Mathspace found out five weeks after it happened.
The online maths platform used in schools across New Zealand and Australia confirmed on 7 September 2026 that 1,079,819 students, parents, teachers, and staff had been affected by unauthorised access to its internal reporting system. The company identified the breach through its own internal review - not through an external alert, not through a security monitoring service, not because an analyst noticed something unusual at 2am. Five weeks after the intrusion window, during a routine review, someone found it.
That's not unusual. Mandiant's M-Trends 2026 report - based on more than 500,000 hours of incident response investigations - found the global median dwell time in 2025 was 14 days. That's the midpoint: half of all breaches went undetected for longer. Organisations that only found out because an external party told them had a median dwell time of 25 days. In some cases, attackers remained undetected for nearly 400 days.
Mathspace's five weeks sits above the median. It is not remotely an outlier.
The question this raises for every NZ business leader reading about these breaches isn't really about Mathspace or ZenTech or Thankyou Payroll. It's a direct one: if an attacker accessed your environment tonight, how long would it take you to find out?
Dwell time matters because of what attackers do with it.
CrowdStrike's 2026 Global Threat Report found the average breakout time - the window between gaining access to one system and moving to another - fell to 29 minutes in 2025. The fastest observed was 27 seconds. Initial access brokers are now handing compromised credentials to ransomware affiliates a median of 22 seconds after compromise, according to Mandiant.
The arithmetic is worth sitting with. An attacker who gains access to one employee account at 11pm has, on average, 29 minutes before moving deeper into the environment. If that movement goes undetected for 14 days - the global median - they have had two weeks to access email, read communications, search for financial information, identify privileged accounts, map backup infrastructure, and position for whatever their final objective is.
If it goes undetected for five weeks, as in the Mathspace case, the picture is considerably more complete.
This is why detection speed is the variable that determines how much damage a breach actually causes. Not whether the attacker got in - that's a question of prevention. How quickly you found them is a question of monitoring.
The New Zealand breach pattern this year illustrates the detection problem at a local level.
ManageMyHealth. MediMap. IntraCare. ZenTech. Thankyou Payroll. Mathspace. Six significant incidents affecting NZ organisations in under nine months. Each one became public at a point where the access had already occurred and, in most cases, data had already been taken.
The ZenTech breach, confirmed on 10 September 2026, involved a ransomware group claiming responsibility and publishing files relating to clinical trials. Health New Zealand became aware of the incident after files attributed to ZenTech were identified online. Forensic specialists were engaged after the fact. The dwell period is not publicly confirmed.
Thankyou Payroll's customers were notified on 10 September that names, IRD numbers, bank account details, and payment histories had been accessed through a compromised third-party analytics tool. The exposure window of the third-party tool preceded the notification.
RNZ described the week as comparable in concentration to the earlier 2026 cluster of three healthcare breaches. Cybersecurity researchers quoted in coverage of that cluster noted a consistent pattern: businesses struggled with governance and were typically reactive rather than proactive in their response.
None of these organisations failed to care about security. Several had security tools in place. What they largely shared was a detection gap - a period during which an attacker was present and active, and the business didn't know.
Security technology - endpoint protection, Microsoft Defender, email filtering - does something important. It detects known threats, blocks malicious files, generates alerts, and logs activity. Without it, detection is harder. With it, detection is possible.
What technology doesn't do is monitor continuously, investigate ambiguous signals, correlate activity across systems, or decide what to do at 2am when an alert appears in a queue that nobody checked.
Mandiant's data is instructive here. Organisations that detected intrusions internally did so in a median of nine days in 2025. Those that found out because an external party notified them took 25 days - nearly three times longer. The businesses detecting fastest were the ones actively looking - not waiting for something obvious enough to be unmissable.
The gap between nine days and 25 days is, broadly, the gap between active monitoring and periodic checking. Both are better than five weeks. Neither is as fast as continuous detection.
Managed Detection and Response closes this specifically. NSP's MDR service - powered by Adlumin's detection platform and backed by a local security operations team - monitors your entire Microsoft 365 environment continuously: endpoints, identity, email, cloud activity, and network traffic. When something anomalous occurs, an analyst investigates it. Not the following morning. When it happens.
For NZ businesses, where IT teams typically carry helpdesk, device management, Microsoft 365 administration, and security monitoring simultaneously, continuous monitoring isn't something that fits alongside the day job. MDR is how it gets done without requiring a dedicated security operations function.
The best way to understand why detection speed matters is to map a realistic scenario against what 14 days of undetected access actually provides.
