Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A 2022 survey of more than 300 ethical hackers found that respondents said they could find and exploit a perimeter weakness in less than 10 hours. That is a reported capability among surveyed ethical hackers—not a stopwatch measurement of criminal intrusions or a reliable deadline for every organization. The finding is a warning to understand what is exposed and how quickly defenders can detect and respond.

What the less-than-10-hours figure means

Dark Reading’s September 28, 2022, account of a SANS and Bishop Fox survey describes the figure as the average ethical hacker’s reported ability to find and exploit a vulnerability that breaches a network perimeter. It measures a specific task, starting with a weakness at the perimeter; it does not say every attacker can compromise every target within that time. Dark Reading’s report and Bishop Fox’s survey overview describe related, but distinct, measures.

The survey was conducted by SANS and sponsored by Bishop Fox, and covered more than 300 ethical hackers around the world, according to the organizations’ 2022 materials. The results reflect respondents’ reported capabilities. The reviewed accounts do not provide detailed sampling methods, exact question wording, or confidence intervals, so the numbers should not be treated as a representative measure of all attackers or organizations.

What the survey measured

The figures make sense only when kept alongside the action and starting point each one describes. Bishop Fox’s summary reports these results from the 2022 SANS/Bishop Fox survey:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Measure Reported result What it describes
End-to-end attack 57% could complete one in less than a day Completion of an attack, not just initial perimeter access.
Data collection and exfiltration after access 64% said they could collect and potentially exfiltrate data in five hours or less; 41% said two hours or less A post-access activity. Bishop Fox’s overview also highlights 64% reporting exfiltration in less than five hours; that is its stated wording and should not be silently substituted for the separate “five hours or less” formulation.
Privilege escalation or lateral movement 36% could escalate or move laterally in three to five hours Actions taken after gaining access, not the time to find the initial weakness.
Defender readiness 74% said only a few or some organizations had sufficient detection and response capabilities Respondents’ assessment of organizations’ ability to detect and respond, not a measured failure rate.

These figures come from Bishop Fox’s September 2022 summary. They are not interchangeable: time to breach, time to finish an attack, and time to act after access have different starting points and endpoints.

Which perimeter weaknesses came up

The survey accounts identify vulnerable configurations, exposed web services, and vulnerable software as common exploitable exposures. For defenders, that points to a practical inventory problem: an organization cannot prioritize or fix an internet-facing system it does not know exists, or a configuration it has not checked.

Dark Reading also reported that social engineering and phishing together accounted for 49% of the vectors respondents considered to have the best return on hacking investment. That is a separate survey result about attack vectors, not part of the perimeter-vulnerability timing figure. Dark Reading’s coverage quotes Bishop Fox’s Tom Eston saying the speed was not surprising to him as an ethical hacker, particularly given social engineering and phishing. His observation is context, not independent validation of a universal attacker timeline.

How to use the finding defensively

The practical response is not to assume a breach will happen on a particular clock. Use the result as a reason to reduce avoidable exposure and prepare to identify and contain incidents:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Maintain an accurate external-asset inventory. Identify internet-facing hosts, web services, domains, and cloud assets, including systems owned by teams outside central IT.
  • Review exposure regularly. Check for unnecessary public services, vulnerable software, and risky configurations; prioritize remediation by exposure and potential impact.
  • Test detection and response. Verify that alerts reach people who can investigate them, and rehearse how the organization would isolate affected systems, preserve evidence, and escalate an incident.
  • Plan for human-driven entry. Because the survey also highlighted phishing and social engineering, combine technical controls with clear reporting routes and response procedures for suspicious messages or clicks.

These are defensive implications of the reported exposures and readiness concerns, not a claim that the survey tested or proved the effectiveness of any particular control. Bishop Fox describes penetration testing and attack-surface testing as services; that is vendor information rather than independent evidence that a service will prevent incidents. Bishop Fox’s overview discusses its offerings alongside the survey.

Rank #3
Sale
Hacking: The Art of Exploitation, 2nd Edition
  • Easy to read text
  • It can be a gift option
  • This product will be an excellent pick for you
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why other attack-time statistics are not equivalent

Dark Reading’s article also mentions separate measurements from other firms: CrowdStrike’s finding that average breakout from initial compromise to other systems took less than 90 minutes, and Mandiant’s historical dwell-time figure of 21 days in 2021, compared with 24 days in the prior year. Those figures describe different populations, methods, and stages of an incident. They do not confirm or refute the ethical-hacker survey’s less-than-10-hours result.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.