Campaign tempo is the speed at which adversaries move from reconnaissance to compromise, persistence, and impact. AI-supported automation increases tempo by reducing the time needed to research targets, create lures, and launch large-scale attacks.
Expanded Definition
Campaign tempo describes how quickly an adversary can progress through an attack lifecycle, from initial reconnaissance to compromise, persistence, and impact. In practice, it captures the pace of planning, adaptation, automation, and execution, not just the volume of activity. That distinction matters because a fast campaign may still be limited in scope, while a slower campaign can remain highly effective if it is stealthy and well resourced.
For security teams, campaign tempo is a useful way to think about operational pressure. AI-supported tooling can compress research, message generation, infrastructure setup, and target selection into a shorter window, which makes detection and response windows narrower. This is one reason the concept aligns well with the governance intent of the NIST Cybersecurity Framework 2.0, which emphasises preparation, detection, response, and recovery as connected capabilities rather than isolated tasks.
Definitions vary across vendors when campaign tempo is discussed in threat intelligence, incident response, or red team reporting. Some use it as a descriptive label for attack speed, while others treat it as an indicator of adversary maturity and automation. The most common misapplication is treating campaign tempo as simple event frequency, which occurs when teams count alerts or phishing emails without measuring how rapidly the attacker advances between phases.
Examples and Use Cases
Implementing campaign-tempo analysis rigorously often introduces classification and measurement overhead, requiring organisations to weigh better adversary visibility against the cost of tracing timelines across logs, detections, and case notes.
- A phishing operation uses generative AI to create targeted lures in minutes, then rapidly rotates domains and sender infrastructure after blocks are detected.
- An intruder scans for exposed services, authenticates with stolen secrets, and establishes persistence before the incident response team has finished triage.
- A ransomware affiliate compresses reconnaissance, privilege escalation, and lateral movement into a short dwell time, leaving fewer artifacts for defenders to correlate.
- An AI agent abused by an attacker automates repeated probe-and-adjust cycles, increasing the speed of testing prompts, payloads, or access paths.
- A security team measures the time between first malicious contact and containment to compare one campaign against another and prioritise control gaps.
For teams building analytic playbooks, campaign tempo is often paired with source enrichment from threat modelling and adversary behaviour references such as MITRE ATT&CK or operational reporting from incident response and threat intelligence partners. While ATT&CK is not a definition of the term itself, it helps teams map speed to observable attacker techniques and sequencing.
Why It Matters for Security Teams
Campaign tempo matters because faster adversaries compress decision time. When reconnaissance, delivery, exploitation, and post-compromise actions happen quickly, controls that depend on human review lose effectiveness unless they are tightly integrated with detection and response. This is especially relevant where identity controls are involved: stolen credentials, session hijacking, and abused secrets can turn a fast-moving campaign into a trusted-looking session before defenders notice.
Security leaders should treat tempo as a planning signal for alert routing, containment automation, and escalation thresholds. If the organisation cannot measure how fast attackers move, it will struggle to judge whether controls are reducing exposure or merely generating more telemetry. Tempo also helps explain why some compromises appear to “skip” traditional stages: the attacker used automation to advance faster than the monitoring chain could interpret. Practitioners tracking identity abuse, NHI misuse, or agentic AI exposure should also consult OWASP guidance where attack sequencing, secret misuse, and automation risks intersect with identity-bearing systems.
Organisations typically encounter the operational impact of campaign tempo only after a breach unfolds too quickly for manual triage, at which point the term becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM | NIST CSF addresses continuous monitoring needed to see attacker speed and progression. |
| NIST AI RMF | GV | AI RMF governance helps manage accelerated AI-enabled attack workflows. |
| OWASP Agentic AI Top 10 | OWASP Agentic AI guidance covers abuse of autonomous tooling that can raise campaign tempo. | |
| OWASP Non-Human Identity Top 10 | OWASP NHI guidance addresses secret misuse and identity abuse that often occurs in fast campaigns. | |
| NIST SP 800-63 | AAL | Digital identity assurance matters when fast campaigns exploit weak or stolen credentials. |
Instrument detection and monitoring so rapid campaign phases are identified before impact.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org