CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Inside the Modern SOC: The 72-Minute Race

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 340

As cited

Copy frozen at (site build).

threat intel

Inside the Modern SOC: The 72-Minute Race

Research indicates attackers can progress from initial access to data exfiltration in approximately 72 minutes. The article discusses how security operations center (SOC) teams can address this timeline through AI-driven automation, threat hunting, managed detection and response (MDR), and extended security information and event management (XSIAM) capabilities.

Why it matters: SOC practitioners need to understand attack speed and deploy faster detection and response mechanisms to prevent data loss during the critical window between compromise and exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Inside the Modern SOC: The 72-Minute Race

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Inside the Modern SOC: The 72-Minute Race

Palo Alto Networks Unit 42 highlights research showing attackers can move from initial access to data exfiltration within 72 minutes. The article discusses how security operations center (SOC) teams can close the response gap using artificial intelligence (AI) driven automation, threat hunting, managed detection and response (MDR), and managed extended security information and event management (XSIAM).

Why it matters: SOC teams and security leaders need faster detection and response capabilities to compete with the speed of modern attacks, and automation plus threat hunting are practical ways to reduce dwell time.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary