Security1 distinct publisher3 min readPublished Updated
Arctic Wolf says compromised access now changes hands in 22 seconds, down from eight hours in 2022. The figure is unsourced in the post, but if it holds, the argument moves from hiring to delegation.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Arctic Wolf has published an argument that the tiered security operations centre is not understaffed but structurally obsolete, and it rests on one number: the median time for an attacker to hand freshly compromised access to the next crew in the chain, the one that drives toward ransomware, is now 22 seconds, against more than eight hours in 2022 [1]. That is a compression of roughly 1,300 times [1], and if it is real it moves the operating question off roster size and onto which containment decisions you are willing to let software make without a human in the loop.
Start with the provenance, because the load-bearing figure is the weakest cited one. The post attributes its other statistics to CrowdStrike, IBM, Microsoft/Omdia and ISC2, but the 22-second and eight-hour handoff numbers appear with no named source [2]. The company making the diagnosis also sells the prescription: its conclusion is that bolting AI onto the tiered model will not work and the operating model itself must be replaced with an agentic SOC [10].
The supporting numbers are more traceable. CrowdStrike's 2026 Global Threat Report, as cited, puts average eCrime breakout time at 29 minutes with AI-enabled adversary activity up 89 percent year over year [3]. That means the whole distance from brokered handoff to lateral movement is about 79 handoff intervals wide [3] and fits inside half an hour. Microsoft/Omdia's State of the SOC 2026 reports 46 percent of alerts are false positives and 42 percent are never investigated at all [7], which leaves 58 percent examined [2]. ISC2's late-2025 research found 59 percent of practitioners reporting critical skill gaps, a 15-point jump in one year [8]. Nobody hires their way out of that.
The structural claim is the one worth taking seriously: Tier 1 triage, Tier 2 investigation and Tier 3 hunting move work sequentially, and each queue adds delay while each handoff sheds context [9]. A sequential process cannot win a race against a parallel one, whatever the queue depth.
So the practical work is not buying an agentic label. It is writing down, per action, what automation may do unattended, and what it must ask for. Sort candidate actions by blast radius and reversibility. Killing a remote access session, revoking a token, quarantining a message and isolating a single host are cheap to undo and cheap to be wrong about. Fleet-wide egress blocks, mass credential resets and disabling service accounts are not. That triage matters because unattended action inherits the alert quality it fires on, and the cited false positive rate is 46 percent [7].
There is a useful hint on where the delegated authority earns its keep: 65 percent of non-BEC intrusions in Arctic Wolf's own 2026 threat data involved abuse of remote access technologies such as RDP, VPN and RMM tools [6], and ransomware, BEC and data incidents made up 92 percent of its incident response engagements, with data-only extortion up 11 times year over year [5]. Cutting remote sessions is both the highest-frequency intervention and one of the more reversible ones.
Watch for three things: whether anyone publishes the methodology behind the 22-second claim; whether agentic products expose a per-action authority list with rollback and an audit trail, or just faster ticket summaries, which the post itself calls a trap [11]; and whether the 42 percent never-investigated figure [7] moves, since that is the only honest measure of whether the automation absorbed work rather than relabelled it.
Ranked by verification strength, evidence, and original report placement.
In the published text, the 22-second and eight-hour handoff figures are presented without attribution to any named report, while other statistics in the same post are attributed to CrowdStrike, IBM, Microsoft/Omdia and ISC2.
CrowdStrike's 2026 Global Threat Report, as cited by Arctic Wolf, found average eCrime breakout time, the span for an adversary to move laterally from a first compromised host, has fallen to 29 minutes, with activity from AI-enabled adversaries up 89% year over year.
IBM's 2026 X-Force Threat Index, as cited by Arctic Wolf, found vulnerability exploitation is now the leading cause of the incidents it observed.
Arctic Wolf's 2026 Threat Report says ransomware, business email compromise and data incidents accounted for 92% of its incident response engagements last year, with data-only extortion incidents surging 11x year over year.
Arctic Wolf's 2026 Threat Report says 65% of non-BEC intrusions involved abuse of remote access technologies such as RDP, VPN and RMM tools.
The Microsoft/Omdia State of the SOC 2026 report, as cited by Arctic Wolf, found 46% of alerts turn out to be false positives and 42% are never investigated at all, while large enterprise SOCs field thousands of alerts a day.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One post, published twice
Strip out the duplication and this story rests on a single vendor blog post. Its third-party statistics are properly named - CrowdStrike, IBM, Microsoft and Omdia, ISC2 - but every one of them reaches us secondhand, and the figure the whole argument turns on arrives with no attribution at all. Arctic Wolf's incident-response numbers are its own book, unaudited here.
No deployment signal
Arctic Wolf names Aurora Agentic SOC and describes how work would be split between agents and humans, then stops. There is no customer, no engagement count, no measured before-and-after on detection or response time, and nobody outside the company has reported on running it. We have no basis to score uptake either way.
The number doing the work is uncited
'Structurally obsolete' is a strong verdict to hang on an unattributed median. And the two speed figures do not describe the same thing: 29 minutes of breakout time is roughly seventy-nine times a 22-second handoff, so the post's most alarming clock is the one measuring how quickly criminals trade access, not how quickly they reach your data. The underlying pain - alert floods, unfilled rosters - is better evidenced than the conclusion drawn from it.
The diagnosis is also the pitch
Arctic Wolf sells managed detection and response, and the post's cure has a product name in it. The argument is built to disqualify the nearest competition too: rivals who add AI to existing triage are said to have fallen into a trap, while replacing the operating model outright - which is what Arctic Wolf is selling - is presented as the only model that works. Published on the company's own blog, in two regional editions.
Sure what was said, unsure it holds
We can be precise about two things: exactly what Arctic Wolf asserts, and who benefits if readers believe it. Both are on the page. What we cannot do with a single self-published account is verify the 22-second median, confirm the relayed research says what it is said to say, or observe whether an agentic SOC outperforms a tiered one. That ceiling is why this sits mid-scale rather than higher.
build
Counting from the vendor advisory stretches the exploitation window to 116 days1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
OpenAI's evaluation agents turned a package registry into their messaging bus1 distinct publisher
invest
Two judges, 42 hours: Nvidia's print and Warsh's first keynote price the same trade1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 18, 2026