CrowdStrike: Russian state-sponsored hackers take less than 20 minutes to start moving laterally in a targeted organization's network after an initial breach
It takes Russian state-sponsored hackers less than 20 minutes to start moving laterally within a targeted organization's network …
Context & Ripple Effects
CrowdStrike's sub-20-minute figure for Russian state-sponsored lateral movement set an early benchmark for how little dwell time defenders get between initial breach and network-wide compromise. The metric has only gotten worse since: CrowdStrike's own later reporting put the average breakout time at 29 minutes across all attackers in 2025, a sharp year-over-year acceleration.
Russia-linked tradecraft has also diversified beyond speed alone — Mandiant documented Turla piggybacking on other hackers' decade-old USB-spread malware to slip into victim networks quietly, while Microsoft tracked highly targeted social engineering against fewer than 40 global organizations. Speed of lateral movement remains the constant that defines the defensive problem.
First-order effects
- Security teams facing Russian state-sponsored intruders have a detection-and-response window measured in minutes, not hours — manual triage workflows are effectively too slow to catch lateral movement once it starts.
Second-order effects
- Vendors are pushed to compete on machine-speed detection and automated containment, since CrowdStrike's own published breakout-time metrics double as a sales argument for its platform over slower-response rivals.
Third-order effects
- If breakout times keep compressing as CrowdStrike's multi-year data shows, incident response structurally shifts from human-led investigation after alerting to pre-positioned automation that acts before analysts read the alert.
The trend: Attacker breakout times are compressing year over year, forcing enterprise defense to automate containment at machine speed rather than analyst speed.