cxo voice
  • Business
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • Press Release
    • Submit Press Release
No Result
View All Result
  • Business
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • Press Release
    • Submit Press Release
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home News Cyber Security

Most Attackers Logged In Instead of Breaking In: Sophos Report

Deepa Sharma by Deepa Sharma
April 3, 2025
A A
Attackers

Image Credit: Pixabay

Sophos has released the ‘2025 Sophos Active Adversary Report.’ This report explores how attackers behave and what methods they use based on over 400 cases of Managed Detection and Response (MDR) and Incident Response (IR) from 2024. The report found that in 56% of these cases, attackers entered networks by exploiting external remote services, like firewalls and VPNs, with valid account passwords.

The combination of external remote services and valid accounts aligns with the top root causes of attacks. For the second year in a row, compromised accounts were responsible for 41% of cases. The next biggest reasons were exploited vulnerabilities (21.79%) and brute force attacks (21.07%).

The Sophos X-Ops team examined ransomware cases like data theft and data extortion to see how quickly attackers acted. They found that the average time from the start of an attack to the data stolen was just under 73 hours (3.04 days). Additionally, once the data was stolen, it took only about 2.7 hours for the attack to be detected.

“Passive security is no longer enough. Organizations must closely watch their networks and respond quickly if they notice any problems. Attacks from determined adversaries require a strong defense. This often means blending knowledge about the business with expert help in detection and response,” said John Shier, field CISO.

Other Key Findings from the 2025 Sophos Active Adversary Report:

  • Attackers can take control of a system in just 11 hours: On average, it took attackers 11 hours from their initial action to their first attempt at breaching Active Directory, a crucial part of any Windows network. If they succeed, they can easily gain control of the organization.
  • Top Ransomware Groups in Sophos Cases: Akira was the most common ransomware group in 2024, followed by Fog and LockBit, despite a major takedown of LockBit earlier in the year. – Dwell Time is Down to Just 2 Days: Overall, the time it takes to detect attacks, known as “dwell time,” reduced from 4 days to just 2 days in 2024, mainly due to more MDR cases being included.
  • Dwell Time is Down to Just 2 Days: Overall, the time it takes to detect attacks, known as “dwell time,” reduced from 4 days to just 2 days in 2024, mainly due to more MDR cases being included.
  • Dwell Time in IR Cases: Dwell time remained stable at 4 days for ransomware attacks and 11.5 days for non-ransomware cases. 
  • Dwell Time in MDR Cases: In MDR cases, dwell time was only 3 days for ransomware and just 1 day for non-ransomware, suggesting that MDR teams can find and respond to attacks quickly.
  • Ransomware Groups Work Overnight: In 2024, 83% of ransomware attacks happened outside of regular business hours.
  • Remote Desktop Protocol (RDP) is Common: RDP was involved in 84% of MDR and IR cases, making it the most commonly abused Microsoft tool.

Read the full report: The 2025 Sophos Active Adversary Report on Sophos.com.

ADVERTISEMENT

Also Read: Why A Homegrown LLM Is the Next Big Leap for India

Deepa Sharma

Deepa Sharma

Deepa Sharma is CXOVoice’s Managing Editor, overseeing all coverage technology, cybersecurity, banking, and financial coverage. She can be reached at [email protected]

Related Posts

Home Routers
Cyber Security

The Home Router Crisis of 2026: How India’s Living Rooms Became the New Cyberwar Frontline

December 23, 2025
Palo Alto Networks and Google Cloud
Cyber Security

Palo Alto Networks and Google Cloud Expand Partnership to Enhance AI Security for Enterprises

December 22, 2025
AI attack
Cyber Security

Palo Alto Networks Report Reveals AI is Driving a Massive Cloud Attack Surface Expansion

December 17, 2025
Check Point Quantum Firewall
Cyber Security

Check Point Launches Quantum Firewall Software R82.10 to Secure the AI-Driven Enterprise

December 5, 2025
Ransomware
Cyber Security

Cyberattacks Surge 5% Year-Over-Year with Ransomware Threats on the Rise, Education Sector Most Targeted

