Site navigation

Cyber-attack ‘Breakout Time’ Now Less Than 30 Minutes

Tom Quinn

,

cyber-attack tactics
“Attackers are moving faster than ever, which means our defences must speed up as well,” said Michael McPherson, ReliaQuest.

Cyber-attackers are moving faster than ever, with lateral movement taking as little as twenty-seven minutes once inside networks, according to a new report from ReliaQuest.

The cybersecurity firm’s latest Annual Threat Report found that once attackers have a foot in the door, their path forward is clear, with the time to lateral movement, or ‘breakout time’, averaging just forty-eight minutes.

According to the report, remote desktop protocol (RDP) was the main cyber-attack tactic used for lateral movement last year, accounting for 26% of observed incidents. Once inside an IT environment and armed with stolen credentials, this offers attackers the most straightforward way of connecting to other internal systems.

Another cyber-attack tactic on the rise is internal spearphishing accounting for 16% of lateral movement, doubling in frequency from 2023 to 2024, likely due to the 200% increase in phishing kits on the dark web over the same period.

By moving faster, threat actors are giving defenders little time to react, a tactic that goes beyond initial access. 

ReliQuest found that those engaged in ransomware activities are now forsaking encryption in the name of speed, with just 20% of these breaches including encryption despite 80% involving data exfiltration.

The firm claims that this method is 34% faster for attackers, with the quickest exfiltration time of 2024 clocking in at just 4 hours and 29 minutes, compared to 6 hours for the fastest encryption.

After exfiltration, the majority of attackers (60%) went on to send the stolen data to cloud storage platforms, quickly uploading reams of data disguised among legitimate traffic, however given the potential for disruption that blocking access to these widely used cloud platforms could cause, ReliaQuest notes that this isn’t a viable solution for defenders.


Recommended reading


“Time is the enemy in cybersecurity,” said Michael McPherson, senior vice president of technical operations at ReliaQuest.

“Attackers are moving faster than ever, which means our defences must speed up as well.

“Manual responses are no longer sufficient to stop today’s threats. We have to take advantage of automation and AI to stay ahead. Agentic AI is now taking this even further and is capable of processing security alerts 20x faster than traditional methods with 30% greater accuracy at identifying true threats to the business.”

To increase their chances against swift-moving attackers, ReliaQuest’s report recommends that security teams continue to incorporate AI and automation into security operations that can autonomously handle alerts end-to-end, as well as barricade common entry points, including public-facing assets and internet-facing external remote services.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data