Detection is not control: the time-to-action gap: Detection exposing a cyber problem while the time-to-action gap still prevents control.Detection is not control: the time-to-action gap: Detection exposing a cyber problem while the time-to-action gap still prevents control.
S10 Group Newsletter · Identity & Containment Series

Detection is not control
the time-to-action gap

Why “we saw it” does not change outcomes unless it leads to a safe move.
Newsletter #4
Published: 17 June 2026
Last updated: 9 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert

The alert is not the outcome

The previous newsletter issues looked at two related questions: what remains controllable when a critical dependency becomes unsafe, and who is actually allowed to act in the first hour. This issue picks up the next gap: even when the signal is seen, how quickly does that become a safe operational move?

There is an uncomfortable truth underneath a lot of cyber reporting.

Many organisations do not lose ransomware events because nobody noticed. They lose them because noticing did not change the situation fast enough.
Detection is not control.
Visibility only matters if it leads to a move that limits further compromise.

The pressure is still rising

Ransomware remains a persistent operational threat. BitSight’s live tracker continues to record substantial victim activity on ransomware leak sites, while Huntress describes an environment in which attackers increasingly combine encryption, data theft, disruption and pressure on customers or partners. The precise numbers will continue to change, but the leadership problem is more durable: once something gets through, can the organisation still change the course of the incident?

Prevention matters, but it is not the final control

Organisations should continue to train staff, harden systems and invest in monitoring, segmentation, backup and response. None of those measures has become less important. However, prevention and detection do not remove the need for control once an incident is active.

AI can increase the scale and plausibility of some intrusion techniques, while also adding complexity to security operations. Yet the board-level question does not depend on predicting exactly how much faster attackers will become. Every organisation already has a finite interval between receiving a credible signal and executing a consequential move. If triage, authority or technical execution consumes that interval, visibility becomes a record of attacker progress rather than a means of changing it.

The time-to-action gap

The emergency begins when visibility does not yet create control.

Because once an adversary is already moving, visibility on its own does not reassure anyone. What matters is whether visibility creates a safe move: reduce access, limit spread, interrupt malicious behaviour, and preserve enough operations to stay governable while trust is rebuilt. The Council of Europe’s ransomware risk guidance is clear that the consequences are not only financial, but also operational, legal, safety, and security related.

This is why I think the real distinction is not prevention versus detection.

It is awareness versus control.

Huntress says attackers are standardising double, triple, and even quadruple extortion tactics. BitSight says the volume is still climbing. Gartner says the operating environment is becoming more complex as AI destabilises established routines in security operations. None of that suggests a future where “we saw it” is enough on its own.

The challenge is not only that attackers are becoming more numerous. The challenge is that AI is compressing the time between discovery and exploitation. Human defenders are still coordinating meetings, approvals and investigations while machine-assisted attackers are increasingly automating analysis, targeting and adaptation. That makes the distance between seeing and stopping even more important.

The real failure is often the time-to-action gap. Not the first signal. Not the first suspicious behaviour. Not even the first alert.

The real failure is the distance between seeing attacker activity and stopping attacker progress.

That gap widens when the signal is debated, when the first move is unclear, or when the organisation has visibility but no safe containment step ready to authorise.

That is a governance problem as much as a security problem. And very quickly, it becomes a leadership one too.
How to measure the time-to-action gap
A fast alert can still be followed by a slow decision and an even slower containment move. To make that delay visible, record four timestamps during exercises and live incidents:

• when the credible signal was received;
• when the threshold for action was met;
• when containment was authorised; and
• when the containment measure became technically effective.

The first interval tests detection and triage. The second tests decision authority. The third tests execution. Reporting only the time taken to detect an incident can therefore conceal the delay that has the greatest effect on its outcome.

NIST SP 800-61 Revision 3 distinguishes Detect, Respond and Recover as separate parts of incident response. The four timestamps above translate that distinction into a practical S10 operating measure.
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details
What is “enough” evidence in your organisation to justify the first safe containment move?

Why this is also a leadership problem

None of this remains a purely technical problem for very long.

We have seen this repeatedly. In incidents such as Change Healthcare, the question quickly became larger than initial detection. The real challenge quickly became operational control, continuity and decision-making while trust in systems was being rebuilt.

