Attackers Move in 29 Minutes. You Get 24 Hours to Report. That Comparison Is Wrong.
Everyone is comparing AI attack speed against EU reporting deadlines and concluding the regulation is too slow. They are timing two different races. The number that should scare you is 14 days.
You have seen the slide. On the left, CrowdStrike's headline number: average breakout time of 29 minutes, fastest ever recorded at 27 seconds. On the right, the NIS2 early warning deadline of 24 hours and DORA's 4-hour initial notification. The conclusion writes itself. The regulators are hopelessly behind the attackers.
The slide is wrong. Not the numbers, those are real. The comparison.
DORA and NIS2 do not set response deadlines. They set reporting deadlines. And both clocks start when you become aware of the incident, not when the attacker gets in. Putting them next to a breakout time is like timing a sprinter against the person who files the race results.
Once you fix the comparison, a much worse number appears.
Two clocks, and neither one starts at compromise
NIS2 Article 23 gives you 24 hours from becoming aware of a significant incident to file an early warning. Then 72 hours for the full notification, and one month for the final report. The early warning is deliberately thin. State the nature of the incident, the systems affected, a preliminary scope, and whether you suspect malicious action or cross-border impact. Nobody expects a finished investigation in a day.
DORA is tighter for financial entities. Initial notification within 4 hours of classifying an incident as major, and in any case no later than 24 hours from becoming aware of it. Then 72 hours and one month, same cascade. If you are in scope of both, DORA wins as the more specific law, and NIS2 Article 4 takes in-scope financial entities out of NIS2 altogether.
Notice the trigger words. "Awareness." "Classification." Neither says compromise. Neither says breach.
The attacker's clock runs on entirely different fuel. CrowdStrike measures breakout from initial access to lateral movement. Mandiant measures the gap from initial access to handoff at 22 seconds in 2025, down from more than eight hours in 2022. In one intrusion CrowdStrike observed exfiltration starting four minutes after access.
Line them up and the gap looks apocalyptic:
| Attacker milestone | Time | vs NIS2 24h | vs DORA 4h | |----------------------------|------------|-------------|------------| | Fastest breakout on record | 27 seconds | 3,200x | 533x | | Access to handoff | 22 seconds | 3,927x | 654x | | Exfiltration begins | 4 minutes | 360x | 60x | | Average eCrime breakout | 29 minutes | 50x | 8x |
Every row of that table is meaningless. The regulatory clock has not started yet.
The number that actually matters
Here is the row that belongs on the slide. Mandiant's M-Trends 2026, built on more than 500,000 hours of incident response in 2025, puts global median dwell time at 14 days. That is up from 11 days in 2024. It went the wrong way.
Break it down and it gets sharper. When you find the intrusion yourself, median dwell is 9 days. When somebody else tells you, it is 25 days, up from 11. Espionage cases and North Korean IT worker cases sit at 122 days. BRICKSTORM persistence cases ran close to 400.
So the honest sequence looks like this. The attacker breaks out in 29 minutes. Then roughly 14 days pass. Then you notice. Then your 24-hour clock starts, and you file comfortably inside it, fully compliant, on day 15.
The regulation is not too slow. Your detection is. And no reporting deadline, however aggressive, addresses that gap. A 4-hour deadline and a 4-minute deadline produce the same outcome when the trigger is awareness and awareness takes a fortnight.
AI is real, but it is not the root cause
Two of the best threat intelligence teams in the world disagree here, and the disagreement is worth sitting with.
CrowdStrike frames AI as the defining accelerant of 2025. AI-enabled adversary activity up 89% year on year. Breakout time 65% faster than 2024. Malicious prompts injected into legitimate generative AI tools at more than 90 organisations to produce credential and crypto stealing commands.
Anthropic's GTG-1002 disclosure is the sharpest single data point. A likely China-nexus actor ran Claude Code through MCP servers against around 30 organisations. The AI executed 80 to 90% of the tactical work: reconnaissance, network mapping, exploit generation, credential harvesting, exfiltration and triage by intelligence value. Humans acted as checkpoint authorities at four to six decision points across the whole campaign. At peak it issued thousands of requests, often several per second.
Mandiant then says the quiet part. 2025 was not the year breaches were directly caused by AI. Human and systemic failures remained the primary cause. Exploits were the top initial vector at 32%. Voice phishing surged to second place at 11%. Somebody phoned your service desk and asked nicely.
Both things are true. AI is compressing the tempo of intrusions that still begin with an unpatched edge device, a stolen credential, or a convincing phone call. Treating AI as the root cause leads you to buy an AI defence product when what you needed was patch management and a service desk that verifies identity.
DORA's first year says something inconvenient
The European Supervisory Authorities published year-one DORA incident data covering 2025. It does not read like a story about AI attackers.
3,383 major ICT incidents reported across the EU, averaging 0.18 per entity. System failures caused 51% of them. Nearly a third originated with third parties: ICT providers, infrastructure operators, other financial institutions. Cybersecurity incidents accounted for 10%, and DDoS plus data exfiltration made up two-thirds of that slice. The ESAs went out of their way to say the volume "should not be interpreted as a sign of structural weaknesses."
The financial sector's biggest operational resilience problem in year one was its own plumbing and its vendors. That is not an argument for ignoring AI-speed attacks. It is an argument for keeping the risk register honest.
One more finding deserves attention. Around 15% of notified incidents never got a final report, and cost data quality was poor. Practitioners describe DORA reporting as morphing into generic data analysis rather than useful information. Industry estimates put sector-wide compliance spend near $181bn a year. A lot of that bought paperwork.
