Skip to main content
Category: Security Operations & Detection

Dwell Time

Also known as: Attacker Dwell Time, Adversary Dwell Time
Simply put

In cybersecurity, dwell time is the length of time a malicious actor has access to a compromised system before the intrusion is detected. In simple terms, it measures how long an attacker goes unnoticed inside an environment. Shorter dwell time generally reflects stronger detection capabilities, since the attacker has less opportunity to cause harm before being discovered.

Formal definition

Dwell time typically denotes the interval between an attacker's initial compromise of a system or environment and the point at which the threat is detected. The evidence provided defines it as the amount of time a malicious actor has access to a compromised system before a threat is detected. Note that dwell time is also used outside cybersecurity in fields such as retail, transportation, logistics, out-of-home advertising, and SEO, where it refers to the duration a person, vehicle, or visitor spends in a location, viewing content, or on a page; these usages should not be conflated with the security meaning. Because the evidence packet does not specify accepted start and end points beyond compromise-to-detection or enumerate common variants, practitioners should confirm the precise measurement boundaries used by a given source or vendor rather than assuming a single industry-standard definition.

Why it matters

Dwell time is one of the most telling indicators of how effective an organization's detection capabilities really are. As the evidence describes, it measures how long a malicious actor has access to a compromised system before a threat is detected. The longer an attacker remains undetected, the more opportunity they have to move laterally, escalate privileges, exfiltrate data, or establish persistence. A short dwell time generally reflects stronger detection, while a long dwell time suggests gaps in monitoring, logging, or alerting that allow an intrusion to go unnoticed.

From a security leadership perspective, dwell time is useful precisely because it reframes security as a question of detection speed rather than prevention alone. No control set eliminates the possibility of compromise, so the practical question becomes how quickly an intrusion is discovered once it occurs. Tracking dwell time over time can help leaders assess whether investments in detection and response are improving outcomes, and it provides a business-relevant way to discuss risk with executives and boards who may not engage with more technical metrics.

Because the term is used differently across industries, care is warranted when interpreting figures. As the evidence shows, dwell time also refers to how long a person spends in a retail location, how long a shipping vehicle sits at a facility, how long someone views an out-of-home ad, or how long a visitor stays on a webpage before returning to search results. These usages should not be conflated with the cybersecurity meaning. Practitioners should also confirm the exact measurement boundaries a given source or vendor uses, since the evidence does not establish a single industry-standard definition beyond the compromise-to-detection interval.

Who it's relevant to

Virtual and Fractional CISOs
For a virtual or fractional CISO advising on security strategy and governance, dwell time offers a way to evaluate the maturity of a client's detection and response capabilities and to prioritize improvements. It is an advisory and program-level metric: the vCISO can help define how it is measured, set targets, and interpret trends, while accountability for acting on the underlying risk remains with the client organization. Note that a vCISO typically does not perform the hands-on monitoring or forensic work needed to measure dwell time directly unless that is explicitly contracted; those activities usually fall to internal teams or a specialized provider.
Security and Detection Teams
Teams responsible for monitoring, logging, and alerting are most directly affected by dwell time, since reducing it depends on their detection coverage and the quality of their telemetry. Reconstructing the initial compromise point and confirming detection are operational tasks that determine whether the metric can even be measured reliably.
Executives and Boards
Dwell time gives organizational leaders a business-oriented way to understand security posture without requiring deep technical knowledge, framing risk in terms of how quickly intrusions are caught. Because legal and organizational accountability for security decisions generally rests with the client organization and its officers, executives benefit from tracking this metric as part of their oversight responsibilities.
Managed Service and Detection Providers
As the evidence notes in a managed service context, dwell time can be measured relative to when a provider detects a threat. Buyers should not assume a virtual CISO engagement is the same as a managed detection service; a vCISO provides leadership and direction, whereas the continuous monitoring that shortens dwell time is typically delivered by a distinct operational provider. Value in either case depends on defined scope, access to systems and stakeholders, and consistent measurement boundaries.

Inside Dwell Time

Plain-language definition
Dwell time is the interval between when an attacker first compromises an environment and when that compromise is detected. In simple terms, it measures how long an intruder goes unnoticed inside a network before defenders become aware of the activity.
Technical definition and measurement boundaries
Technically, dwell time is measured from the estimated point of initial compromise (the earliest evidence of adversary presence, often reconstructed during forensic investigation) to the point of detection or identification of the incident. Because the true start point is frequently established only retrospectively, the measured value depends on the fidelity of forensic timeline reconstruction and may vary by how an organization defines each endpoint.
Common variants and related metrics
Dwell time is sometimes decomposed into or discussed alongside related detection metrics. One common variant frames dwell time as the sum of time-to-detect and time-to-contain, while stricter usage limits it to compromise-to-detection only. It is also frequently compared with mean time to detect (MTTD) and mean time to respond (MTTR). Definitions and start/end points can differ between providers and reporting sources, so the specific interpretation should be confirmed in any given engagement.
Relationship to detection and response programs
Dwell time serves as an outcome indicator for the effectiveness of an organization's detection, logging, monitoring, and threat-hunting capabilities. Shorter dwell times generally reflect stronger visibility and faster identification, though the metric reflects program maturity rather than guaranteeing any particular security outcome.
Role of a virtual CISO relative to dwell time
In a vCISO engagement, dwell time is typically treated as a governance and risk metric the advisor helps define, benchmark, and drive down through strategy, program design, and prioritization. Reducing measured dwell time usually depends on operational execution such as SOC monitoring, log management, and incident response, which are generally out of scope for a vCISO unless explicitly contracted, and accountability for acting on detections remains with the client organization.

Common questions

Answers to the questions practitioners most commonly ask about Dwell Time.

