When adversaries move faster, security teams need faster detection, decisions and response. They do not need lower standards for claiming success.
CrowdStrike's 2026 Global Threat Report describes a 29-minute average eCrime breakout time in its observed 2025 data, an 89% year-over-year increase in attacks by AI-enabled adversaries, and 82% malware-free detections. Those figures come from CrowdStrike's telemetry and analytic definitions. They are valuable threat intelligence, not universal population statistics.
The accepted operational response
NIST CSF 2.0's Detect, Respond and Recover outcomes, incident-response guidance, continuous monitoring and threat-informed defence all support shorter feedback loops. Automation is a reasonable response where delay has material cost.
The IO position
Speed changes the window, not the evidence rule.
- A rapid containment can be operationally correct before a complete baseline exists.
- The first reliable observation can establish the baseline for subsequent work.
- The emergency action is not retrospectively called Verified merely because it was necessary or because the incident ended.
- Confidence, source gaps and incomplete populations remain visible.
This protects responders from a perverse choice between acting quickly and maintaining honest measurement. They can act immediately; the record simply states what the available evidence can and cannot prove.
Trusted pathways need behavioural measures
The report's emphasis on valid credentials, SaaS integrations, cloud trust and software supply chains matters because many traditional indicators test whether an action is authorised, not whether it is expected. A valid identity is a fact about authentication. It is not proof of benign intent.
IO therefore favours measures such as:
- time from anomalous trusted activity to triage and containment;
- privileged actions outside established behavioural or workflow context;
- service-account and agent actions outside declared purpose;
- unexpected data movement through approved SaaS; and
- recurrence after the intervention window.
What not to claim
Do not say an intervention prevented a breach because no breach was observed. Do not extrapolate vendor telemetry to every organisation without qualification. Do not convert faster closure into lower risk without measuring the condition the action was intended to change.
References
- CrowdStrike, 2026 Global Threat Report, supplied vendor threat-intelligence report
- NIST, Cybersecurity Framework 2.0 (opens in a new tab)
- NIST, Computer Security Incident Handling Guide (opens in a new tab)