Blog

Faster Detection Doesn’t Matter When Breakout Takes Seconds

If a threat is detected fast, you can stop it before it negatively impacts your business. This has been a core objective of security operations teams.

Not surprisingly, every dashboard, every KPI review, and every budget conversation about the SOC has quietly rested on reviewing metrics around alerts.

Detect sooner, respond sooner, less risk… right?  It made sense for a long time, and the data supported it.

Unfortunately, with the rise of AI-driven threats, this changed faster than most security programs could ever prepare for. According to recent reports, the median breakout time (the window between initial compromise and the moment an attacker moves laterally or escalates privileges) collapsed from roughly eight hours to approximately 22 seconds.

We’re not talking 22 minutes. Twenty-two seconds.

That number should be enough to make any CISO stop mid-meeting and reconsider how their SecOps is measured, staffed, and designed, because the primary objectives everything was built on no longer holds.

The Detection-Speed Fallacy

Mean Time to Detect, alert-to-triage time, and time to notify are common metrics to track in SecOps, but these numbers only made sense when defenders actually had more of a leg in the game. When an attacker needed hours to move through an environment, shaving minutes off detection helped create an advantage for teams since it gave them more time to respond on the back-end.

With a breakout happening in seconds, that equation breaks down completely. Even if an analyst receives an alert the instant it hits, they still have to investigate it, figure out whether it’s legitimate, weigh the business context, decide on a response, and then actually execute that response. This is all manual, and time consuming. This incident is bound by human decision, internal workflows, and  whatever approval chains an organization has in place.

We’ve spent years optimizing detection, but at this point, detection may not be the part of the process that needs the most optimizing. The industry has gotten very good at accelerating detection, while quietly accepting that decision-making would stay human, and therefore slow. That trade-off worked…until attackers could move through an environment faster than an analyst can finish reading the alert that was flagged to them.

The Real Bottleneck Is Decision Capacity

Ask most security leaders what keeps them up at night and they’ll say alert volume. It’s the easy answer, and it’s not wrong exactly, but it’s incomplete. Alert volume is a symptom. The actual bottleneck sitting underneath it is decision capacity. (See our previous post on Security Theatre)  

Most SOCs have already automated a large share of routine, repeatable events. When a familiar

condition shows up, a deterministic workflow fires and handles it without a human ever touching it.

That part of the problem is largely solved, and it isn’t what’s keeping teams stretched paper thin. What’s left after that automation runs its course is the harder category: the novel situations, the unusual combinations of signals, the suspicious-but-incomplete patterns that don’t cleanly match a known rule. That smaller set of cases eats a disproportionate share of the SOC’s time and energy precisely because traditional automation can’t confidently make a call on them, and yet these are exactly the moments where defenders now need to act at machine speed rather than human speed.

Yet many organizations are still investing heavily in detection while leaving the operating model around it largely untouched. An analyst is still expected to review the evidence, make the call, get the necessary approval, and initiate a response. Attackers have accelerated dramatically; most of those internal processes haven’t.

(We go more into why the Old Cyber Defense Model Breaks in the Autonomous Threat Era here.)

Why “Human in the Loop” Is No Longer Enough

“Human in the loop” has become something of a mantra in cybersecurity, and for good reason. Nobody wants an AI system making unchecked decisions inside their environment, but the model starts to break down the moment every single decision requires a person to stop, review, and click approve. If an AI agent can investigate an event in seconds but still has to wait on a human to read the recommendation and press a button, there is still a bottleneck.

None of this means humans step out of the picture. What changes is the nature of the role. Rather than making every decision themselves, security professionals shift toward something more strategic: defining what acceptable risk looks like, setting the rules of engagement, deciding where escalation thresholds sit, and owning accountability for how things play out. The machine operates inside those boundaries, making and executing the operational decisions that fall within them. It’s the difference between a human making every decision and a human governing how decisions get made, and that distinction is the whole point.

Machine-Speed Decisions, Human Accountability

Most CISOs aren’t hesitant about AI because they doubt it can move fast enough. Speed was never really the concern, but trust is. It’s likely they’re asking:

Who’s accountable when an autonomous system gets it wrong?

What does the audit trail look like after the fact?

How much authority should a system have on day one, and how does that change over time?

These questions have less to do with the underlying technology than with how an organization chooses to govern it.

(When Attacks Move in Seconds: How CIOs Build Trust with Automated Response is a good read from Gareth Lindhal-Wise)

The answer isn’t to pull humans out of the loop entirely, and it isn’t to keep them wedged into every single step either. The answer is to redesign the process itself, so that machines can make and execute the decisions that fall within clearly defined guardrails, while humans retain full responsibility for setting those guardrails and adjusting them as confidence grows.

How much autonomy a system gets should track directly with an organization’s risk tolerance, its operational maturity, and the confidence it has earned over time. That confidence doesn’t arrive all at once, but builds incrementally, decision by decision, the same way trust in any new capability is built.

A New Metric for a New Era

Security leaders need to rethink what they’re measuring. If a breakout happens in 22 seconds, traditional detection metrics and standards start to lose their connection to what matters.

Detecting something faster doesn’t automatically make an organization more resilient, and MTTD starts to matter less and less when human defender decision-making can’t keep pace with how fast attackers execute.

The future of SecOps won’t be defined by who fires off the most or fastest alerts. It will be defined by who can scale judgement, decision-making, and response at machine speed while keeping accountability in human hands.

In a world where breakout takes seconds, detection was never really the race. Decision-making is.

Sharing
Keywords