Why Are Half The Breaches Are Found by Someone Outside the Team

Internal security detection had a genuinely good year in 2025. According to Mandiant’s M-Trends 2026 report, organizations caught 52% of breaches internally, up sharply from 43% the year before. That’s a real result, and it reflects real investment in security operations center (SOC) capability, monitoring, and tooling.

It’s also, on its own, the wrong headline to take away from the report. Look at the rest of the number: 48% of breaches, very nearly half were still discovered by someone other than the security team. 34% came from an external entity flagging the problem. 14% came from the attacker themselves, disclosing the compromise on their own terms, usually via a ransomware note. And underneath the improved topline, median dwell time (how long an intruder sits undetected inside a network) actually rose in 2025, from 11 days to 14, with Mandiant specifically flagging a growing number of intrusions that go unnoticed for one to six months.

What Internal Teams Are Built to Catch

A SOC doesn’t detect “an attack” in the abstract. It detects deviations from a defined baseline for instance; known malware signatures, known behavioral patterns, known attack chains that match a rule someone already wrote. Every dollar of the recent detection improvement Mandiant measured went into getting better at exactly that: faster alerting, better correlation, more coverage of known indicators. That investment is real and it worked, which is precisely why internal detection jumped nine points in a single year.

But a system built to recognize known patterns has a hard ceiling,  you cannot write a detection rule for a pattern you have never seen. The 14% of breaches that adversaries disclosed themselves, and a meaningful share of the 34% that came from an external party, are cases where nothing inside the organization’s own telemetry looked wrong because the activity genuinely didn’t resemble the organization’s model of “bad” until the damage was already done.

Why the Undetected Cases Keep Getting Longer

This is the part of the 2026 data that should worry security leaders more than the headline improvement reassures them. Median dwell time didn’t fall alongside better detection, it rose. And the specific growth Mandiant called out was in the long tail: intrusions that stay hidden for months, driven disproportionately by espionage-motivated actors and insider threats, the two categories of intrusion built from the ground up to look like nothing at all.

That’s the known-problem trap operating exactly as the name suggests. A sophisticated or insider actor isn’t trying to beat your detection rules head-on; they’re operating in the space your detection rules were never written to cover, because that space doesn’t look like an incident yet. The better an internal team gets at catching everything that matches a known signature, the more the remaining, undetected cases skew toward exactly the kind of activity no internal system was built to flag. Improvement at the top of the funnel doesn’t shrink the blind spot underneath it. It concentrates the blind spot.

Why an Outside Vantage Point Keeps Catching What Internal Teams Miss

This is also why external notification hasn’t disappeared as internal capability improved and why it likely won’t. An outside party, whether a vendor, a customer, a partner, or an independent reviewer, isn’t operating from the same baseline model of “normal” that the internal team built. They notice a downstream customer’s data appearing somewhere it shouldn’t, a vendor flags anomalous access to a shared system, a third-party audit surfaces something buried too deep in day-to-day operations to trip an internal alert. None of that requires the outside party to be more skilled than the internal team. It requires them to be looking from a different position, with a different set of assumptions about what normal looks like, which is exactly the vantage point an internal team can’t hold on itself.

That’s a pattern worth generalizing beyond security specifically, because it shows up anywhere an organization is asked to detect problems in its own output: the reviewer closest to the work is the best-positioned to catch the errors that look like errors, and the worst-positioned to catch the ones that don’t. An organization pairing its internal team with a structurally different, external vantage point isn’t admitting its internal capability is weak. It’s acknowledging that internal and external reviews are built to catch two different categories of failure, and neither one substitutes for the other.

 

Leave a Reply

Your email address will not be published. Required fields are marked *