Articles

Threat Speed Does Not Remove the Need for Evidence

When adversaries move faster, security teams need faster detection, decisions and response. They do not need lower standards for claiming success.

Threat-informed articleDocument v3.12 min read

When adversaries move faster, security teams need faster detection, decisions and response. They do not need lower standards for claiming success.

CrowdStrike's 2026 Global Threat Report describes a 29-minute average eCrime breakout time in its observed 2025 data, an 89% year-over-year increase in attacks by AI-enabled adversaries, and 82% malware-free detections. Those figures come from CrowdStrike's telemetry and analytic definitions. They are valuable threat intelligence, not universal population statistics.

The accepted operational response

NIST CSF 2.0's Detect, Respond and Recover outcomes, incident-response guidance, continuous monitoring and threat-informed defence all support shorter feedback loops. Automation is a reasonable response where delay has material cost.

The IO position

Speed changes the window, not the evidence rule.

  • A rapid containment can be operationally correct before a complete baseline exists.
  • The first reliable observation can establish the baseline for subsequent work.
  • The emergency action is not retrospectively called Verified merely because it was necessary or because the incident ended.
  • Confidence, source gaps and incomplete populations remain visible.

This protects responders from a perverse choice between acting quickly and maintaining honest measurement. They can act immediately; the record simply states what the available evidence can and cannot prove.

Trusted pathways need behavioural measures

The report's emphasis on valid credentials, SaaS integrations, cloud trust and software supply chains matters because many traditional indicators test whether an action is authorised, not whether it is expected. A valid identity is a fact about authentication. It is not proof of benign intent.

IO therefore favours measures such as:

  • time from anomalous trusted activity to triage and containment;
  • privileged actions outside established behavioural or workflow context;
  • service-account and agent actions outside declared purpose;
  • unexpected data movement through approved SaaS; and
  • recurrence after the intervention window.

What not to claim

Do not say an intervention prevented a breach because no breach was observed. Do not extrapolate vendor telemetry to every organisation without qualification. Do not convert faster closure into lower risk without measuring the condition the action was intended to change.

References

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.