Detection Is Not Containment: A 168-Hour Model of Alert-to-Enforcement Latency in IT and OT
Security programs frequently treat a detected event as a controlled event. The two are not equivalent. A SIEM, IDS, endpoint product, or operations dashboard may produce a correct signal, yet the environment stays exposed until a person or a preauthorized control changes the state of the affected identity, endpoint, network path, application, or process. This paper treats that post-detection interval as a distinct engineering problem, and it argues a blunt conclusion from the result: detection is not containment, and a security portfolio whose return-on-investment case is weighted toward detection purchases knowledge of breaches rather than prevention of them. The paper defines alert-to-enforcement latency (AEL), time to enforcement (TTE), and time to verified containment (TVC); synthesizes standards, peer-reviewed security-operations research, government assessments, and 2024-2026 incident datasets; and models response across the full 168-hour week using 500,000 Monte Carlo trials per scenario with transparent triangular stage assumptions. Under the modeled assumptions, a mature 24x7 SOC with endpoint telemetry and preauthorized isolation applies containment in a median 1.03 hours and verifies it in 1.39 hours, yet applies only 0.07% of actions inside the 29-minute average attacker breakout window. Business-hours IT with email alerts and endpoint coverage needs a median 12.6 hours to verified containment, with a 90th percentile of 51.0 hours. A continuously staffed OT operations center still models at 13.5 hours median to verified containment, because process validation, authority, and safe implementation remain separate from alarm monitoring. Only high-confidence, preauthorized, bounded automation fits inside observed attacker windows, at a median 7.4 minutes to enforcement. The measured field record matches the model: attacker breakout in 29 minutes and criminal access hand-off in 22 seconds against a 14-day median dwell and a 247-day mean identify-and-contain lifecycle that reversed five years of improvement. Four canonical incidents—Target, Equifax, Colonial Pipeline, and Change Healthcare—show the pipeline failing in the field exactly where the model says it fails. Detection remains essential for unknown threats, hunting, evidence, recovery, and control validation. It is not protection, and it should not be funded as if it were.
Authors
- Francesco Trama (ORCID: https://orcid.org/0009-0004-8437-6351)
Institutions
- Fundação de Amparo à Pesquisa do Estado do Rio Grande do Sul (BR)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-08-25
- DOI
- https://doi.org/10.5281/zenodo.22100402
- Citations
- 2
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 36.48