Most security teams know that dwell time matters. The harder question is what to do about it.
Dwell time is the period between an attacker gaining access and the security team containing the threat. During that window, a threat actor has time to learn the environment, steal credentials, move between systems, and reach sensitive data.
For years, security teams have tried to reduce this window by adding more detection tools. The problem is that more alerts do not necessarily mean faster detection. A recent industry incident response report puts the global median dwell time at 14 days, up from 11 the year before, quietly reversing a run of steady improvement that had held for close to a decade.
The better way to think about it is as an operational problem. Two numbers matter most. Mean time to detect (MTTD) tells you how quickly the team recognizes a real threat, while mean time to respond (MTTR) tells you how quickly the team investigates and contains it.
An AI native SIEM tool can compress both.
Why does dwell time stay high
Attackers rarely spend their entire time doing something obviously malicious. They may sign in with a real user's credentials, run tools already installed on the machine, or make small changes that look harmless when viewed separately.
A traditional detection tool might see each event without understanding the connection between them.
Consider a compromised account. The user signs in from an unusual location, and a few minutes later, the account connects to a server it rarely accesses. Then a process runs on that server, and another account is created.
One alert might not justify an investigation. Put the events together, and the picture changes. This is one reason dwell time grows. The evidence exists, but the security team has to find it across thousands of events and multiple systems.
Start with the two clocks you can control
If you want to reduce dwell time, break it into two operational clocks.
- MTTD measures how long it takes to recognize that something is wrong.
- MTTR measures how long it takes to investigate the threat and take action.
Suppose an attacker gets access at 1 a.m. The security team identifies the attack at 9 a.m. and contains it at noon. MTTD is eight hours. MTTR is another three. That gives the attacker roughly eleven hours to operate.
Now imagine better detection cuts MTTD to two hours, and faster investigation cuts MTTR to one hour. The exposure window drops from 11 hours to three.
That difference has economic value even if you cannot attach an exact dollar amount to every hour. Every hour removed is an hour in which the attacker cannot continue exploring systems, accessing additional accounts, or moving closer to critical data.
IBM's 2026 Cost of a Data Breach report shows how costly those delays can become. The average breach now costs $4.99 million globally, while organizations take an average of 247 days to identify and contain a breach. Breaches lasting more than 200 days cost an average of $5.65 million, compared with $4.32 million for those resolved sooner.
Our own research points to the operational consequences. The 2026 Kaseya Cybersecurity Outlook report found that about 40% of businesses experienced at least a full day of downtime following a security incident.
Once an incident starts affecting operations, time stops being just a metric. It becomes a business cost.
Where AI native SIEM changes the equation
Traditional SIEM helped security teams centralize logs and search large amounts of security data. But analysts still had to spend considerable time deciding which signals mattered and investigating what happened.
AI native SIEM changes that workflow.
The value is not simply adding AI to an existing SIEM interface. It comes from applying AI throughout detection and investigation so the system can help analysts make sense of activity faster.
That can reduce dwell time in a few practical ways.
- Connect related signals sooner. An unusual login, endpoint event and identity change may look weak separately. AI can help connect them into a sequence that deserves attention.
- Reduce investigation time. Analysts spend a lot of time gathering context. AI can help summarize activity and surface relevant evidence so the analyst starts with more of the story already assembled.
- Prioritize what deserves attention. Security teams cannot investigate every alert with the same urgency. Better context helps push activity with greater potential impact toward the front of the queue.
- Speed up routine response. When the evidence is strong enough, automated workflows can help isolate endpoints, disable accounts or start other approved response actions without waiting for every step to be performed manually.
There is already movement in this direction. Our Cybersecurity Outlook report found that 32% of businesses see value from AI in threat detection and anomaly identification. Looking ahead, 30% plan to use AI for automated response or remediation.
None of this removes the analyst from incident response. It gives the analyst a better starting point and less manual work between signal and decision.
Think about detection in hours saved
Security teams often struggle to explain the financial value of better detection. Trying to calculate the exact cost of one hour of attacker dwell time can create false precision. A ransomware incident and a compromised account do not carry the same cost.
A simpler model is more useful.
Start with your current MTTD and MTTR. Then look at where the time goes.
- If analysts spend two hours gathering context for an investigation, ask how much of that work can be automated.
- If important alerts wait four hours in a queue, ask whether better prioritization can move them up the queue.
- If containment takes an hour because several teams need to coordinate manually, ask which approved actions can happen automatically.
Then measure the time removed.
The economic argument follows naturally. Shorter investigations require fewer analyst hours. Faster containment reduces the period in which an attacker can cause additional damage. Earlier intervention can also prevent a relatively small incident from becoming a much larger one.
You do not need to claim that every hour is worth a specific dollar amount. You need to show that the organization is buying back attacker time.
Measure the gaps, not just the averages
There is one caution to keep in mind when using MTTD and MTTR.
Averages can hide the incidents that matter most.
A team might have a strong average MTTD because it detects hundreds of simple threats in minutes, while a handful of serious intrusions remain unnoticed for days.
Look beyond the headline metric. Ask how long high-severity incidents take to detect. Measure the time between the first useful signal and the moment an analyst begins investigating it. Track how much time analysts spend gathering context. Measure how long containment waits for a decision or manual action.
Those gaps tell you where dwell time is actually coming from.
They also give you a practical way to evaluate an AI-native SIEM. The question is not how many AI features the product has. The question is how much time it removes from the path between the first meaningful signal and containment.
Make dwell time the outcome
Security teams have spent years measuring alerts, events, and detection coverage. Those metrics have their place, but they do not tell you how quickly you can stop an attacker.
Dwell time does.
For security leaders evaluating an AI-native SIEM, this creates a useful test. Measure MTTD before deployment. Measure MTTR. Find the stages where analysts lose time. Then measure them again after changing the workflow.
Shrinking it, hour by hour, is one of the highest-value things a security team can work on this year.
Reducing dwell time is one way to build stronger cyber resilience. See how businesses are approaching AI, threat detection and response in the 2026 Kaseya Cybersecurity Outlook.
Author Bio: Austin O'Saben is a Product Marketing Manager at Kaseya focused on cybersecurity solutions for MSPs and small to mid-sized businesses. He helps translate complex security technologies, such as EDR, MDR, and cloud security into practical strategies that help IT providers better protect their customers. Austin works closely with product and security teams to educate the MSP community on emerging threats, best practices, and modern threat detection.
Austin O'Saben — Product Marketing Manager at Kaseya https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiihbE5qGKjcXudrOXSdY4lj8_xbj6ZVpP53pvhPmkG5dv_dqTbn-0h3-SWsWvnf2yJVpT3RVbA8coIYAS5vSRmnW235vr9lyuIDZRWXxU0aAYWaf8xAK1ybHGyhQh8cddYi-dMIIsGdEz8_hlmm_5xWZ8VpeuDPx0xcB2LAXaZCDMswR1c58csRoG3YyY/s1700-e365/Austin.png


