Product1 publisher3 min readPublished
The 500-plus engagements behind that share are all companies that already needed an outside responder, so the figure describes how fast a bad day closes rather than your odds of having one. It still decides which of your controls can fire in time.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
An on-call analyst gets paged, opens the console, and reaches the part of the runbook that involves other people: a bridge line, an approval to disable a service account, a call to whoever owns the affected system. In nearly one in five of the cases Unit 42 worked in 2024, the data had already left inside the first hour of compromise [4]. Every one of those steps has to fit inside that window, or it is documentation rather than response.
Multiply it out. Unit 42 responded to more than 500 major attacks last year [1], so nearly one in five puts roughly 100 engagements in the group where exfiltration beat the first status update [12]. The other four fifths left more room. That split, not the headline percentage, is the thing a detection budget is actually being asked to choose between.
What teams tell themselves is that faster alerting buys down the whole curve. The report's own diagnosis is duller than that: it names complexity, gaps in visibility and excessive trust as the three enablers, with fragmented architectures, unmanaged assets and overly permissive accounts as the space attackers work in [9]. Seventy percent of the incidents ran on three or more fronts [6] and 86 percent produced business disruption [3]; if both shares come from the same set of engagements, at least 56 percent did both, since 86 plus 70 minus 100 leaves 56 [13]. A plan that treats endpoint, cloud and identity as separate queues with separate owners is being asked to work in the case where all of them are live at once. Forty-four percent of the incidents involved a web browser, including phishing and malware downloads [7], while one campaign scanned more than 230 million unique targets looking for sensitive data [8]. The funnel in front of you is automated and wide; the door is often a tab somebody in finance has open.
Read the denominator before this goes into a budget meeting. Palo Alto Networks is publishing its own responders' casework [14]: over 500 major attacks at large organizations dealing with extortion, network intrusions, data theft and advanced persistent threats [16], across 38 countries [2]. Firms enter that set because they already needed outside help, which makes it a good measure of how bad days go and a poor one of how often they arrive. The fifth trend, AI-assisted attacks, is offered as early observations with no figure attached at all [11], which is precisely the one most likely to survive into a slide. The remedies read as direction rather than a bill of materials: Zero Trust, securing applications and cloud from development to runtime, consolidated logs across on-premises, cloud and endpoint, and automation-driven detection and remediation [10].
The usable version is a table. For each of your three most exfiltration-worthy data stores, sort every control that would stop the theft into one of three columns: already on, fires without a human, needs a human to approve. Anything in the third column is out of play for the fast fifth. Then name which slice you are buying down, because cutting mean time to detect from days to hours does nothing for a 60-minute exfiltration, and pre-authorising containment that fires on its own is a governance argument with a security budget attached to it.
Ranked by verification strength, evidence, and original report placement.
In 2024, Unit 42 responded to over 500 major cyberattacks.
The targets of those attacks spanned all major industry verticals and 38 countries.
In 2024, 86% of incidents Unit 42 responded to involved business disruption, spanning operational downtime, reputational damage or both.
In nearly one in five cases, data exfiltration took place within the first hour of compromise.
70% of the incidents Unit 42 responded to happened on three or more fronts, across endpoints, networks, cloud environments and the human factor.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-hand casework that outsiders cannot verify
Every number in this story comes from one place, the case logs of Palo Alto Networks' own responders, published by Palo Alto Networks. The access is as direct as security data gets, since those responders were inside the affected environments, and the verification is absent, because nobody outside the firm can re-examine the cases. The report also keeps its mechanics to itself: what counted as a 'major' attack, how the 500-plus engagements fed each percentage, and whether the 86% and 70% shares run over the same base.
Incidents tallied, adoption unmeasured
The report tallies incidents, not uptake. There is no figure for how many organizations moved toward Zero Trust, consolidated their logs or shortened time to detection, and the 500-plus engagements measure demand for emergency help rather than deployment of anything. Nothing in this reporting supports a number here.
The speed figure travels further than its sample
The numbers are precise and the framing stretches them. 'Nearly one in five' first-hour exfiltrations is a property of engagements that had already escalated to an outside call, a limit the report acknowledges in its introduction and then drops when the executive summary presents the same share as the time defenders have. The widest part of the gap is the fifth trend: AI-assisted attacks are asserted with no count of any kind while sitting beside four trends that each lead with one.
The diagnosis matches the catalogue
Complexity, visibility gaps and excessive trust are the three conditions the report blames, and Zero Trust, dev-to-runtime cloud and application security, and consolidated security operations with automation are the three things it tells leaders to invest in. Palo Alto Networks sells all three, and it also sells the post-incident posture work described in the same section. Vendor casework is frequently the only casework anyone publishes, so the incentive does not void the data; it does explain which findings won the executive summary, and why 'fragmented security architectures' does double duty as a diagnosis and a consolidation pitch.
Concrete figures, unverifiable method
The individual numbers are worth citing because they are concrete and first-hand: 500-plus engagements, 38 countries, 44% browser involvement, one campaign scanning 230 million targets. What holds confidence down is that none of it can be re-derived -- no methodology is released, and the whole set contains a single year-over-year comparison, the tripling of North Korea-linked insider cases. The report itself can be cited reliably, but the measurement behind it resists any outside test.
science
Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours2 publishers
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 publisher
product
Cloudflare turns OpenAI's cyber model into WAF rules that wait on human approval1 publisher
security
AI agents ran more than 50 ATT&CK techniques through one enterprise in under 10 hours2 publishers
Publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026