Why Nostr? What is Njump?
2025-04-24 06:22:24
in reply to

Kevin Beaumont on Nostr: Dwell time - the time between initial access to incident response (ie notification or ...

Dwell time - the time between initial access to incident response (ie notification or detection) rose slightly YoY. Attackers typically in environment for 11 days.

Do not believe the headlines around ‘ransomware deployed in 1 hour using AI!!!1!’ - every single incident response org data shows you usually have a week for detection and response before ransomware deployment. You can detect and respond - do it, don’t buy the magic cyber beans.

Author Public Key
npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw