By David Chernitzky, CEO and Co-Founder, Armour Cybersecurity · Serving Toronto and organizations across Canada · Last updated August 10, 2026
Quick answer
Incident response time is the interval between detecting a security incident and executing the first effective containment action, and the first two hours carry disproportionate weight. They shape how far the attack spreads, how much data is compromised, how long recovery takes, what the legal exposure looks like, and what the incident costs in total. Organizations with pre-established response capability, documented decision authority, and a team that activates fast consistently outperform the ones that start organizing after the incident is already running.
Key Takeaways
- Ransomware propagation, data exfiltration, and lateral movement all outpace improvised response. Every minute of uncontested access widens the scope of the incident.
- Three decisions dominate the first two hours: who has authority to take systems offline, whether backup systems are intact, and whether breach counsel is engaged before any external communication goes out.
- Organizations without pre-established response capability spend the first hour working out who should be on the call. Organizations with a retainer spend it executing containment.
- Forensic evidence preserved in the first two hours is what makes insurance claims and regulatory submissions defensible. Remediating before forensics are captured destroys the evidentiary record.
- Mandiant’s M-Trends 2026 puts global median dwell time at 14 days, up from 11 the year before, so by the time most organizations detect an intrusion the attacker has had two weeks inside.
What the Dwell Time Data Says About Incident Response Time
Response time only becomes meaningful once you know how long the attacker was already there. Mandiant’s M-Trends 2026 report, built on Mandiant Consulting investigations across 2025, puts the global median dwell time at 14 days, up from 11 days the year before. That reverses close to a decade of steady improvement.
The breakdown matters more than the headline. Cyber espionage cases and North Korean IT worker incidents carried a median dwell time of 122 days, roughly four months of undetected presence. On the other hand, organizations detected malicious activity internally 52% of the time in 2025, up from 43%, so internal visibility is improving even as the median climbs. Exploits remained the most common initial infection vector at 32%, and highly interactive voice phishing surged to 11% to become the second most common.
Read that alongside the first-two-hours question and the picture sharpens. Detection is usually late, which means the response clock starts with the attacker already established, already holding credentials, and often already aware of the backup infrastructure. There is no early portion of the incident left to waste.
What Is Happening on the Attacker Side in the First Two Hours?
Ransomware operators who gain initial access do not fire the encryption payload immediately. The gap between access and execution, dwell time, gets spent on reconnaissance, privilege escalation, and positioning. When encryption finally runs, it is timed to hit as many systems as possible before anyone notices.
During that window the attacker is mapping the environment, locating backup systems and trying to compromise them, exfiltrating high-value data ahead of encryption so there is a second lever for extortion, and planting persistence mechanisms that survive an incomplete response. Every undetected hour adds to what the response team eventually has to unwind.
Business email compromise runs on a different clock with the same urgency. Once a fraudulent wire instruction is acted on, the window to recall the transfer through the banking system is usually measured in hours rather than days, and the financial institution’s fraud team needs to hear about it before the funds clear the receiving bank. An organization that finds the fraud at 9am and spends two hours deciding who owns the response may have already missed the recall window.
What Does Poor Early Response Look Like?
Poor early response follows a recognizable pattern. Not because the people involved are careless, but because the structures and relationships needed to move fast were never built.
The notification delay
Whoever notices first, usually someone in IT, is not sure this is serious enough to escalate. So they investigate a little longer, trying to confirm scope before raising an alarm. Thirty to sixty minutes disappear. Escalation from IT to the CISO takes another fifteen. Deciding to engage external responders takes thirty more. The external team gets its first call ninety minutes after detection.
The authority gap
The response team asks for authorization to isolate a server that processes customer transactions. The IT lead cannot approve taking it offline. The CISO can, but wants the COO to confirm the business impact is acceptable, and the COO is in a board meeting. Twenty minutes pass. The attacker spends them using that server as a pivot into additional systems.
The evidence destruction problem
Before the external team arrives, internal IT reboots several compromised systems trying to restore normal operation. Two servers that were the original entry point get reimaged under standard procedure. Firewall logs covering the critical window have already rolled off, because retention was forty-eight hours and detection came seventy-two hours after initial access. The trail that would have shown how the attacker got in, which credentials were taken, and what data was touched is gone. Sequencing technical forensics ahead of remediation is what prevents this, and it is the single most expensive mistake on this list.
The communications improvisation
While the technical response is still assembling, someone in customer service answers questions about the service disruption with a vague post on social media. The wording implies the incident was minor and contained, before scope has been confirmed. Two hours later the scope turns out to be larger, and the legal team inherits a public statement to manage on top of the breach. Coordinating early messaging through breach coach services keeps the technical and legal positions from contradicting each other in public.
What Does Good Early Response Look Like?
Good early response comes down to speed, authority, and discipline.
The first notification reaches the right person immediately, because the escalation threshold is documented and the notification tree is current. The decision to engage external response happens in minutes, since the criteria were settled in the incident response plan rather than debated during the incident.
Activation starts with context already in place. For retainer clients, the engagement call reaches a team that holds the asset inventory, the network architecture, the critical system documentation, and the business contacts from onboarding. The first thirty minutes go to confirming incident type and severity instead of introductory questions about the environment.
Evidence preservation runs in parallel with the first containment actions, because the team knows the order: evidence before isolation, isolation before remediation. Authority for containment is clear and the person holding it is reachable. The cyber insurance carrier is notified through the documented procedure. Breach counsel is on a parallel call, shaping legal guidance before anyone drafts an external statement.
