• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Sophos Report: In 56% of Sophos IR and MDR Cases, adversaries logged in, instead of breaking in

by CXO Staff
April 3, 2025
in Future, News, Tech

Sophos released the 2025 Sophos Active Adversary Report, which details attacker behavior and techniques from over 400 Managed Detection and Response (MDR) and Incident Response (IR) cases in 2024

Sophos Report: In 56% of Sophos IR and MDR Cases, adversaries logged in, instead of breaking in

Sophos released the 2025 Sophos Active Adversary Report, which details attacker behavior and techniques from over 400 Managed Detection and Response (MDR) and Incident Response (IR) cases in 2024. The report found that the primary way attackers gained initial access to networks (56% of all cases across MDR and IR) was by exploiting external remote services, which includes edge devices such as firewalls and VPNs, by leveraging valid accounts.

The combination of external remote services and valid accounts aligns with the top root causes of attacks. For the second year in row, compromised credentials were the number one root cause of attacks (41% of cases). This was followed by exploited vulnerabilities (21.79%) and brute force attacks (21.07%).

Understanding the speed of attacks

When analysing MDR and IR investigations, the Sophos X-Ops team looked specifically at ransomware, data exfiltration, and data extortion cases to identify how fast attackers progressed through the stages of an attack within an organisation. In those three types of cases, the median time between the start of an attack and exfiltration was only 72.98 hours (3.04 days). Furthermore, there was only a median of 2.7 hours from exfiltration to attack detection.

“Passive security is no longer enough. While prevention is essential, rapid response is critical. Organisations must actively monitor networks and act swiftly against observed telemetry. Coordinated attacks by motivated adversaries require a coordinated defense. For many organisations, that means combining business-specific knowledge with expert-led detection and response. Our report confirms that organisations with proactive monitoring detect attacks faster and experience better outcomes,” said John Shier, field CISO.

Other key findings from the 2025 Sophos active adversary report:

  • Attackers can take control of a system in just 11 hours: The median time between attackers’ initial action and their first (often successful) attempt to breach Active Directory (AD) – arguably one of the most important assets in any Windows network – was just 11 hours. If successful, attackers can more easily take control of the organisation.
  • Top ransomware groups in Sophos cases: Akira was the most frequently encountered ransomware group in 2024, followed by Fog and LockBit (despite a multi-government takedown of LockBit earlier in the year).
  • Dwell time is down to just 2 days: Overall, dwell time – the time from the start of an attack to when it is detected – decreased from 4 days to just 2 in 2024, largely due to the addition of MDR cases to the dataset.
  • Dwell time in IR cases: Dwell time remained stable at 4 days for ransomware attacks and 11.5 days for non-ransomware cases.
  • Dwell time in MDR cases: In MDR investigations, dwell time was only 3 days for ransomware cases and just 1 day for non-ransomware cases, suggesting MDR teams are able to more quickly detect and respond to attacks.
  • Ransomware groups work overnight: In 2024, 83% of ransomware binaries were dropped outside of the targets’ local business hours.
  • Remote desktop protocol continues to dominate: RDP was involved in 84% of MDR/IR cases, making it the most frequently abused Microsoft tool.

To shore up their defenses, Sophos recommends that companies do the following:

  • Close exposed RDP ports
  • Use phishing-resistant multifactor authentication (MFA) wherever possible
  • Patch vulnerable systems in a timely manner, with a particular focus on internet-facing devices and services
  • Deploy EDR or MDR and ensure it is proactively monitored 24/7
  • Establish a comprehensive incident response plan and test it regularly through simulations or tabletop exercises

Tags: 2025 Sophos Active Adversary ReportIRMDRSophos
ShareTweet

Related Posts

Meriam ElOuazzani, Senior Regional Director, Middle East, Turkey, and Africa, SentinelOne
Feature

A day in the life of Meriam ElOuazzani

What does your morning routine look like? I start my day around 5:00 AM with a few minutes of meditation—it...

July 4, 2025
Tenable research finds rampant cloud misconfigurations exposing critical data and secrets
Future

Tenable research finds rampant cloud misconfigurations exposing critical data and secrets

Tenable released its 2025 Cloud Security Risk Report, which revealed that 9 percent of publicly accessible cloud storage contains sensitive...

July 4, 2025

Discussion about this post

Latest Issue

Meriam ElOuazzani, Senior Regional Director, Middle East, Turkey, and Africa, SentinelOne

A day in the life of Meriam ElOuazzani

July 4, 2025
Tenable research finds rampant cloud misconfigurations exposing critical data and secrets

Tenable research finds rampant cloud misconfigurations exposing critical data and secrets

July 4, 2025
How co-packaged optics boost speed and slash energy use

How co-packaged optics boost speed and slash energy use

July 3, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2024 - CXO Insight Middle East. All Rights Reserved.