Average Time to Detect a Data Breach: 241 Days in 2025
Average time to detect a data breach: 241 days per IBM 2025 data, versus the 60 seconds it takes to click a phishing link, and how to close that gap.
Average time to detect a data breach: 241 days per IBM 2025 data, versus the 60 seconds it takes to click a phishing link, and how to close that gap.
The average time to detect a data breach is 181 days, with another 60 days to contain it once found, a total breach lifecycle of 241 days, according to IBM’s 2025 Cost of a Data Breach Report. That is the fastest this figure has been in nine years, and it is still eight months. In that same window, the median time for an employee to click a phishing link and enter credentials is about 60 seconds.
Table of Contents
ToggleTwo numbers define the real risk in data breach detection, and the gap between them is the story. Attackers move in seconds. Defenders, on average, take months. A phishing email lands, an employee clicks and submits credentials within about a minute, and from that point the attacker often has extended, quiet access to systems long before anyone notices anything is wrong.
IBM’s 2025 research breaks the 241-day figure into two parts: 181 days to identify a breach and 60 days to contain it after identification. Healthcare breaches take longer still, averaging 279 days, more than five weeks past the cross-industry average. Organizations that detected a breach internally, rather than being told about it by an attacker or a third party, saved roughly $900,000 in breach costs, underscoring how much of the cost sits in the delay itself rather than the initial compromise.
Detection and containment times have improved steadily, but the 241-day figure is still measured in months, not hours, for a structural reason: most organizations are built to investigate incidents, not to catch behavior in the moment it happens. A phishing click generates no alarm by itself. It only becomes visible once the attacker does something a monitoring tool is tuned to notice, and tuning that sensitively without drowning the security team in false positives is a genuinely hard problem.
Verizon’s 2025 Data Breach Investigations Report found 60% of breaches involve a human element, meaning the initial entry point is rarely a novel technical exploit. It is a credential, a click, or an approval an attacker only needed once. That single moment doesn’t announce itself. Everything that happens for the next 181 days is the security team trying to notice a door that was already quietly opened.
Discover how Threatcop protects your workforce from modern cyber threats.
The one place the 2025 data shows real acceleration is in organizations using AI and automation extensively in their security operations. Those organizations identified and contained breaches 80 days faster on average, and saved nearly $1.9 million per breach compared to organizations with no AI or automation in their detection pipeline. That gap is large enough to represent a genuine shift in what’s achievable, not just incremental tuning of existing tools.
The catch is that the same period saw AI risk cut the other way too: breaches involving unsanctioned or shadow AI cost $670,000 more on average and took 10 days longer to identify and contain, and 63% of organizations reported having no governance policy for AI tools at all. Faster detection tooling and a bigger, less-governed attack surface are advancing at the same time, which is why the improvement in the average masks a widening gap between organizations doing both well and those doing neither.
Every day shaved off the 241-day average is a day of reduced cost and exposure, but the highest-leverage fix sits earlier than detection tooling: reducing how often the 60-second click happens in the first place. Phishing incident response programs that shorten the loop between an employee spotting something suspicious and a security team acting on it compress the 181-day identification window directly, because employee reports are often the fastest detection signal an organization has, faster than any log analysis pipeline.
A few things compound that advantage:
The detection and containment timeline gets most of the attention because it’s the number tied to cost, but it starts downstream of a much smaller number: the 60 seconds it takes one person to decide whether an email is safe. Closing the eight-month gap between attacker speed and defender speed means treating that decision point, and what happens in the minutes after someone reports it, with the same urgency as the automated detection stack.
If your organization’s incident response playbook still treats the human reporting layer as a secondary signal instead of a primary one, Threatcop’s phishing incident response tooling is built to close exactly that gap, and understanding where human risk concentrates in your organization is the fastest way to find out where the next 181 days would start.
According to IBM’s 2025 Cost of a Data Breach Report, organizations take an average of 181 days to identify a breach and another 60 days to contain it, for a total breach lifecycle of 241 days, the fastest this figure has been in nine years.
Industry data cited from Verizon’s Data Breach Investigations Report puts the median time for a user to click a phishing link and submit credentials at roughly 60 seconds from when the email is opened.
Yes, substantially. IBM’s 2025 research found organizations using AI and automation extensively in their security operations identified and contained breaches 80 days faster on average than organizations with no AI or automation involved.
Most breaches begin with a human element, such as a phishing click or compromised credential, rather than a novel technical exploit. That initial moment produces no automatic alarm, so detection depends on noticing downstream behavior, which is slower and harder to tune accurately than catching the initial entry point.
Reducing friction in how employees report suspicious activity has an outsized effect, since employee reports are frequently the fastest detection signal available, often faster than automated log analysis, but only if the report reaches a response process immediately rather than sitting in a queue.

Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Password reuse attacks explained: how stolen credentials power account takeovers, why 60% of users still reuse passwords, and the...
RBI cybersecurity framework for banks explained: what it requires, why training and awareness controls are the most common gap,...
Cognitive warfare in cybersecurity targets decision-making, not systems. How these attacks work and how to build workforce resilience.
Table of Contents
×