None of that is luck. It is the product of establishing the relationship in advance, documenting escalation thresholds, clarifying decision authority, and making sure the response team starts from context rather than a blank page. A breach readiness assessment is how most organizations find out which of those four they are actually missing.
Three Decisions That Cannot Wait
Most of the first two hours is execution, but three calls have to be made by a human with authority, and each one gets harder the longer it sits.
Who can take systems offline. Containment often means stopping something the business depends on. If that authority is not named in advance, the decision escalates through people who are not available, and the attacker keeps moving during the escalation.
Whether backups are intact. Modern ransomware operators target backup infrastructure deliberately, before encryption. Confirming backup integrity early determines whether recovery is a restoration exercise or a negotiation.
Whether counsel is engaged before anyone communicates. Legal privilege, regulatory notification timing, and public messaging all flow from this. Once a statement is out, correcting it costs more than delaying it would have.
What Should the CEO Know About Breach Response Timing?
Business owners and CEOs are usually not close to security operations until a breach happens, and the timing of their involvement matters.
The CEO is typically the decision-maker for the choices with the most material business consequence: accepting operational disruption to stop a spreading attack, engaging a ransom negotiator, and deciding when to talk to customers and partners. Those are not delegable to IT. They carry financial, legal, and reputational weight that requires the authority and accountability of ownership.
A CEO who has reviewed the decision authority framework and sat through a tabletop makes those calls faster and with more confidence than one hearing the options for the first time at midnight. That is the entire argument for cyber simulation exercises at the executive level, not just the technical one.
How Early Response Affects Canadian Reporting Obligations
Under PIPEDA, a Canadian organization has to report a breach of security safeguards to the Office of the Privacy Commissioner as soon as feasible once it is reasonable to believe the breach creates a real risk of significant harm. Assessing that risk requires knowing what data was touched, which is exactly what gets destroyed when remediation runs ahead of forensics.
Every breach also has to be recorded and kept for at least 24 months, whether or not it met the reporting threshold, and the Commissioner can ask to see those records. The evidence captured in the first two hours is what those records are built from. The full sequence of obligations sits inside the wider incident response lifecycle, where documentation is a concurrent deliverable rather than a closing report.
Frequently Asked Questions
What is a good incident response time?
There is no single benchmark, because the meaningful measure is time to effective containment rather than time to first phone call. A practical target for most mid-sized organizations is external responders engaged within the first hour of confirmed detection, with initial containment actions executing inside the first two. Retainer arrangements typically hit that window because activation and onboarding are already settled. Emergency engagements rarely do, since the team has to learn the environment and the incident at the same time.
How much faster is retainer response compared to emergency engagement?
The difference concentrates in the early stages. A retainer engagement activates with pre-established context: the team knows the environment, has documented the critical systems, and has communication channels in place before anything happens. An emergency engagement begins with discovery, understanding the environment, the business, and the incident simultaneously. That discovery can add several hours at exactly the point where speed matters most.
What is dwell time and how does it affect the response?
Dwell time is the period between an attacker gaining initial access and the moment the intrusion is detected. During it, attackers conduct reconnaissance, escalate privileges, exfiltrate data, and position for the main attack. Mandiant’s M-Trends 2026 reports a global median of 14 days, rising to 122 days for cyber espionage and North Korean IT worker cases. Longer dwell time means a larger response: more systems potentially compromised, more data potentially taken, and more persistence mechanisms waiting to be found.
Should we notify our cyber insurance carrier before we call the response team?
Treat them as parallel actions rather than a sequence. Most policies require carrier notification within a defined period of becoming aware of an incident, and many specify that carrier-approved vendors handle forensic response, so engaging an unapproved responder first can create a coverage problem. Engage the response team immediately while the carrier notification process starts alongside it. The response team should be able to guide that engagement and structure the documentation for the claim.
Can we contain the breach ourselves and only call for help if needed?
Internal containment is a reasonable first step when the organization has trained security staff and clear procedures. Revoking a compromised account, blocking a known malicious address, or isolating a specific endpoint are all actions internal IT can take immediately. The risk lies in delaying external engagement, because containment without forensic preservation, root cause investigation, and full eradication tends to produce incomplete remediation. Attackers leave persistence mechanisms internal teams do not know to look for.
What is the most important thing to do in the first fifteen minutes of a breach?
Activate the response structure rather than trying to solve the incident. Notify the designated response lead through the escalation procedure in the IR plan, activate the retainer if one exists, notify breach counsel if that relationship is in place, and start the carrier notification procedure. Leave compromised systems running and untouched while that happens. Fifteen minutes spent convening the right people with the right authority is worth more than fifteen minutes of well-intentioned remediation that destroys the evidence.
The Bottom Line
Incident response time is not really a measure of how fast a team can type. It measures how much was decided before the incident: who holds containment authority, which responders get called, whether counsel and the carrier are already in the plan, and whether the team on the other end of the call already knows the environment. Organizations that settle those questions in advance spend the first two hours containing an attack. The rest spend them building an org chart. Armour Cybersecurity’s breach response services operate on both models, retainer and emergency activation, and the difference between them shows up almost entirely in those first two hours.
Fast breach response rarely works alone. It is one pillar of Armour’s managed cybersecurity services, operating alongside a managed Security Operations Center whose monitoring shortens detection time, cyber threat intelligence on active adversary behaviour, vCISO leadership to set escalation authority before an incident, cyber awareness training to reduce the incidents that start with a click, and the all-in-one Armour 360 managed program.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate.