In a fast-moving incident, nobody remembers that a dashboard lit up. They remember whether the organisation reduced the blast radius, protected critical operations, and stayed in control long enough to make defensible decisions. The Council of Europe notes that ransomware can lead to downtime, missed deadlines, supply-chain disruption, layoffs, and even closures. Those are not alert-quality problems. They are outcome problems.

And they are leadership problems too. Because when the signal is seen but the move is unclear, the burden shifts quickly onto people: who decides, how fast they decide, what they are willing to disrupt, and how much uncertainty they are prepared to act under.

That is where visibility stops being a security discussion and becomes a governability test.

A line I keep coming back to is this:

Detection buys awareness. Only containment buys time.

That is the difference between seeing the incident and changing its outcome. It is also why the first hour matters so much more than many reporting packs suggest. By then, the question is no longer whether the signal was technically accurate. It is whether the organisation can turn that signal into controlled action.

Most organisations do not lose the outcome because nobody saw the signal.
They lose it because the signal did not change the situation fast enough.

The real question for leadership

The real question is: “If we detected it, how quickly would that become control?”

These are not technical footnotes. They are the questions that decide whether visibility leads to control or simply to a more informed form of delay.

One practical pressure-test suggestion:
Run a time-to-action validation around a credible early-stage ransomware signal. Do not test whether the tool detects. Assume the alert already exists.

Instead, test whether the organisation can answer, in sequence:

  • Is this signal credible enough to act?
  • Who can authorise the first move?
  • What is the first safe move?
  • How quickly can trust be reduced without freezing the business?
  • What remains operational while containment is underway?


The value is not the discussion.
The value is finding out whether awareness in your environment can actually become action. That is the real question for leadership.

Not whether the alert exists. But whether the organisation can turn that alert into a safe move before the situation becomes harder to govern.

From visibility to control

Our platform is designed for the moment when an alert needs to become a controlled response. It complements existing preventive and detective controls by adding an operational containment layer that can help interrupt lateral movement, constrain unsafe paths and reduce the attacker’s room to act, while the organisation preserves as much safe operation as the incident allows.

Our aim is not to suggest that every alert immediately creates certainty. The practical value is that the organisation gains an executable move between observing malicious activity and resorting to broad shutdown or recovery. That is why we believe containment should be demonstrated in the customer’s own environment rather than accepted as a product promise.

The critical question is therefore not simply whether the organisation would detect the incident, but how quickly that detection could become control.

What Containment Changes
A safe containment move shortens the distance between awareness and control.

For readers who want to go further

I can share more detail on how S10 Group’s platform helps close the gap between seeing the signal and changing the outcome.

And for teams that want to pressure-test their own setup: I can run a free remote resilience assessment in your own sandbox environment, with your existing security controls enabled, to show how your current environment behaves under pressure and what difference that added control makes in practice.

If any of these would be relevant for your team, feel free to contact me.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.

No noise. No automated campaign stream. Just a simple signal when there is something worth reading.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Further readings

Previous S10 Group newsletter arc

17 March 2026 - #01: The Odido lesson:
The Odido Lesson →
Return to the identity-trust lesson: access may continue to work even after the organisation can no longer trust what that access represents
08 April 2026 - #02:
When the Vendor Is Non-Negotiable →
Explore how dependency on critical suppliers can reduce room to manoeuvre when trust becomes uncertain.
14 May 2026 - #03:
The First Hour: Who Is Allowed to Act? →
Revisit the decision-rights question that determines whether the first hour produces action or delay

Context & discovery

The sources below informed the themes in this newsletter: time-to-action gaps, AI-accelerated threats, ransomware containment, operational resilience, leadership decision-making, and the difference between awareness and control.
Public reporting and incident analysis
Change Healthcare, MGM Resorts, Synnovis, Colonial Pipeline, and other major cyber incidents used to illustrate how cyber incidents often evolve from detection challenges into operational control, continuity, communication, and leadership challenges.
Research and reporting on AI-assisted cyber operations:
Industry research examining how artificial intelligence is accelerating reconnaissance, exploit development, social engineering, targeting, and attacker adaptation, increasing pressure on organisational response times.