Independent newsroom The Wyre News Network OpEd desk

Analysis 6 min read

Twenty-Five Minutes

In May 2025 Unit 42 simulated a ransomware operation from initial compromise to data exfiltration in 25 minutes, calling it a 100x increase in speed powered entirely by AI. The 25 minutes is the number that gets quoted and it is the less important half. The important half is what the exfiltration agent did when a control worked: blocked mid-transfer, it self-prompts, switches to embedding the data in outbound OneDrive syncs, and resumes. A control fired, caught a live exfiltration, stopped that channel, and bought nothing. Defensive architecture has never assumed controls hold, only that a control which fires buys time, and that assumption carries the whole response function. Nine months later Unit 42's incident report, drawn from 750 real intrusions across 50 countries, put the fastest observed attackers at 72 minutes from access to exfiltration, four times faster than the year before. Meanwhile 90 percent of surveyed security leaders are confident of their recovery objectives and 28 percent of ransomware victims fully recovered their data. Why confidence is being reported as evidence, why recovery quietly became the primary defence, and the unglamorous weekend exercise that turns a target into a fact.

In May 2025, Palo Alto Networks' Unit 42 published the result of an experiment. Using AI at every stage of the attack chain, it simulated a ransomware operation from initial compromise to data exfiltration in 25 minutes. Its own framing was blunt: "That's a 100x increase in speed, powered entirely by AI."

The 25 minutes is the number that gets quoted, and it is the less important half of the result.

The important half is what the exfiltration agent did when a control worked. In Unit 42's description: "When the channel is blocked midtransfer, it self-prompts, switches to embedding data in outbound OneDrive syncs, and resumes."

Read that sentence again from the defender's side

A control fired. It was the right control, it caught a live exfiltration in progress, and it stopped that channel. By every conventional measure it worked.

The agent then re-planned without being asked, moved the data into traffic that looks like ordinary corporate file syncing, and carried on. No operator was woken. No second tool was needed. The gap between the block and the workaround was the time it takes a model to produce a few hundred tokens.

Defensive architecture has never assumed controls hold. It assumes something weaker and entirely reasonable: that a control which fires buys time. That is the assumption underneath the whole response function, from alert routing to escalation tiers to what counts as an acceptable on-call rotation. It is why "we detected it and contained it" is a sentence that normally means something.

What the simulation demonstrated is not a control failing. It is a control succeeding and purchasing nothing.

The lab number stopped being hypothetical

It would be easy to file a 2025 red-team exercise under interesting-but-staged. The following February, Unit 42 published its 2026 Global Incident Response Report, drawn from more than 750 major incidents across over 50 countries. It reports that "in the fastest cases we investigated, attackers needed just 72 minutes to move from initial access to data exfiltration, 4X faster than last year."

Seventy-two minutes is not 25. But it is real rather than simulated, it is a fourfold acceleration in a single year, and the direction of travel between the laboratory bound and the observed floor is only going one way.

The same report notes that "identity weaknesses played a material role in nearly 90% of our investigations," with attackers logging in using stolen credentials and tokens rather than exploiting vulnerabilities. That detail matters later.

What organisations believe about themselves

Set the trend against how prepared people say they are. In a survey of more than 900 security leaders reported in Veeam's Data Trust and Resilience Report, 90 percent said they were very or extremely confident they could meet their defined recovery time objectives. Sixty-nine percent said those objectives were fully aligned with business continuity goals.

Now set it against what happened to those actually tested. Among organisations that suffered an incident in the previous twelve months, more than 40 percent reported customer or service disruption, 41 percent reported financial loss or revenue impact, and 38 percent experienced extended downtime of critical systems. For ransomware specifically, only 28 percent fully recovered all affected data, and 29 percent ended with loss, downtime or disruption they could not undo.

Ninety percent confident. Twenty-eight percent whole.

Confidence is being reported as though it were evidence

Reading that gap as overconfidence is true and not very useful. The more precise reading is that most organisations have never produced the evidence that would let them hold a calibrated view at all.

A recovery time objective is a target. It becomes a capability only once somebody has restored the systems in question, from the backups that actually exist, using the runbook as written, with the staff who would really be on shift, inside the stated window. Short of that, the figure in the continuity plan rests on four separate assumptions: that the backup jobs completed, that the data is intact and restorable, that the procedures are current, and that people can execute them under pressure.

Each is individually plausible. The chance that all four hold at once, never having been checked, is not the number anyone imagines. A plan that has never failed in rehearsal has not been shown to work. It has been shown never to have been rehearsed.

Why the speed changes the arithmetic rather than the advice

While intrusions unfolded over days, an untested recovery plan was a survivable risk. There was room to find the gap during the incident and improvise around it, because the adversary was also improvising, also sleeping, also waiting on a human being.

At machine speed the slack disappears from one side only. The attack re-plans in the time an alert takes to route. The defence still has to wake somebody, convene a call, find the runbook, and discover on the call that it references a system decommissioned in March.

So recovery has quietly moved from being the fallback to being the primary defence, without a matching move in where the evidence sits. Prevention budgets still buy real value. They simply buy less of the specific thing they used to buy, which was time.

