The point: More than half of critical cyberattacks are discovered only after more than 90 days because security solutions fail to generate reliable alerts and organizational shortcomings extend response times.
A Kaspersky analysis shows that malicious activity in corporate networks often goes unnoticed for months. In serious security incidents, 52 percent were not discovered until more than 90 days later.
The Kaspersky analysis examined security incidents with regard to their detection time. The results reveal significant delays: in 31 percent of analyzed cases, malicious activity had been active in IT environments for longer than three months. Particularly alarming is the rate for critical incidents – 52 percent of attacks were not detected until more than 90 days after compromise. In extreme cases, a compromise remained undetected for four years.
A core problem lies in the unreliability of existing security tools. In 60 percent of the incidents examined, the systems deployed did not generate alerts with sufficiently high confidence levels. As a result, attacks had to be identified through alternative means – such as manual review by administrators or security teams. One in five security incidents examined was detected exclusively through manual means. An additional risk lies in backup systems: in 40 percent of cases, webshells or other malware remained undetected in backups, which can lead to reinfections after supposedly successful remediation.
Beyond technical deficiencies, organizational shortcomings hinder defense. In nearly one-third of analyzed cases, experts identified problems such as unclear communication channels, lack of feedback on implemented measures, or knowledge loss due to staff turnover. These factors significantly delay incident response.
Kaspersky recommends complementing traditional protective measures with regular security assessments, continuous threat-hunting activities, and updated patching processes. Additionally, organizations should optimize their detection mechanisms, systematically evaluate even low-priority alerts, and conduct realistic exercises for incident response teams. Clear organizational procedures and regular employee training help identify incidents faster and limit their impact.
Source: www.it-daily.net · Published July 9, 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.