November 13, 2025
AI in Banks
Cyber Security

Banks and Insurers Turn to AI Agents to Fight Fraud and Create New Roles to Keep Them in Check: Report

November 12, 2025
India's Cybersecurity ecosystem
Cyber Security

Inside India’s $20 Billion Cybersecurity Ecosystem: Growth, Challenges, and the Road Ahead

November 11, 2025
ransomware retailers
Cyber Security

58% of retailers hit by ransomware paid the ransom: Report

November 4, 2025
Load More
ADVERTISEMENT

Latest Updates

Rajkumar Bafna Delhi Pollution

Akums Pharma’s Finance Chief Rajkumar Bafna Resigns Citing Pollution in Delhi

by CXOVoice Edtiroial Team
8 hours ago

Coforge Encora

Coforge to Acquire Encora in $2.35 Billion Deal, Creating Global AI Engineering Powerhouse

by Deepa Sharma
3 days ago

MediaTek and DENSO

MediaTek and DENSO Forge Strategic Alliance to Drive Next-Gen Automotive ADAS Solutions

by CXOVoice Edtiroial Team
3 days ago

Deloitte India and Google Cloud

Deloitte India Expands Partnership with Google Cloud to Deliver Next-Gen AI-Powered Security Solutions

by News Desk
4 days ago

NetApp and Agastya

NetApp and Agastya Launch Data Explorers Lab to Advance Data & AI Education in India

by Deepa Sharma
5 days ago

Noida International Airport

Noida International Airport Taps Tech Mahindra to Bolster Cybersecurity and Network Operations

by Deepa Sharma
6 days ago

Expert Views

Cybersecurity predictions 2026
Opinion

Prioritizing Proactive Cybersecurity as a Strategic Advantage: The Top 5 Predictions for India in 2026

December 23, 2025
Home Routers
Cyber Security

The Home Router Crisis of 2026: How India’s Living Rooms Became the New Cyberwar Frontline

December 23, 2025
Storage Engineers
Opinion

5 Future-Ready Skills Every Storage Engineer Should Build in 2026

December 22, 2025
AI Govern
AI

How CIOs and CISOs Can Govern AI Without Slowing the Business

December 22, 2025
Technology trends 2026
Opinion

Technology trends redefining how enterprises will operate in 2026

December 19, 2025

Get Latest Update

Subscribe to our mailing list to receives newsletter direct to your inbox!

ADVERTISEMENT

Leaders Interviews

NewgenONE
Interview

Reimagining Enterprise Transformation: Varun Goswami on the Future of NewgenONE and AI-Driven Automation

-
Jagat Shah, Chairman & CEO of MITSUMI Group
Leaders Talk

Leadership in Emerging Markets: Exclusive Interview with Jagat Shah, Chairman & CEO of MITSUMI Distribution

-
Tokenization
Interview

Revolutionizing Finance: An Exclusive Interview with Sid Ugrankar, Co-founder of Qila.io on the Future of Blockchain and Tokenization

-
Steve Wilson, GenAI Cybersecurity LLMs
Cyber Security

How effective is GenAI in cybersecurity? The role of LLMs and AI in security solutions. [Interview with Steve Wilson]

-

Entrepreneur

Persistent Gender Bias Clouds Perceptions of Leadership in Tech: Study Finds

Top Leadership Skills Entrepreneurs Need in the Age of AI

Samsung Electronics appoints its first female president

Inspiring Women Entrepreneurs in India (2022)

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. We publish informed analysis, news reporting, expert commentary, and expert insights across enterprise technology, digital transformation, cybersecurity, data, AI, sustainability, and governance.

Connect with us

Easy Links

  • Cryptocurrency
  • Event
  • Blockchain
  • Press Release
  • Resources & Downloads
Loading
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Editorial Policy
  • Feedback

Copyright © 2025 de Audience - All Right Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • News
  • Business
  • Technology
  • Cyber Security
  • Opinion
  • Leaders Talk

Copyright © 2025 de Audience - All Right Reserved