/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CrowdStrike says the average breakout time for attackers moving from intrusion to other network systems fell to 29 minutes in 2025, a 65% YoY increase in speed

CyberScoop Matt Kapko

Context & Ripple Effects

CrowdStrike’s new lateral-movement measure extends an arc in which its threat reporting has flagged a sharp rise in cloud intrusions and a growing share of malware-free intrusions. Together, those developments make post-compromise detection—not only blocking an initial payload—more central to defenders’ response.

The reported 29-minute average also puts renewed focus on an older warning that some state-sponsored operators could begin moving laterally in under 20 minutes; the difference is that rapid lateral movement is now being presented as a broad, accelerating operating condition.

First-order effects

  • Security teams have a narrower interval to isolate an affected identity, endpoint, or network segment before an intrusion reaches additional systems.
  • CrowdStrike customers and other buyers of detection and response tools will place greater value on telemetry and workflows that identify lateral movement quickly, especially where malware-free access methods are involved.

Second-order effects

  • Detection-and-response vendors face pressure to demonstrate faster correlation, containment, and investigation across endpoint, identity, and cloud environments rather than relying chiefly on preventive controls.
  • Organizations may prioritize incident-response automation and segmentation investments, as credential theft and malware-free intrusion methods can make a fast initial foothold harder to distinguish from normal activity.

Third-order effects

  • If breakout times continue to compress, cybersecurity architecture will shift further from periodic alert review toward continuously enforced, cross-domain response designed to limit an intruder’s blast radius.
  • The practical competitive measure for security platforms may increasingly be time from suspicious activity to containment, although the reported average alone does not establish how broadly that shift has occurred across sectors.

The trend: Cyber defense is becoming a race to contain identity- and cloud-enabled intrusions before increasingly rapid lateral movement turns an initial compromise into a wider incident.

Discussion

  • @adam_cyber @adam_cyber on x
    Incredible work by CrowdStrike Counter Adversary Operations and our broader team on this year's report. The trend line is clear: breakout times continue to accelerate. Defenders have less time than ever to detect, respond, and contain before impact. AI is reshaping the
  • @anthonyspiteri Anthony Spiteri on x
    TL:DR The pointy end is getting pointier!
  • @crowdstrike @crowdstrike on x
    🚨 The CrowdStrike 2026 Global Threat Report is here. In the age of AI, even less sophisticated threat actors can execute complex attacks, and advanced adversaries have become dramatically more dangerous. This year's report exposes the latest tradecraft of the evasive [video]
  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    Per CrowdStrike:  —breakout time from initial access to lateral movement and network compromise was 29 mins last year  —this is down from 98 mins 5 years ago  —fastest breakout time recorded was 27 seconds  —  https://www.crowdstrike.com/ ...  [image]