Dwell Time: Why Attackers Sit Inside Networks for Weeks

Cyberattacks on healthcare organizations often look sudden. One morning the systems are locked, or a notice arrives that data has been stolen. But the attacker rarely arrived that morning. In many incidents, the intruder had been inside the network for days or weeks, exploring quietly, collecting information and preparing the moment of greatest impact.

The period between the first unauthorized access and its discovery is called dwell time. The shorter it is, the less damage an attacker can do. This post explains what attackers do during that time and the practical measures that help a small or mid-size organization find them sooner.

What dwell time means

Dwell time is the gap between when an attacker first gets in and when you detect them. Ideally, that is minutes. In practice, it varies widely, and security reports regularly show that intrusions can go unnoticed for a long stretch. Because the number depends on the incident and the organization, avoid relying on any single figure. The key point is that a longer stay generally gives an attacker more opportunity.

What attackers do while they wait

An attacker who gets in through a stolen password or a phishing email rarely strikes immediately. Typical activities include:

Learning the environment. Mapping systems, servers, shared drives and user accounts.

Gaining more access. Looking for administrator credentials, so they can move beyond the first account.

Moving sideways. Reaching other computers and servers across the network.

Finding valuable data. Locating records, financial files and backups.

Disabling protections. Turning off security tools or tampering with backups to make recovery harder.

Stealing data. Copying files out of the network quietly, sometimes before any ransomware is deployed.

Setting up persistence. Creating hidden accounts or tools that let them return even if one entry point is closed.

Choosing the moment. Many ransomware attacks are launched at nights, weekends or holidays when fewer people are watching.

Healthcare organizations are attractive targets because data is sensitive and downtime affects care. Small organizations with limited IT staff may be especially exposed because no one is watching the logs.

Why intruders go unnoticed

Nobody reviews the logs, or the logs are not kept long enough.

Alerts are noisy, so important ones are missed.

Old accounts and shared logins blend in with normal activity.

Antivirus alone does not catch attackers using legitimate tools and valid passwords.

Unmanaged devices and forgotten servers sit outside normal monitoring.

Practices that shorten dwell time

Turn on and keep logs

Make sure your email platform, identity system, firewall and key servers record activity, and that the records are retained long enough to investigate. You cannot detect or investigate what was never recorded.

Monitor sign-ins

Watch for unusual sign-ins: unfamiliar locations, impossible travel, sign-ins at odd hours, repeated failures followed by a success and new devices. Many identity platforms can alert on these patterns.

Use endpoint detection and response

Modern endpoint tools watch behavior on computers and servers, not just known malware. When combined with someone who actually responds to the alerts, they can catch an intruder's movements early.

Consider managed detection and response

Small organizations rarely have staff watching alerts around the clock. A managed service can supply that coverage. Ask exactly what is monitored, how fast they respond and what they are authorized to do.

Watch for warning signs inside email

Unexpected forwarding rules, new mail permissions and strange messages sent from staff accounts are common signs of compromise. Check for them regularly.

Limit privileges and segment the network

When accounts have only the access they need, and critical systems are separated, an intruder has fewer places to go. Use separate administrator accounts, protect them with strong multi-factor authentication and keep them from being used for everyday work.

Keep an inventory

You cannot protect what you do not know you have. Maintain a list of devices, servers, accounts and cloud services, and retire what you no longer use.

Patch and reduce exposure

Keep systems updated, especially anything reachable from the internet. Close ports and remote access paths that are not needed. CISA publishes guidance and a list of known exploited vulnerabilities that can help you prioritize.

Protect and test backups

Keep backups separate from the main network and test restoring them. Attackers often look for backups first.

Practice your response

An incident response plan, with contacts and decision-makers identified in advance, shortens the time between detection and action.

Signs to take seriously

Investigate promptly if you see accounts locked unexpectedly, security tools turned off, unfamiliar administrator accounts, unusual data transfers, slow systems for no clear reason or staff reporting strange prompts or messages.

Bringing dwell time down

No organization can prevent every intrusion, but you can make hiding harder. UnityCare IT helps healthcare organizations set up logging, sign-in monitoring and response processes, so unusual activity is noticed in hours instead of weeks.

Related service

Wi-Fi, switching, firewalls and internet that hold up across a whole facility.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172