Every ransomware attack starts the same way: An attacker finds a way in. That could be via stolen credentials, a phishing email, an exposed remote desktop connection, or an unpatched vulnerability. TTR starts counting the moment that access happens, and it stops the moment ransomware is deployed.
In between those two points, threat actors are busy. They might move laterally across the network, escalate their privileges, disable security tools, dump credentials, or steal data before they ever trigger the ransomware payload. According to Huntress' 2026 Cyber Threat Report, the average TTR across security incidents was almost 17 hours, with ransomware groups taking an average of 18 actions before triggering the ransomware payload.
That average hides a lot of variation, though. Some attackers had a TTR average of just over four hours after gaining initial access, which means every minute counts once a threat actor is inside. TTR is closely related to a concept called dwell time—the length of time an attacker remains in your environment before they're detected and removed.
Federal guidance from the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC), including their joint #StopRansomware Guide, focuses on reducing both the likelihood and impact of ransomware and data extortion incidents through preparation, prevention, and response best practices.
Why TTR keeps shrinking
Threat actors don't all work the same way, and their TTR reflects that. Some groups favor speed. They go in already knowing what tools and defenses a target relies on, deploy ransomware quickly, and then pressure the victim to pay before the security team can react. Other groups take a slower, more deliberate approach, spending more time inside the network to steal data, disable backups, or clear logs before triggering encryption.
A few things are pushing average TTR down across the board:
- Prebuilt attack playbooks. Many ransomware groups follow tried-and-true methods, which cuts down on the guesswork and time needed to move through a network.
- Automation. Faster, more automated tools mean fewer manual steps between gaining access and deploying ransomware.
- Defense evasion. Some threat actors intentionally speed up their timeline specifically because they suspect security tools might catch them if they linger too long.
- Ransomware-as-a-Service (RaaS). Affiliates using RaaS kits often follow standardized, fast-moving processes built by the ransomware developers they work with.