The compliance industry optimised the wrong half
Both regulations contain a half that almost nobody budgets for.
NIS2 Article 21 mandates risk management measures: incident handling, business continuity, supply chain security, vulnerability handling and disclosure, and testing whether any of it works. DORA Articles 5 to 15 require an ICT risk management framework with detection mechanisms, response and recovery, backup policy, and a learning loop.
Then DORA Articles 26 and 27 go further than anything in NIS2. Designated entities must run threat-led penetration tests at least every three years, on live production systems, including critical third-party infrastructure. Not an audit. Not a scoped pentest against a staging environment. Intelligence-led red teaming against real adversary techniques, run by independent testers, following the TIBER-EU pathway.
TLPT is the single most relevant provision to the AI-speed question, because it measures whether detection and response actually function under realistic conditions. That is the metric that is failing. And it is the provision that gets a fraction of the attention given to registers of information and reporting templates.
If you are not designated for TLPT, run the exercise anyway. The finding you want is not "did we pass." It is "how many days did we take."
What to do on Monday
The 2026 guidance converges from Microsoft, SANS, Mandiant and the incident response community. Eight things, roughly in order of how much they buy you.
Pre-authorise containment. For each asset class, decide now which actions the SOC may take without escalation and which need a human. This one change converts a 29-minute breakout window from a loss into a fight. It costs nothing and it is a policy decision, not a purchase. Go identity-first. 82% of CrowdStrike detections were malware-free. Valid credentials, trusted identity flows, nothing to scan for. Continuous authentication, behavioural analytics, minimal privilege, short-lived just-in-time tokens. Measure decision latency, not just detection. Time how long your identity controls take to decide, not only whether they eventually alert. Against attacks that run in parallel, decision speed is itself a control. Treat every AI agent as a distinct identity. Named human owner, minimum tools and data, short-lived tokens, its own audit trail. Agents sharing a service account are invisible when they misbehave. Automate the reporting pack. The 24-hour early warning is only hard because teams start assembling infrastructure context after the alert fires. Pre-correlate asset, DNS, certificate and traffic data continuously, and a credible early warning becomes a query instead of a project. Watch backup and recovery. Mandiant reports ransomware shifting from encryption toward recovery denial: destroying backup infrastructure, abusing AD Certificate Services, deleting cloud backup objects, going after the hypervisor layer. Fix the third-party register properly. A third of DORA major incidents started with a third party. Your reporting clock still runs when the outage belongs to your vendor. Get the executives in the room. NIS2 carries personal liability for management bodies. Senior executives must approve cybersecurity risk management measures and can face sanctions when the organisation fails. The people who sign that off are the same people who need to pre-authorise containment.
One rule change is worth tracking. The EU Digital Omnibus, agreed provisionally on 7 May 2026, creates a single reporting entry point operated by ENISA, where one notification satisfies GDPR, NIS2, DORA, eIDAS and CER obligations. It is due within 18 months of entry into force, and GDPR breach notification moves from 72 to 96 hours. Useful, though it solves the regulator's aggregation problem more cleanly than the operator's. You still need a crosswalk between regimes with different definitions and thresholds before one form does the job.
The point
The only answer to machine-speed attack is machine-speed containment inside human-set guardrails. Roughly two-thirds of organisations are experimenting with AI agents in security operations. Fewer than one in four have put them into production. Vendors claim containment in under two minutes and 98% faster mean time to resolution, and you should treat those figures as marketing until somebody independent checks them. The direction is still right.
Start with the honest question. Not "can we file within 24 hours." You almost certainly can. Ask how long it takes you to notice, and whether you have ever measured it under conditions that resemble a real attack.
Fourteen days is the median. Half of everyone is worse.
Compliance will not tell you which half you are in.
Sources
- CrowdStrike 2026 Global Threat Report: AI Accelerates Adversaries - 29-minute average breakout time, 27-second record, +89% AI-enabled adversary activity, 82% malware-free detections
- M-Trends 2026: Data, Insights, and Strategies From the Frontlines - 14-day median dwell time, 22-second access-to-handoff, AI malware families, and the key caveat that AI did not directly cause 2025 breaches
- Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign - Primary source on GTG-1002 — 80-90% autonomous execution, thousands of requests per second, 4-6 human decision points
- Pillsbury: DORA's First Year of Major Incident Reporting - ESAs year-one DORA data — 3,383 major incidents, 51% system failures, only 10% cybersecurity, a third from third parties
- NIS 2 Directive, Article 23: Reporting obligations - Authoritative text of the NIS2 24h/72h/1-month reporting cascade
- Legiscope: DORA vs NIS2 — Key Differences for Financial Entities - The DORA 4h vs NIS2 24h comparison and the lex specialis deconfliction rule
- Silent Push: NIS2's 24-Hour Early Warning Requirement - Why "awareness" is the hard part of the 24-hour clock, plus NIS2 personal liability for management bodies
- DORA Threat-Led Penetration Testing (TLPT): Articles 26-27 Requirements - TLPT Articles 26-27 — three-year cycle on live production systems, TIBER-EU pathway, which entities are designated
- Hunton: EU Digital Omnibus Introduces a Single Reporting Point for Cybersecurity Incidents - ENISA-operated single reporting portal, 18-month timeline, GDPR breach deadline moving 72 to 96 hours
- NIS2 Country Transposition Tracker 2026: Status by Member State - Transposition status 23/27, Ireland referred to the CJEU July 2026, first NIS2 fines in Belgium, Italy and Hungary
- Microsoft Security: Four priorities for AI-powered identity and network access security in 2026 - Parallel attack execution economics, treating AI agents as distinct IAM identities, measuring decision latency