longer of the two. CareCloud, whose electronic health record environment was accessed for six days in March, took until late June to determine what had been taken and until the end of July to notify at least 345,000 people.

Mandiant’s report explains why scoping drags. Sophisticated attackers mask file modifications and clear system logs, which can make the timeline of a data theft nearly impossible to reconstruct, and standard 90-day log retention cannot cover intrusions that run for a year or more. Without definitive forensic evidence, Mandiant warns, an organization may be forced to assume the worst-case theft and disclose it.

Where the storage layer shortens both clocks

Most intrusions that matter eventually have to touch the data. An edge-device backdoor, a voice-phished help desk reset, and a stolen contractor login all lead to the same place: reads and writes against the files and records the attacker came for. Because the activity cannot be routed around that point, the storage layer is where detection time and scoping time can both be shortened.

RackTop BrickStor SP evaluates every SMB, NFS, S3, and Web Drive operation inline. Its Active Defense engine profiles normal activity for each user, host, and dataset and ends an anomalous session in under a second, so a valid account reading a share it never uses, or a session copying files in bulk, is stopped while it is happening. Attribute-based access control limits how much any one identity can reach in the first place. Every operation is also written to an immutable audit record held by the storage itself, separate from the hosts an attacker can wipe, which turns the scoping question into a query: which files the session read, when, and from where.

Industry benchmarks tell you where the field stands. The measure that matters for your own estate is narrower: how long a valid account could read sensitive files before anything stopped it, and how quickly you could list what it read. Both can be tested, and the seven proof-of-concept tests in RackTop’s Cyberstorage evaluation guide are built to measure them.

Frequently asked questions

Dwell time is the number of days an attacker is present in an environment before the intrusion is detected. Mandiant’s M-Trends 2026 report puts the global median at 14 days for intrusions it investigated in 2025, up from 11 days in 2024.
It depends on the measure. Mandiant’s M-Trends 2026 reports a global median dwell time of 14 days across its 2025 investigations, with cyber espionage and North Korean IT worker intrusions at a median of 122 days. IBM’s 2026 Cost of a Data Breach Report found an average of 183 days to identify a breach and 64 days to contain it. The gap reflects a median versus a mean, different populations, and different intervals.
Dwell time runs from an attacker’s arrival to the moment the intrusion is detected. Time to contain runs from detection to the point the attacker is shut out. A third interval, scoping, runs until the organization knows what data was taken, and it often determines how broad the breach notification has to be.Six days inside, three months to say what left: the CareCloud breach
Ransomware announces itself: in Mandiant’s 2025 ransomware investigations, the attacker was the first to notify the victim 44% of the time, usually with a ransom note. Data theft and espionage depend on staying quiet, which is why Mandiant measured a median dwell time of 122 days for cyber espionage and North Korean IT worker intrusions.
Detect at the data. Behavioral analysis of every file operation, reads included, can flag and stop a valid account that starts reading or copying files outside its normal pattern. RackTop BrickStor SP does this inline across SMB, NFS, S3, and Web Drive, ends anomalous sessions in under a second, and keeps an immutable per-operation audit for scoping.NAS ransomware protection: behavior-based defense

Measure your own detection time

Put BrickStor SP in your environment for 90 days and time how long it takes to stop a bulk read from a valid account, with a RackTop engineer alongside you.

Data Breach Dwell Time: How Long Breaches Go Undetected | RackTop