Metric

Dwell Time

The length of time an attacker remains undetected inside a network or system after an initial compromise, from breach to discovery.

Definition

Dwell time is the duration between the moment an attacker first gains unauthorized access to a network or system and the moment the intrusion is detected and remediation begins. It is a key measure of how effective an organization's detection capabilities are, since a compromise that goes unnoticed for months allows far more damage than one caught within hours.

During the dwell time period, an attacker typically moves beyond the initial point of entry, escalating privileges, mapping the network, locating valuable data, and often establishing multiple footholds to survive if one is discovered and removed. Longer dwell time gives attackers the opportunity to exfiltrate large volumes of data gradually and quietly, rather than in a single detectable burst, and to study the target's environment closely enough to time a more damaging action, such as deploying ransomware, for maximum impact. Attackers actively try to extend their own dwell time by disabling logging, using legitimate administrative tools to blend in, and avoiding actions that would trigger obvious alerts.

Dwell time matters because it directly correlates with the scale of damage and cost of a breach: the longer an attacker operates undetected, the more data can be stolen, the more systems can be compromised, and the more expensive and complex the eventual remediation becomes. For financial institutions and other regulated organizations in Indonesia, a long dwell time can mean a breach affecting far more customer records than initially assumed once the full scope is finally uncovered, complicating both the technical response and regulatory notification. Reducing dwell time is consistently one of the highest-leverage improvements an organization's security program can make.

Shortening dwell time relies on strong detection capabilities, including continuous monitoring, behavior-based anomaly detection, and a well staffed or outsourced security operations function that can investigate alerts promptly rather than letting them accumulate unreviewed. Threat hunting, where security teams proactively search for signs of compromise rather than waiting for automated alerts, catches sophisticated attackers who are specifically trying to avoid detection. Encouraging employees to report unusual system behavior or suspicious activity they notice, even something that seems minor, adds a valuable human detection layer alongside technical monitoring.

At a glance

Type
Security metric
What it measures
Time from initial compromise to detection
Healthy target
Days, not months
Better when
Lower

How it works

  1. 1

    Initial compromise: an attacker gains unauthorized access to a network or system.

  2. 2

    Lateral movement: they escalate privileges, map the network, and locate valuable data.

  3. 3

    Persistence: multiple footholds are often established to survive if one is discovered.

  4. 4

    Evasion: attackers disable logging and use legitimate tools to blend in and avoid alerts.

  5. 5

    Detection: the clock stops once the intrusion is identified and remediation begins.

Key points

  • It is the duration between initial compromise and detection plus the start of remediation
  • Longer dwell time allows more data to be exfiltrated gradually and quietly
  • Attackers actively try to extend their own dwell time to avoid detection
  • It directly correlates with the scale of damage and the cost of a breach
  • Reducing dwell time is one of the highest-leverage improvements a security program can make

Best practices

  • Invest in continuous monitoring and behavior-based anomaly detection
  • Maintain a well staffed or outsourced security operations function to investigate alerts promptly
  • Run proactive threat hunting rather than waiting only for automated alerts
  • Encourage employees to report unusual system behavior, even if it seems minor
  • Review dwell time trends after every incident to identify detection gaps

Real-world example

A financial institution eventually discovers that an attacker had access to its network for four months before detection, during which time customer records were quietly exfiltrated in small batches to avoid triggering alerts. A subsequent investment in behavior-based detection and threat hunting reduces the organization's dwell time on later incidents to under two weeks.

How Claro helps

Claro's phish reporting workflow shortens the path from a real attack landing in an inbox to security team awareness, directly contributing to lower dwell time when an employee reports what automated filters missed.

Frequently asked questions

What exactly does dwell time measure?

The time between an attacker first gaining unauthorized access to a network or system and the moment the intrusion is detected and remediation begins.

Why do attackers try to extend their own dwell time?

Longer dwell time lets them exfiltrate more data gradually without triggering obvious alerts, and gives them time to study the environment before a more damaging action such as deploying ransomware.

What reduces dwell time?

Continuous monitoring, behavior-based anomaly detection, a well staffed security operations function, and proactive threat hunting that searches for signs of compromise rather than waiting for alerts.

How does employee reporting affect dwell time?

Employees reporting unusual system behavior or suspicious activity adds a human detection layer that can catch what automated monitoring misses, shortening the time to detection.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo