The world of cybersecurity is undergoing a rapid transformation, driven by the accelerating pace of cyber-attacks. In the past, cybercriminals would spend weeks or months inside a compromised network, carefully laying the groundwork for their malicious activities. But today, the situation has changed dramatically. Attackers can now move from initial entry to data exfiltration in a matter of minutes, posing a significant challenge to enterprise cybersecurity strategies.
According to the CrowdStrike Global Threat Report 2026, the average breakout time for an intrusion during 2025 was a startling 29 minutes. This rapid decline in breakout time is a cause for concern, as it means that cybercriminals are becoming increasingly efficient and elusive. In 2024, the average breakout time was 48 minutes, and in 2023, it was over an hour. The trend is clear: cybercriminals are getting faster, and this acceleration is set to continue.
One of the most alarming aspects of this trend is the use of compromised credentials by cybercriminals. Instead of traditional hacking methods, attackers are now logging in using legitimate corporate usernames and passwords, especially in organizations that rely on cloud services. This approach, known as 'logging in rather than hacking in,' is becoming increasingly prevalent. Adam Meyers, head of counter adversary operations at CrowdStrike, highlights the shift: 'They are increasingly using compromised identities, logging in and going across into SaaS and cloud.'
These incidents often involve cybercriminals gaining access by using stolen credentials, which they obtain through phishing attacks, underground forums, or brute force attacks. Once logged in, attackers can swiftly move across cloud applications and exfiltrate data, as the activity appears legitimate. Meyers explains, 'These are lightweight attacks and fast to implement. Once you are logged in, there is very little stopping you as a legitimate user.'
The rise of attackers compromising legitimate accounts has made it harder for defenders to detect potential malicious activity using traditional security and identity management tools. The focus has shifted from verifying user accounts to examining the context of user activity. Gabrielle Hempel, security operations strategist at Exabeam, emphasizes the importance of behavioral analytics, stating, 'We have business context, user behavior history, and knowledge of the environment, which we can tie together for the context of what's happening.'
The impact of artificial intelligence on cyber-attacks cannot be overstated. AI is enabling cybercriminals to exploit weaknesses within organizations at an unprecedented speed. Information security teams are now using agentic AI to identify cybersecurity vulnerabilities, but this has led to a challenging situation. Rapid patching of security bugs has become difficult to manage, and malicious hackers are already exploiting this vulnerability.
Hempel highlights the acceleration of zero-day exploitation, where attackers can now identify and exploit new vulnerabilities within days, rather than months. This has created a race against time for defenders, who must now adopt strategies for rapid patching to avoid falling victim to the ever-increasing stream of security vulnerabilities. The AI era has indeed shrunk the timeline for patching and mitigating security issues.
The response to suspicious activity is a critical aspect of cybersecurity. James Ellison OBE, director of national resilience at the UK National Cyber Security Centre (NCSC), emphasizes the importance of exercises in preparing for cyber incidents. He states, 'The biggest discriminator between an organization that copes well with an attack and one that doesn’t is exercise.' Cybersecurity fundamentals, such as understanding network assets and the threat landscape, are vital for organizational resilience.
In conclusion, the rapid pace of cyber-attacks is reshaping enterprise cybersecurity strategies. Defenders must adapt to the evolving threat landscape, focusing on behavioral analytics, context-based detection, and rapid response plans. The race for cybersecurity is a constant battle, and speed is of the essence in preventing and mitigating cyber-attacks. As cybercriminals continue to innovate, organizations must stay one step ahead, ensuring they are prepared for the challenges that lie ahead.