Does a low dwell time mean my organization is well protected against breaches?
Not necessarily. Dwell time measures the interval between an attacker's initial compromise and the moment the intrusion is detected. A low figure indicates faster detection, but it does not, on its own, prove strong protection. An organization could report a short dwell time simply because it experienced a noisy attack that was easy to spot, or because it detects only certain categories of incidents while missing quieter ones. Dwell time also says nothing about how quickly an incident is contained or remediated after detection, nor about the damage done before detection occurred. A virtual CISO would typically treat dwell time as one indicator within a broader detection and response program rather than as a standalone measure of security posture, and would caution that a favorable number can create false confidence if underlying detection coverage is incomplete.
Is dwell time just another name for how long it takes to respond to or fix an incident?
No, and conflating these is a common mistake. Dwell time typically refers specifically to the compromise-to-detection interval, meaning the time an adversary remains present and undetected in an environment. It generally ends at the point of detection, not at containment or full remediation. Related but distinct metrics cover what happens after detection, such as mean time to respond and mean time to contain. Treating them as interchangeable can obscure where a program is actually weak. An organization might detect intrusions quickly yet respond slowly, or vice versa. In many engagements a virtual CISO will help distinguish these measures so that improvement efforts target the correct phase of the detection and response lifecycle.
Where exactly should we mark the start and end points when we measure dwell time?
In its common technical definition, dwell time starts at the earliest evidence of compromise, often the initial point at which an attacker gained a foothold in the environment, and ends at the point of detection. In practice the precise start point is frequently established retrospectively through forensic investigation, because the true moment of initial access may not be known until after an incident is analyzed. Variants exist across providers and reports, so it is important to document your chosen definition. Some measure from initial compromise to detection, while others may frame the interval differently. Because organizations may define these boundaries inconsistently, a virtual CISO would typically recommend recording your measurement convention explicitly so that figures remain comparable over time and are not misread by stakeholders.
What data sources and capabilities do we need in place to measure dwell time reliably?
Reliable dwell time measurement generally depends on having sufficient telemetry and log retention to reconstruct when a compromise actually began, along with detection capabilities that record when an intrusion was first identified. Without adequate logging, historical visibility, and forensic capability, the start point may be unknowable, which can make reported dwell time misleading or incomplete. The metric's value therefore depends heavily on organizational maturity and instrumentation. A virtual CISO advises on strategy and governance around such measurement but typically does not perform the hands-on SOC monitoring, tool administration, or forensic investigation required to generate the data, unless those activities are explicitly contracted. Accountability for maintaining the necessary detection and logging capabilities remains with the client organization.
How can a virtual CISO help us use dwell time as part of our security program?
A virtual CISO typically helps at the strategy, governance, and program level rather than through operational execution. This can include helping define how dwell time is measured and reported, situating it alongside related detection and response metrics, and interpreting trends for executive and board audiences in business risk terms. A vCISO may also help prioritize investments intended to reduce the interval, such as improving detection coverage or log retention, and set realistic expectations about what the metric does and does not demonstrate. Actual monitoring, tuning of detection tooling, and incident response execution are generally out of scope for a vCISO engagement unless specifically agreed. The value of this guidance depends on client cooperation, defined scope, and access to relevant stakeholders and data.
What limitations should we keep in mind when reporting dwell time to leadership?
Several limitations warrant caution. Dwell time can only be calculated for incidents that are eventually detected, so undetected compromises are excluded, which can bias the picture. The measured interval often relies on retrospective forensic determination of the compromise start point, which may carry uncertainty. Definitions and start and end points can vary by provider and report, so comparisons across sources may not be like-for-like. The metric also does not capture post-detection response speed or the impact of an incident. Because of these factors, a virtual CISO would typically advise presenting dwell time with clear context about its scope, measurement method, and what it excludes, so leadership does not overinterpret a single number or treat it as a guarantee of breach prevention.

Common misconceptions

Dwell time has a single, universally agreed definition and measurement method.
Start and end points vary by source and provider. Some measure compromise-to-detection only, while others include containment time. The initial compromise point is often reconstructed retrospectively through forensics, so reported figures depend on definitions, evidence quality, and methodology and should not be compared across sources without confirming how each was calculated.
Hiring a virtual CISO will directly reduce dwell time.
A vCISO advises on strategy, governance, and program development but generally does not perform hands-on detection, monitoring, or incident response unless explicitly contracted. Reducing dwell time depends on operational capabilities and client execution. The vCISO can help define, target, and prioritize improvements, but the measurable reduction results from the organization's tooling, staffing, and cooperation.
A low dwell time means an organization is safe from breaches.
Dwell time measures how quickly a compromise is detected, not whether compromise can be prevented. It is an outcome indicator of detection and response maturity and does not guarantee breach prevention. It should be interpreted alongside other risk and program metrics rather than treated as a standalone measure of security.

Best practices

Define and document your organization's specific start and end points for dwell time (for example, compromise-to-detection versus detection-plus-containment) before measuring or benchmarking, so figures are comparable over time.
Track dwell time alongside related metrics such as MTTD and MTTR rather than in isolation, and interpret it as an indicator of detection and response maturity rather than proof of prevention.
Clarify in the engagement scope whether the vCISO is advising on dwell-time strategy only or whether operational detection, monitoring, and response activities that actually reduce it are included or contracted separately.
Invest in logging, visibility, and retention that make accurate forensic timeline reconstruction possible, since the reliability of any dwell-time figure depends on the quality of available evidence.
Confirm the methodology behind any external or benchmark dwell-time figures before using them for comparison, as definitions and measurement approaches differ across providers and sources.
Assign clear responsibility for acting on detections within the client organization, recognizing that a vCISO advises and directs while operational and organizational accountability for reducing dwell time remains with the client.