Mean-Time-to-Adapt: The Only Clock That Matters Now

mean-time-to-adapt

Schedule a Portnox Cloud demo today.

Contents

Mean-Time-to-Adapt: The Only Clock That Matters Now 

The average enterprise breach still takes 241 days to detect and contain, 181 days to identify, and 60 more to shut down, according to IBM’s Cost of a Data Breach Report. That number has barely moved in years, and most security programs are still built around shrinking it.

Attackers aren’t waiting around for that clock to run out. CrowdStrike’s 2026 Global Threat Report found that breakout time, the window an attacker needs to pivot from a first compromised host to a second, has fallen to just 29 minutes, down from 48 minutes in 2024 and 98 in 2021. The fastest recorded breakout took only 27 seconds. In one case, data exfiltration began four minutes after initial access.

Your Calendar vs. Their Stopwatch

Two clocks, two very different speeds. Security teams are still measuring themselves against a calendar. Attackers are operating on a stopwatch. That mismatch is the real problem. The real question isn’t whether machines are outpacing people, and by the way, the answer is, they are. It’s whether a human can still be in the loop by the time it matters and at 29 minutes, that window is closing fast.

You Can Patch. You Just Can’t Patch Fast Enough.

Our previous article in this series, Mythos and the Death of the Patch Window, covered how AI-driven vulnerability discovery, put on full display by Anthropic’s Claude Mythos Preview, is compressing the time between a flaw being found and a working exploit being built. AI can uncover thousands of high-severity vulnerabilities and build functioning exploits on the first attempt. More often than not, the clock the business used to rely on before an exploit turned into real damage simply isn’t there anymore.

Some Devices Were Never Meant to be Patched

That piece landed on a hard truth: some devices, legacy systems, unmanaged endpoints, medical devices, industrial control systems, will never be patched in time. And my favorite ‘your IoT is out to get you‘ story, the fish tank incident, still holds up as a warning. Some devices simply aren’t built to be updated. That’s not a reason to give up on the device. It’s a reason to control what it can access instead.

Patch Speed was Always a Proxy

So, if patching isn’t the finish line, what is? The honest answer is that it never really was. Patch speed was always a stand-in for the real thing that mattered: how long a system stayed exposed before someone closed the door. This isn’t a hypothetical strain. CVE submissions surged 263% between 2020 and 2025, growth so steep that NIST shifted the National Vulnerability Database to a triage model in April 2026, meaning it can no longer enrich every submission that comes in. The volume problem was already outpacing defenders before AI entered the picture. Mythos-class capabilities are set to compound it, adding machine speed on top of a system already buckling under volume.

AI Assisted Attacks Have Lowered the Skill Bar

That stand-in metric, patch speed, only worked as a measure of risk because of two assumptions: exploitation took time, and exploiting a fresh CVE required real skill. AI-driven vulnerability discovery is breaking both. It isn’t only compressing the timeline for sophisticated actors, it’s lowering the skill floor required to find and exploit a vulnerability at all. The big truth we all need to wrap our security strategies around is: an attacker who couldn’t have built a working exploit a year ago can now get there by prompting the right model. That doesn’t just make the fastest attackers faster, it expands who counts as a credible attacker in the first place. Imagine all the things an AI-assisted attacker can get into in 29 minutes.

Defining Mean-Time-to-Adapt

Let’s call it what it is: mean-time-to-adapt, the average time between an identity or device becoming untrustworthy and its access actually being restricted. Not detected. Not flagged for review. Restricted.

This is different from the metrics security teams already track. Mean-time-to-detect and mean-time-to-patch are about finding and fixing a known problem. Mean-time-to-contain, in the traditional incident response sense, kicks in only after a breach is confirmed, still a reactive measure, still running on the defender’s calendar. Mean-time-to-adapt is continuous. It doesn’t wait for a ticket, an alert triage, or a change window. It asks a simpler question: if something on this network stopped being trustworthy right now, how long would it take to lose its access?

That question only means something if it’s measured against the attacker’s clock. A security program that can restrict access in a day looks reasonably fast next to a 241-day breach lifecycle. It looks nowhere close to fast enough next to a 29-minute breakout. Mean-time-to-adapt has to be measured in the same unit attackers are already operating in: minutes, not months.

Three Things That Move the Needle

Shrinking mean-time-to-adapt isn’t about working harder inside the old model. It requires a few specific capabilities, the kind built to keep a problem contained to one room instead of letting it spread through the whole house:

  • Continuous visibility into every device, user, and identity, including AI agents, connecting to the network and evaluated for the life of the session rather than checked once at login.
  • Automated access decisions that don’t route through a human ticket queue. If a device’s posture changes, its access should change with it.
  • Scoped access by default, so a device or identity only reaches what it needs, not the whole network by default, keeping any one compromise contained to a single room instead
    of the whole house.

This isn’t just a theoretical gap. Portnox Field CISO Garrett Gross recently examined the OpenAI/Hugging Face incident, in which AI models operating inside an internal security test escaped their sandbox and compromised Hugging Face’s production systems. He found the same problem hiding in plain sight. As Gross put it, “the thing doing the escalating wasn’t a person, or even a static service account you could point to and revoke… a model spun up thousands of short-lived processes, each one capable of independently finding and chaining vulnerabilities, with nothing resembling a fixed identity to shut off.”

Mean-time-to-adapt is meaningless if there’s no identity to act on in the first place, and agentic AI is making that gap more common, not less. None of this eliminates the value of detection or patching. It just stops treating those reactions as the primary defense and starts treating them as one layer behind a faster, proactive one.

Share

About the Author

Picture of Mandy Reyes

Mandy Reyes

Mandy Reyes has spent two decades in enterprise technology, beginning her career at Cisco Systems. She led global go-to-market for SolarWinds' Network Management portfolio and worked embedded with IBM product teams across its Automation and Security portfolios. Mandy is a senior product marketer and writes for Portnox on access control, zero trust, and passwordless authentication for the practitioners who live it.

About the Author

Picture of Mandy Reyes

Mandy Reyes

Mandy Reyes has spent two decades in enterprise technology, beginning her career at Cisco Systems. She led global go-to-market for SolarWinds' Network Management portfolio and worked embedded with IBM product teams across its Automation and Security portfolios. Mandy is a senior product marketer and writes for Portnox on access control, zero trust, and passwordless authentication for the practitioners who live it.

Related Reading

Artificial IntelligenceCyber AttacksSecurity Trends

Mythos and the Death of the Patch Window

August 26, 2026
Security Trends

Assume Misbehavior: Agentic Identity is the Latest Thing You Need to Govern

August 24, 2026
Security Trends

AI Agents Need a Birth Certificate. The Government Just Said So.

August 20, 2026

[Webinar with Forrester] The Identity Blind Spot: AI Agents & Access Control (Sept. 10)

X