Detection Is Not Containment: A 168-Hour Model of Alert-to-Enforcement Latency in IT and OT

Security programs frequently treat a detected event as a controlled event. The two are not equivalent. A SIEM, IDS, endpoint product, or operations dashboard may produce a correct signal, yet the environment stays exposed until a person or a preauthorized control changes the state of the affected identity, endpoint, network path, application, or process. This paper treats that post-detection interval as a distinct engineering problem, and it argues a blunt conclusion from the result: detection is not containment, and a security portfolio whose return-on-investment case is weighted toward detection purchases knowledge of breaches rather than prevention of them. The paper defines alert-to-enforcement latency (AEL), time to enforcement (TTE), and time to verified containment (TVC); synthesizes standards, peer-reviewed security-operations research, government assessments, and 2024-2026 incident datasets; and models response across the full 168-hour week using 500,000 Monte Carlo trials per scenario with transparent triangular stage assumptions. Under the modeled assumptions, a mature 24x7 SOC with endpoint telemetry and preauthorized isolation applies containment in a median 1.03 hours and verifies it in 1.39 hours, yet applies only 0.07% of actions inside the 29-minute average attacker breakout window. Business-hours IT with email alerts and endpoint coverage needs a median 12.6 hours to verified containment, with a 90th percentile of 51.0 hours. A continuously staffed OT operations center still models at 13.5 hours median to verified containment, because process validation, authority, and safe implementation remain separate from alarm monitoring. Only high-confidence, preauthorized, bounded automation fits inside observed attacker windows, at a median 7.4 minutes to enforcement. The measured field record matches the model: attacker breakout in 29 minutes and criminal access hand-off in 22 seconds against a 14-day median dwell and a 247-day mean identify-and-contain lifecycle that reversed five years of improvement. Four canonical incidents—Target, Equifax, Colonial Pipeline, and Change Healthcare—show the pipeline failing in the field exactly where the model says it fails. Detection remains essential for unknown threats, hunting, evidence, recovery, and control validation. It is not protection, and it should not be funded as if it were.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-08-25
DOI
https://doi.org/10.5281/zenodo.22100402
Citations
2
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
36.48
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Detection Is Not Containment: A 168-Hour Model of Alert-to-Enforcement Latency in IT and OT

Francesco Trama
2 citations
Zenodo (CERN European Organization for Nuclear Research)
Information and Cyber Security
36.48
article

Detection Is Not Containment: A 168-Hour Model of Alert-to-Enforcement Latency in IT and OT

Francesco Trama
article en
2 citations

Abstract

Security programs frequently treat a detected event as a controlled event. The two are not equivalent. A SIEM, IDS, endpoint product, or operations dashboard may produce a correct signal, yet the environment stays exposed until a person or a preauthorized control changes the state of the affected identity, endpoint, network path, application, or process. This paper treats that post-detection interval as a distinct engineering problem, and it argues a blunt conclusion from the result: detection is not containment, and a security portfolio whose return-on-investment case is weighted toward detection purchases knowledge of breaches rather than prevention of them. The paper defines alert-to-enforcement latency (AEL), time to enforcement (TTE), and time to verified containment (TVC); synthesizes standards, peer-reviewed security-operations research, government assessments, and 2024-2026 incident datasets; and models response across the full 168-hour week using 500,000 Monte Carlo trials per scenario with transparent triangular stage assumptions. Under the modeled assumptions, a mature 24x7 SOC with endpoint telemetry and preauthorized isolation applies containment in a median 1.03 hours and verifies it in 1.39 hours, yet applies only 0.07% of actions inside the 29-minute average attacker breakout window. Business-hours IT with email alerts and endpoint coverage needs a median 12.6 hours to verified containment, with a 90th percentile of 51.0 hours. A continuously staffed OT operations center still models at 13.5 hours median to verified containment, because process validation, authority, and safe implementation remain separate from alarm monitoring. Only high-confidence, preauthorized, bounded automation fits inside observed attacker windows, at a median 7.4 minutes to enforcement. The measured field record matches the model: attacker breakout in 29 minutes and criminal access hand-off in 22 seconds against a 14-day median dwell and a 247-day mean identify-and-contain lifecycle that reversed five years of improvement. Four canonical incidents—Target, Equifax, Colonial Pipeline, and Change Healthcare—show the pipeline failing in the field exactly where the model says it fails. Detection remains essential for unknown threats, hunting, evidence, recovery, and control validation. It is not protection, and it should not be funded as if it were.

Zenodo (CERN European Organization for Nuclear Research)
Fundação de Amparo à Pesquisa do Estado do Rio Grande do Sul (BR)
Peace, Justice and strong institutions
Openalex Percentile: Top 0%
Information and Cyber Security
36.48
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.