CrowdStrike says the average breakout time for attackers moving from intrusion to other network systems fell to 29 minutes in 2025, a 65% YoY increase in speed
Context & Ripple Effects
CrowdStrike’s new lateral-movement measure extends an arc in which its threat reporting has flagged a sharp rise in cloud intrusions and a growing share of malware-free intrusions. Together, those developments make post-compromise detection—not only blocking an initial payload—more central to defenders’ response.
The reported 29-minute average also puts renewed focus on an older warning that some state-sponsored operators could begin moving laterally in under 20 minutes; the difference is that rapid lateral movement is now being presented as a broad, accelerating operating condition.
First-order effects
- Security teams have a narrower interval to isolate an affected identity, endpoint, or network segment before an intrusion reaches additional systems.
- CrowdStrike customers and other buyers of detection and response tools will place greater value on telemetry and workflows that identify lateral movement quickly, especially where malware-free access methods are involved.
Second-order effects
- Detection-and-response vendors face pressure to demonstrate faster correlation, containment, and investigation across endpoint, identity, and cloud environments rather than relying chiefly on preventive controls.
- Organizations may prioritize incident-response automation and segmentation investments, as credential theft and malware-free intrusion methods can make a fast initial foothold harder to distinguish from normal activity.
Third-order effects
- If breakout times continue to compress, cybersecurity architecture will shift further from periodic alert review toward continuously enforced, cross-domain response designed to limit an intruder’s blast radius.
- The practical competitive measure for security platforms may increasingly be time from suspicious activity to containment, although the reported average alone does not establish how broadly that shift has occurred across sectors.
The trend: Cyber defense is becoming a race to contain identity- and cloud-enabled intrusions before increasingly rapid lateral movement turns an initial compromise into a wider incident.