Book an Appointment

Compromise Assessment: tracking down hidden attackers

How forensic methods give you a reliable answer to whether your IT environment is currently compromised or was compromised in the past – and what consequences follow from that.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

14 daysglobal median dwell time in 2025 – per M-Trends 2026
52%of investigated incidents were detected internally – no more than that
10%prior compromise – third most common initial attack vector
30%prior-compromise share in ransomware cases

Attackers often move through corporate networks undetected for weeks: according to Mandiant M-Trends 2026, the global median dwell time in 2025 was 14 days – significantly longer for espionage operations – and only 52% of the incidents investigated were detected internally. A compromise assessment therefore reverses the usual assessment perspective: instead of asking where an attacker could break in, forensic methods are used to determine whether a compromise has already taken place ("assume breach"). Typical triggers include corporate acquisitions, concrete grounds for suspicion, the follow-up to security incidents, or questions from cyber insurers. The result is a documented, evidence-based statement on the compromise status, together with prioritized recommendations for hardening and detection.

The Essentials at a Glance

Six topic blocks — tap to expand.

Typical Triggers

Four situations in which a compromise assessment is commissioned – tap a trigger.

10% prior compromise
  • Before integration, the buyer verifies whether it is taking over an existing compromise along with the target company.
  • According to M-Trends 2026, a prior compromise was the third most common initial attack vector at 10% – rising to 30% in ransomware cases.
Mergers & acquisitionsPrior compromiseRansomware

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Mandiant (Google Cloud) · 2026

M-Trends 2026

Median dwell time of 14 days (2025), 52% internal detection, "prior compromise" as the third most common initial vector (10%) – the data basis for the relevance of compromise assessments.

NIST · 2025

NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Current reference (April 2025, replaces Rev. 2) for integrating incident response into risk management – relevant for the transition from assessment to incident response.

MITRE · 2026

MITRE ATT&CK

Knowledge base of tactics, techniques, and procedures (TTPs), currently at version v19 (April 2026) – the foundation of TTP-based sweeps in a compromise assessment.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2)(b) requires measures for handling security incidents – the anchor point for compromise assessments in cases of suspicion and post-incident follow-up.

BSI · 2023

IT-Grundschutz-Kompendium (Edition 2023), Baustein DER.2.2 „Vorsorge für die IT-Forensik“

Requirements for forensic readiness (data sources, evidence preservation) that significantly determine the quality and validity of a compromise assessment.

Want to clarify the compromise status of your environment?

In a no-obligation initial consultation, we will jointly define the scope, the available data, and the appropriate depth of investigation for a compromise assessment in your environment.