TL;DR: Ransomware dwell time is the interval that determines how far attackers can move, what they can steal, and whether backups survive, according to Sprocket Security's analysis. Shorter detection windows materially reduce blast radius, because the encryption event is usually the last step in a campaign already underway for days or weeks.
NHIMG editorial — based on content published by Sprocket Security: Dwell time, not initial access, determines ransomware blast radius
By the numbers:
- The median dwell time for ransomware attacks tracked by Sophos in 2024 was 16 days.
- The median detection time across all intrusion types in Mandiant M-Trends 2024 was 10 days.
- IBM reported that organisations with high levels of security AI and automation detected breaches 100 days faster.
Questions worth separating out
Q: How should security teams reduce ransomware blast radius after initial access?
A: Focus on privileged access first.
Q: Why do stolen credentials make ransomware outbreaks harder to contain?
A: Stolen credentials matter because they turn the attacker into a valid user, which often bypasses basic trust checks.
Q: Where do ransomware programmes most often fail operationally?
A: They fail when teams assume prevention alone is enough and do not measure how long an attacker could stay hidden.
Practitioner guidance
- Measure exposure age, not just exposure count Track how long critical internet-facing assets, exposed credentials, and privileged paths remain discoverable before remediation.
- Tie identity telemetry to abnormal movement Correlate authentication events with post-login behaviour such as administrative tooling, unusual backup access, and lateral movement.
- Isolate backup administration from domain privilege Remove backup management from broad admin roles and require separate authorisation paths for recovery infrastructure.
What's in the full article
Sprocket Security's full analysis covers the operational detail this post intentionally leaves for the source:
- Breakdown of the continuous penetration testing workflow used to validate new exposures as they appear.
- The vendor's view of how attack-surface monitoring changes the window between compromise and detection.
- Examples of the exposure categories that most often create dwell-time risk in external environments.
- The full argument linking remediation speed, blast radius, and ransomware economics.
👉 Read Sprocket Security's analysis of dwell time and ransomware blast radius →
Dwell time and ransomware blast radius: what should teams measure now?
Explore further
Standing credential exposure windows are the real ransomware control gap. The article correctly shifts attention from the moment of encryption to the period when attackers operate invisibly. In practice, the failure is often not missing tools but delayed recognition that a credential, service account, or remote access path has already been abused. That maps directly to NHI governance, where standing privilege and weak lifecycle control create an attacker runway. Organisations should treat credential visibility and exposure duration as first-order risk metrics.
A question worth separating out:
Q: Who should own containment when ransomware access is detected?
A: Ownership should sit with the teams that control identity, privileged access, endpoint containment, and recovery infrastructure together. If those functions act separately, attackers can move faster than the response. Accountability needs a single incident path that can revoke access, isolate hosts, and protect backups before the campaign reaches its end state.
👉 Read our full editorial: Dwell time, not initial access, determines ransomware blast radius