A compromise assessment is a point-in-time, forensically supported investigation of an IT environment for traces of active or past compromises. It follows the "assume breach" principle: what is examined is not the absence of vulnerabilities but the presence or absence of attacker activity – on endpoints and servers, in identity services, and in network and cloud logs. The investigation is limited in time and delivers a snapshot for a defined scope and observation period. It replaces neither continuous detection nor a security operations center; rather, it answers a point-in-time question that day-to-day operations alone cannot answer.
Compromise Assessment: tracking down hidden attackers
How forensic methods give you a reliable answer to whether your IT environment is currently compromised or was compromised in the past – and what consequences follow from that.
14 daysglobal median dwell time in 2025 – per M-Trends 2026
52%of investigated incidents were detected internally – no more than that
10%prior compromise – third most common initial attack vector
30%prior-compromise share in ransomware cases
Attackers often move through corporate networks undetected for weeks: according to Mandiant M-Trends 2026, the global median dwell time in 2025 was 14 days – significantly longer for espionage operations – and only 52% of the incidents investigated were detected internally. A compromise assessment therefore reverses the usual assessment perspective: instead of asking where an attacker could break in, forensic methods are used to determine whether a compromise has already taken place ("assume breach"). Typical triggers include corporate acquisitions, concrete grounds for suspicion, the follow-up to security incidents, or questions from cyber insurers. The result is a documented, evidence-based statement on the compromise status, together with prioritized recommendations for hardening and detection.
The Essentials at a Glance
Six topic blocks — tap to expand.
Typical Triggers
Four situations in which a compromise assessment is commissioned – tap a trigger.
- Before integration, the buyer verifies whether it is taking over an existing compromise along with the target company.
- According to M-Trends 2026, a prior compromise was the third most common initial attack vector at 10% – rising to 30% in ransomware cases.
Mergers & acquisitionsPrior compromiseRansomware
- Triggers include notifications from authorities or CERTs, anomalous telemetry, or an extortion message.
AuthoritiesCERTsAnomalous telemetryExtortion message
- After a security incident has been handled, the assessment demonstrates before systems go back online that no residual access remains.
- A building block of incident handling, which NIS2, for instance, requires of affected entities in Art. 21(2)(b).
Residual accessIncident handlingNIS2 Art. 21(2)(b)
- During risk dialogues or after a claim, for example, a documented compromise status may be required or helpful.
Cyber insuranceRisk dialogueClaimCompromise status
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
M-Trends 2026
Median dwell time of 14 days (2025), 52% internal detection, "prior compromise" as the third most common initial vector (10%) – the data basis for the relevance of compromise assessments.
NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management
Current reference (April 2025, replaces Rev. 2) for integrating incident response into risk management – relevant for the transition from assessment to incident response.
MITRE ATT&CK
Knowledge base of tactics, techniques, and procedures (TTPs), currently at version v19 (April 2026) – the foundation of TTP-based sweeps in a compromise assessment.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2)(b) requires measures for handling security incidents – the anchor point for compromise assessments in cases of suspicion and post-incident follow-up.
IT-Grundschutz-Kompendium (Edition 2023), Baustein DER.2.2 „Vorsorge für die IT-Forensik“
Requirements for forensic readiness (data sources, evidence preservation) that significantly determine the quality and validity of a compromise assessment.
Want to clarify the compromise status of your environment?
In a no-obligation initial consultation, we will jointly define the scope, the available data, and the appropriate depth of investigation for a compromise assessment in your environment.