Published · 3d agoSecurity3 min read
A 22-second handoff makes the triage queue the vulnerability, not the headcount
Arctic Wolf says compromised access now changes hands in 22 seconds, down from eight hours in 2022. The figure is unsourced in the post, but if it holds, the argument moves from hiring to delegation.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Arctic Wolf states the median time for one attacker to hand freshly compromised access to the next team in the chain, the group that drives toward ransomware, was 22 seconds in 2025, compared with more than eight hours in 2022.
- In the published text, the 22-second and eight-hour handoff figures are presented without attribution to any named report, while other statistics in the same post are attributed to CrowdStrike, IBM, Microsoft/Omdia and ISC2.
- CrowdStrike's 2026 Global Threat Report, as cited by Arctic Wolf, found average eCrime breakout time, the span for an adversary to move laterally from a first compromised host, has fallen to 29 minutes, with activity from AI-enabled adversaries up 89% year over year.
- IBM's 2026 X-Force Threat Index, as cited by Arctic Wolf, found vulnerability exploitation is now the leading cause of the incidents it observed.
- Arctic Wolf's 2026 Threat Report says ransomware, business email compromise and data incidents accounted for 92% of its incident response engagements last year, with data-only extortion incidents surging 11x year over year.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Arctic Wolf has published an argument that the tiered security operations centre is not understaffed but structurally obsolete, and it rests on one number: the median time for an attacker to hand freshly compromised access to the next crew in the chain, the one that drives toward ransomware, is now 22 seconds, against more than eight hours in 2022 [1]. That is a compression of roughly 1,300 times [1], and if it is real it moves the operating question off roster size and onto which containment decisions you are willing to let software make without a human in the loop.
Start with the provenance, because the load-bearing figure is the weakest cited one. The post attributes its other statistics to CrowdStrike, IBM, Microsoft/Omdia and ISC2, but the 22-second and eight-hour handoff numbers appear with no named source [2]. The company making the diagnosis also sells the prescription: its conclusion is that bolting AI onto the tiered model will not work and the operating model itself must be replaced with an agentic SOC [10].
The supporting numbers are more traceable. CrowdStrike's 2026 Global Threat Report, as cited, puts average eCrime breakout time at 29 minutes with AI-enabled adversary activity up 89 percent year over year [3]. That means the whole distance from brokered handoff to lateral movement is about 79 handoff intervals wide [3] and fits inside half an hour. Microsoft/Omdia's State of the SOC 2026 reports 46 percent of alerts are false positives and 42 percent are never investigated at all [7], which leaves 58 percent examined [2]. ISC2's late-2025 research found 59 percent of practitioners reporting critical skill gaps, a 15-point jump in one year [8]. Nobody hires their way out of that.
The structural claim is the one worth taking seriously: Tier 1 triage, Tier 2 investigation and Tier 3 hunting move work sequentially, and each queue adds delay while each handoff sheds context [9]. A sequential process cannot win a race against a parallel one, whatever the queue depth.
So the practical work is not buying an agentic label. It is writing down, per action, what automation may do unattended, and what it must ask for. Sort candidate actions by blast radius and reversibility. Killing a remote access session, revoking a token, quarantining a message and isolating a single host are cheap to undo and cheap to be wrong about. Fleet-wide egress blocks, mass credential resets and disabling service accounts are not. That triage matters because unattended action inherits the alert quality it fires on, and the cited false positive rate is 46 percent [7].
There is a useful hint on where the delegated authority earns its keep: 65 percent of non-BEC intrusions in Arctic Wolf's own 2026 threat data involved abuse of remote access technologies such as RDP, VPN and RMM tools [6], and ransomware, BEC and data incidents made up 92 percent of its incident response engagements, with data-only extortion up 11 times year over year [5]. Cutting remote sessions is both the highest-frequency intervention and one of the more reversible ones.
Watch for three things: whether anyone publishes the methodology behind the 22-second claim; whether agentic products expose a per-action authority list with rollback and an audit trail, or just faster ticket summaries, which the post itself calls a trap [11]; and whether the 42 percent never-investigated figure [7] moves, since that is the only honest measure of whether the automation absorbed work rather than relabelled it.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Arctic Wolf states the median time for one attacker to hand freshly compromised access to the next team in the chain, the group that drives toward ransomware, was 22 seconds in 2025, compared with more than eight hours in 2022.
- [2]
In the published text, the 22-second and eight-hour handoff figures are presented without attribution to any named report, while other statistics in the same post are attributed to CrowdStrike, IBM, Microsoft/Omdia and ISC2.
ReportedView cited source - [3]
CrowdStrike's 2026 Global Threat Report, as cited by Arctic Wolf, found average eCrime breakout time, the span for an adversary to move laterally from a first compromised host, has fallen to 29 minutes, with activity from AI-enabled adversaries up 89% year over year.
- [4]
IBM's 2026 X-Force Threat Index, as cited by Arctic Wolf, found vulnerability exploitation is now the leading cause of the incidents it observed.
- [5]
Arctic Wolf's 2026 Threat Report says ransomware, business email compromise and data incidents accounted for 92% of its incident response engagements last year, with data-only extortion incidents surging 11x year over year.
- [6]
Arctic Wolf's 2026 Threat Report says 65% of non-BEC intrusions involved abuse of remote access technologies such as RDP, VPN and RMM tools.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- arcticwolf.comArctic Wolf5d agoThe Tiered SOC Is Breaking: Why the Agentic SOC Is the Only Model Built for Machine-Speed Attacks
- arcticwolf.comArctic Wolf5d agoThe Tiered SOC Is Breaking: Why the Agentic SOC Is the Only Model Built for Machine-Speed Attacks
Additional citations
- Arctic Wolf blog post
- CrowdStrike 2026 Global Threat Report, cited by Arctic Wolf



