Breaches stay costly when teams cannot detect and contain them quickly enough. The article shows that containing a breach within 200 days saves money, while the average identify and contain time is 277 days. Long dwell time expands exposure, increases response effort, and raises the chance that regulators, customers, and operations all feel the impact.
Why Security Tools Do Not Eliminate Breach Cost
Security tools reduce exposure, but they do not automatically shorten the time between initial compromise and containment. Breach cost is driven by how long attackers can stay active, how much data they can reach, and how many teams must respond. When detection is slow, even strong preventive tooling leaves organisations paying for cleanup, investigation, downtime, and recovery.
The expensive part is often the delay between compromise and action, not the initial intrusion itself. That is why containment speed is a practical cost control, especially when stolen credentials, exposed secrets, or over-privileged accounts keep the attacker moving after the first alert.
What Actually Drives the Cost Curve
Long dwell time expands the incident from a single security event into an operational problem. More time in the environment usually means more systems touched, more logs to review, more legal and regulatory work, and more customer or business disruption. The cost rises because the organisation is forced to investigate a broader blast radius instead of a narrow event.
In the supplied guidance, the key timing signal is simple: containing a breach within 200 days saves money, while the average identify-and-contain time is 277 days. That gap matters because every extra day creates more opportunity for data theft, persistence, and secondary abuse.
Weak visibility is often the real failure mode. A tool may detect an event, but if teams cannot correlate identities, secrets, endpoints, cloud activity, and third-party access quickly enough, response becomes fragmented and expensive. The control problem is therefore not just buying more tooling, but improving the ability to interpret and act on what the tools reveal.
Risk and Threat Considerations
Breaches stay costly when attackers can maintain access long enough to escalate privilege, exfiltrate data, or reuse stolen access paths. The longer the dwell time, the more likely the incident shifts from a contained compromise to a wider operational and regulatory event.
Failure mechanism: Detection gaps, delayed triage, and incomplete containment let the attacker keep using valid access, hidden persistence, or lateral movement paths after the first compromise.
Impact: The organisation absorbs higher response labour, broader remediation, business interruption, and greater exposure to customer, regulatory, and reputational consequences.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RS.RP — Response Planning | Faster containment directly reduces breach duration and cost. |
| DE.CM — Continuous Monitoring | Detection speed is central to avoiding long dwell time and escalation. | |
| RS.CO — Communications | Coordinated response limits delay when containment decisions span teams. | |
| Recommendation — Set response playbooks to shorten time-to-containment and limit incident cost. Use continuous monitoring to surface compromise earlier and reduce dwell time. Coordinate response communications so containment actions are not delayed. | ||
| CIS Controls v8 | 8 — Audit Log Management | Log visibility is needed to reconstruct attack paths and contain faster. |
| 17 — Incident Response Management | Containment speed is the main cost lever in breach response. | |
| Recommendation — Centralise and retain logs to speed investigation and containment decisions. Practice incident response to reduce dwell time and recovery expense. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Stolen or exposed secrets can prolong attacker access and inflate breach cost. |
| NHI-03 — Privilege and Authorization | Excessive privilege increases blast radius when containment is slow. | |
| Recommendation — Rotate exposed secrets quickly and remove long-lived credentials. Reduce privilege so a delayed response cannot produce broad compromise. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Attackers often stay costly by reusing legitimate access after initial compromise. |
| Recommendation — Hunt and revoke abused valid accounts to end attacker persistence. | ||
Practitioner Guidance
What to prioritise: Measure the time from first suspicious signal to containment, not just the number of alerts or tools deployed. If investigation requires manual correlation across logs, identity systems, and cloud records, cost will remain high even when preventive controls look strong on paper.
What to verify: Confirm that the team can isolate the first compromised account, session, host, or API key quickly enough to stop continued access. In practice, organisations often discover that recovery speed depends on access governance and revoke capability more than on the original detection product.
Practitioner takeaway: Breach cost falls when containment becomes fast and decisive, because the expensive part of most incidents is the time attackers remain active, not the fact that a tool raised an alert.
Related resources from NHI Mgmt Group
- Why do employee data breaches keep happening even when organisations already run security awareness training?
- Why do organisations struggle to contain breaches quickly even when they have many security tools?
- Why do organisations struggle to reduce cloud data risk even when they already have data security tools in place?
- Why do organisations still struggle with cyber risk even after buying more security tools?