What would actually change the position

Boards are shifting from mean time to detect toward mean time to recover, which is the right direction. The useful discipline is narrower than a metric.

Start with identity, and note that this is now an evidenced priority rather than a preference: if identity weaknesses are material in nearly nine of ten investigated incidents, then the identity provider is both the most likely entry point and the system every other recovery depends on. Restoring a database into an environment where nobody can authenticate is not a recovery.

Then take the systems everything else rests on, which in most organisations means identity, the primary databases, and whatever runs the money. Restore them from backup into an isolated environment, on the clock, using the current runbook and people who have not seen the exercise in advance. Record the real elapsed time and compare it with the published objective. Do it before anyone certifies that objective in a filing or an insurance application.

The exercise is unglamorous, it costs a weekend, and it is the only thing that turns a target into a fact. Everything else, including a 90 percent confidence reading from a room of experienced people, describes what an organisation believes rather than what it can do.

An agent needed 25 minutes in a laboratory and routed around the one control that stopped it. Real attackers are at 72 and moving four times faster than they were a year ago. The reasonable question on Monday is not whether the perimeter would hold. It is how long the restore takes, and whether anybody in the building has ever actually measured it.

Sources

  • Sam Rubin, Palo Alto Networks Unit 42, "Unit 42 Develops Agentic AI Attack Framework", 14 May 2025. Source for the simulated ransomware attack completed from initial compromise to data exfiltration in 25 minutes, for the quoted characterisation of that as a 100x increase in speed, and for the exfiltration agent's behaviour on being blocked, quoted verbatim: "When the channel is blocked midtransfer, it self-prompts, switches to embedding data in outbound OneDrive syncs, and resumes." This was a controlled simulation by a vendor with a commercial interest in the finding, and it is treated here as a demonstration of what is possible rather than as a measurement of what is typical.
  • Palo Alto Networks Unit 42, 2026 Global Incident Response Report, 17 February 2026, drawn from more than 750 major incidents across over 50 countries. Source for "in the fastest cases we investigated, attackers needed just 72 minutes to move from initial access to data exfiltration, 4X faster than last year," and for "identity weaknesses played a material role in nearly 90% of our investigations." The full report is published separately.
  • Veeam, Data Trust and Resilience Report, as reported in "2026 Cyber Resilience Trends: Where Confidence Meets Reality". Source for the survey of more than 900 security leaders, the 90 percent confidence and 69 percent alignment figures, the incident outcomes over the previous twelve months, and the ransomware recovery figures of 28 percent fully recovered and 29 percent left with damage they could not undo. These reach us through that secondary account rather than from the report read directly, and the survey's field dates are not stated there.

Wyre's opinion bylines are editorial personas of Floof Digital LLC, not separate members of staff. Essays are produced with AI assistance under human editorial direction. How Wyre works.

More Opinion

From the same desk

Analysis

The Lawsuit That Names Its Victims

Sony Music and Warner have sued Anthropic, alleging what the labels call a "brazen campaign" of intellectual property theft and "one of the largest and most blatant ongoing thefts of intellectual property in history." What sets this complaint apart from earlier AI copyright litigation is not the size of the claim but its shape: rather than gesturing at training data in the abstract, the labels frame their case around specific tracks and specific dates, turning a philosophical argument about fair use into a set of facts that can be checked, contested and produced in discovery. That distinction matters more than it might seem, because Anthropic's conduct elsewhere this year, from a Claude Code limit change that reads as a raise but functions as a cut, to employee sentiment souring inside the company, suggests an organisation already uncomfortable defending decisions in detail.

4 min

Analysis

Nobody Asked to Skip the Links

Google has removed the "Show More" button that used to sit beneath AI Overviews, the one small control that let a searcher push past the AI summary toward ordinary links. At the same time, AI Overviews are expanding into more queries and a judge is asking pointed questions about the fallout from Google's AI rollout and spam updates. Put those two things side by side and the argument writes itself: a company facing legal scrutiny over how much control it holds over search just narrowed the one interface choice that acknowledged users might not want its AI answer. Nobody asked for that button to disappear. Its removal doesn't settle the market power question in a courtroom, it settles it in the product, before any ruling arrives.

4 min

Essay

The Inauspicious Zone

Roughly one Chinese county in sixteen sits, at any given moment, in a direction its city's mayor has been told is unlucky for him personally, and those counties record about 2 percent lower GDP than the rest of the same city. The reason the finding is worth an hour is not the superstition but the identification strategy: unfavourable orientations derived from birth details in official yearbooks, a compass laid over a map, the place held constant while only the private belief of the person allocating money varies. Nothing supernatural is claimed. The effect runs through reduced policy support and public investment, compounding into 6 percent lower firm entry and 4 percent lower productivity among the firms that stay. Why the contrast between mayors and party secretaries is what makes it credible, why the measured 2 percent is not an upper bound on this class of problem but the one instance where it happened to be measurable, and the question most organisations cannot answer about how their own would ever be found.

7 min