cxo voice
  • Business
  • Technology
    • Artificial Intelligence
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • CXO Insights
  • Cyber Security
  • CXO Interviews
No Result
View All Result
  • Business
  • Technology
    • Artificial Intelligence
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • CXO Insights
  • Cyber Security
  • CXO Interviews
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home Cyber Security

Most Attackers Logged In Instead of Breaking In: Sophos Report

Deepa Sharma by Deepa Sharma
April 3, 2025
Attackers

Image Credit: Pixabay

Sophos has released the ‘2025 Sophos Active Adversary Report.’ This report explores how attackers behave and what methods they use based on over 400 cases of Managed Detection and Response (MDR) and Incident Response (IR) from 2024. The report found that in 56% of these cases, attackers entered networks by exploiting external remote services, like firewalls and VPNs, with valid account passwords.

The combination of external remote services and valid accounts aligns with the top root causes of attacks. For the second year in a row, compromised accounts were responsible for 41% of cases. The next biggest reasons were exploited vulnerabilities (21.79%) and brute force attacks (21.07%).

The Sophos X-Ops team examined ransomware cases like data theft and data extortion to see how quickly attackers acted. They found that the average time from the start of an attack to the data stolen was just under 73 hours (3.04 days). Additionally, once the data was stolen, it took only about 2.7 hours for the attack to be detected.

“Passive security is no longer enough. Organizations must closely watch their networks and respond quickly if they notice any problems. Attacks from determined adversaries require a strong defense. This often means blending knowledge about the business with expert help in detection and response,” said John Shier, field CISO.

Other Key Findings from the 2025 Sophos Active Adversary Report:

  • Attackers can take control of a system in just 11 hours: On average, it took attackers 11 hours from their initial action to their first attempt at breaching Active Directory, a crucial part of any Windows network. If they succeed, they can easily gain control of the organization.
  • Top Ransomware Groups in Sophos Cases: Akira was the most common ransomware group in 2024, followed by Fog and LockBit, despite a major takedown of LockBit earlier in the year. – Dwell Time is Down to Just 2 Days: Overall, the time it takes to detect attacks, known as “dwell time,” reduced from 4 days to just 2 days in 2024, mainly due to more MDR cases being included.
  • Dwell Time is Down to Just 2 Days: Overall, the time it takes to detect attacks, known as “dwell time,” reduced from 4 days to just 2 days in 2024, mainly due to more MDR cases being included.
  • Dwell Time in IR Cases: Dwell time remained stable at 4 days for ransomware attacks and 11.5 days for non-ransomware cases. 
  • Dwell Time in MDR Cases: In MDR cases, dwell time was only 3 days for ransomware and just 1 day for non-ransomware, suggesting that MDR teams can find and respond to attacks quickly.
  • Ransomware Groups Work Overnight: In 2024, 83% of ransomware attacks happened outside of regular business hours.
  • Remote Desktop Protocol (RDP) is Common: RDP was involved in 84% of MDR and IR cases, making it the most commonly abused Microsoft tool.

Read the full report: The 2025 Sophos Active Adversary Report on Sophos.com.

Also Read: Why A Homegrown LLM Is the Next Big Leap for India

Deepa Sharma

Deepa Sharma

Deepa Sharma is CXOVoice’s Managing Editor, overseeing all coverage technology, cybersecurity, banking, and financial coverage. She can be reached at [email protected]

Related Posts

AI-enabled cyberattacks
Cyber Security

2026 X-Force Threat Index Warns of AI-Enabled Exploits and Rising Cyberattacks

February 26, 2026
Kyndryl cyber
Cyber Security

Kyndryl Launches First Cyber Defense Operations Center in Bengaluru

February 19, 2026
Palo Alto Acquisition of CyberArk
Cyber Security

Palo Alto Networks Completes Acquisition of CyberArk to Lead in AI-Era Security

February 12, 2026
Cyber Resilience
Cyber Security

Why Identity Will Define Enterprise Cyber Resilience in an AI-First World

February 10, 2026
Cyber Attacks AI
Cyber Security

Cyber Attacks Surge 70% as AI-Powered Threats Reach Record Levels, Check Point Report

January 29, 2026
Check Point Exposure Management
Cyber Security

Check Point Unveils AI-Driven Exposure Management to Close Cybersecurity Remediation Gap

January 22, 2026
Cybersecurity predictions 2026
Cyber Security

Prioritizing Proactive Cybersecurity as a Strategic Advantage: The Top 5 Predictions for India in 2026

December 23, 2025
Home Routers
Cyber Security

The Home Router Crisis of 2026: How India’s Living Rooms Became the New Cyberwar Frontline

December 23, 2025
Load More

More Articles

MeltPlan

MeltPlan Raises $10 Million Seed Round to Build AI Layer for Preconstruction Planning

by Arshi Khan
February 26, 2026

AMD and Nutanix

AMD and Nutanix Forge $250M Strategic Partnership to Build Open Enterprise AI Infrastructure

by Deepa Sharma
February 26, 2026

AI-enabled cyberattacks

2026 X-Force Threat Index Warns of AI-Enabled Exploits and Rising Cyberattacks

by CXOVoice Editorial Team
February 26, 2026

Outdoor edge servers

What the XR9700 Outdoor Edge Server Means for Cloud RAN Deployments

by CXOVoice Editorial Team
February 26, 2026

Get Weekly CXO Intelligence.

[wpforms id="31079"]

CXO Insights

AI India
Artificial Intelligence

AI as a Public Good: From Democratic Principles to Ground-Level Practice

by News Desk
February 13, 2026
Cyber Resilience
Cyber Security

Why Identity Will Define Enterprise Cyber Resilience in an AI-First World

by Sunil Sharma
February 10, 2026
HDDs storage
Opinion

5 Reasons HDDs Will Continue to Dominate Enterprise Storage in the AI Era

by Owais Mohammed
January 13, 2026
Cybersecurity predictions 2026
Cyber Security

Prioritizing Proactive Cybersecurity as a Strategic Advantage: The Top 5 Predictions for India in 2026

by Heba Sayed
December 23, 2025

CXO Interviews

1Point1
Business

How 1Point1 Solutions Is Betting Its Future on AI to Redefine BPM

>
NewgenONE
Business

Reimagining Enterprise Transformation: Varun Goswami on the Future of NewgenONE and AI-Driven Automation

>
Jagat Shah, Chairman & CEO of MITSUMI Group
Business

Leadership in Emerging Markets: Exclusive Interview with Jagat Shah, Chairman & CEO of MITSUMI Distribution

>
Tokenization
Blockchain

Revolutionizing Finance: An Exclusive Interview with Sid Ugrankar, Co-founder of Qila.io on the Future of Blockchain and Tokenization

>

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. We publish informed analysis, news reporting, expert commentary, and expert insights across enterprise technology, digital transformation, cybersecurity, data, AI, sustainability, and governance.

Connect with us

Easy Links

  • Cryptocurrency
  • Company Announcements
  • Event
  • Blockchain
  • Resources & Downloads
[wpforms id="30660"]
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Editorial Policy
  • Feedback

Copyright © 2026 CXOVoice - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • News
  • Business
  • Technology
  • Cyber Security
  • Opinion

Copyright © 2026 CXOVoice - All Rights Reserved