A staff member receives a convincing phishing email. Their credentials are captured. The attacker authenticates using those credentials - a sign-in that appears in the Microsoft 365 logs, flagged as unusual by Entra ID's risk detection, generating an alert that goes into a queue nobody monitors continuously.
By day one, the attacker has reviewed the contents of the inbox, identified who the employee communicates with, and noted any financial transactions or pending payments in correspondence.
By day three, they've accessed SharePoint sites the account has permission to view, identified documents containing pricing, contracts, or client financial information, and possibly connected a persistent application to maintain access that survives a password change.
By day seven, they've identified who in the organisation has broader access, and made attempts to access those accounts through internal phishing emails that appear to come from the compromised employee's legitimate address.
By day 14 - the global median - they have a detailed map of the organisation's internal communications, financial relationships, and access structure. They are positioned for ransomware deployment, for business email compromise targeting a financial transaction, or for data exfiltration and extortion.
An analyst who was monitoring the environment on day one would have seen the unusual sign-in, reviewed the access patterns, and flagged the account for containment. The story ends at day one, not day 14.
That's the business case for MDR in a single scenario.
These aren't technical questions. They're operational ones that any business leader can ask their IT provider or internal IT team directly.
If an unusual sign-in occurred on one of our Microsoft 365 accounts at 11pm tonight, who would see the alert? Not eventually - tonight, when it happened.
If an account started accessing files it doesn't typically access, or creating email forwarding rules it didn't have before, would anyone notice? Would that activity be correlated against other signals in the environment, or would each event sit in a separate queue?
When did we last check whether our security tools are generating alerts that nobody is reviewing? Not whether the tools are deployed - whether the output of those tools is being acted on.
If we were in the same position as Mathspace - with an active breach running for five weeks - what would eventually surface it? An internal review? An external notification? A ransomware group publishing files?
The Mandiant data is clear that organisations detecting internally do so in nine days. The difference between nine days and 25 days, between nine days and five weeks, is whether someone is actively looking.
What is dwell time and why does it matter?
Dwell time is the period between an attacker gaining initial access to a system and that access being detected. The longer an attacker remains undetected, the more they can access, map, and position within an environment. Mandiant's M-Trends 2026 report found the global median dwell time was 14 days in 2025. Organisations that only discovered the breach through external notification had a median of 25 days. In some cases, attackers remained undetected for nearly 400 days.
How quickly can an attacker move through an environment after gaining access?
CrowdStrike's 2026 Global Threat Report found the average breakout time - from initial access to lateral movement to another system - was 29 minutes in 2025, with the fastest recorded at 27 seconds. Initial access is handed off to ransomware affiliates a median of 22 seconds after compromise. Detection speed is the primary variable in limiting how far an attacker moves before they're stopped.
Does having Microsoft Defender mean my environment is being monitored?
Microsoft Defender generates alerts based on detected threats and suspicious behaviour. It does not monitor those alerts continuously, investigate whether they represent genuine attacks, or correlate activity across your identity, email, endpoint, and cloud systems. That investigation and correlation requires a security analyst actively watching your environment. MDR adds that human layer to the detection capability Defender provides.
What is Managed Detection and Response and how is it different from antivirus?
Antivirus detects known threats based on signatures. MDR combines continuous monitoring across your entire environment - endpoints, identity, email, cloud activity - with security analysts who investigate alerts, correlate activity, and respond when a genuine threat is confirmed. The distinction is between technology that flags something and people who determine what it means and what to do about it.
How quickly does MDR detect a breach compared to not having it?
Mandiant's data shows organisations that detect internally do so in a median of nine days. With active, continuous MDR monitoring, anomalous activity is identified in real time - the same session or the same day rather than after days or weeks of accumulation. NSP's MDR service monitors your environment 24 hours a day, including weekends and public holidays, with no unwatched hours.
Is MDR only relevant for large businesses?
MDR is arguably more relevant for NZ SMEs than for large enterprises. Large organisations can staff a security operations function internally. Smaller businesses typically cannot - IT teams carry too many operational responsibilities to monitor security continuously alongside everything else. MDR provides the continuous monitoring capability that SMEs need without requiring them to build and staff a security team.
Most NZ businesses find out they weren't when something surfaces it - a ransomware group publishes files, a client flags unusual communication, an internal review turns up access that's been running for weeks.
A free 30-minute consultation with NSP covers where your current monitoring sits, what a continuous detection capability would look like for your specific environment, and what would change about your detection timeline.
Book your free consultation with NSP
Or call us directly: 0508 010 101