Field Notes / Threat detection
11 days: how long an attacker sits inside a Philippine SMB before anyone notices
Filipino SMBs spot an intruder slower than the global median. Here is what happens in those 11 days, and the three changes that pull detection down to hours.
01 Why detection lags here
leven days. That is the figure we keep landing on. Mandiant's M-Trends 2025 report places the global median dwell time at ten days. When we lined up our own engagement notes from the past 18 months across Manila, Cebu, and Davao, the equivalent figure for Filipino SMBs sits closer to eleven. Some businesses had been compromised for over a month before our team flagged it on a scoping call.
Filipino SMBs share a security profile that all but guarantees slow detection. Most rely on a single outsourced IT provider whose contract covers helpdesk and infrastructure. Threat detection sits outside that contract. The MSP installs antivirus on endpoints, configures the firewall, and calls the job done. None of that catches an attacker who is already inside with a valid login.
Business chat is the second blind spot. Internal coordination here runs through Facebook Messenger and Viber. Neither leaves a business-grade audit trail. When an attacker takes over a staff account and uses Messenger to pull internal information, no SIEM rule fires. Microsoft Defender does not see it. There is no CISO. The owner finds out when the wire transfer has already cleared.
Third, the tooling that would catch lateral movement fast is priced for enterprises. A proper Endpoint Detection and Response platform with 24/7 monitoring runs PHP 250,000 to PHP 600,000 a year for a small firm. Most owners assume their existing antivirus does the job. Antivirus alone catches under 7% of modern intrusions Verizon DBIR 2024 .
02 What 11 days buys an attacker
Eleven days is a long time for a competent operator, and the pattern is consistent across the engagements we run. Day one is rarely loud. Most initial access starts with phishing, and the first hours go to confirming the foothold and working out the user's role in the business.
By day three, a real attacker has done what we do in reconnaissance. They pull the org chart from the email signature graph, map who reports to whom, and single out the two or three people who can authorise a wire. They read the last 90 days of email between the CEO and the CFO. They learn the cadence of payments to suppliers in Hong Kong, Singapore, and Shenzhen.
By day five, lateral movement is usually done. The attacker pivots from the phished account into the accounting workstation, often on a reused password (the bookkeeper kept the same one for Outlook and the local QuickBooks login). Now they hold read-write access to invoice templates, banking instructions, and the customer master file.
Day eight to eleven is the patient phase. A supplier invoice arrives. The attacker intercepts it, changes the bank details (one digit, or a Hong Kong account swapped for a Mauritius one), and re-sends from a domain that looks identical. The CFO approves it. The thread looks legitimate, the amount matches an expected payment, the supplier has billed for years. Days later the supplier asks where their money is. That is the moment of detection. Anything earlier is luck.
03 From 11 days to 11 hours
Cut detection from weeks to hours and the BEC email never clears, because the forwarding rule that set it up gets flagged the minute it is created. Three shifts get you there, and none of them need an enterprise budget.
The first is logging. Microsoft 365 Business Premium includes audit log retention and Defender for Office 365 alerts. Most Filipino SMBs we audit have these in their licence and never switched them on. One administrator turns them on in a Saturday afternoon. After that, an anomalous mailbox forwarding rule (a classic BEC pre-attack signal) raises a visible alert within minutes.
The second is segmentation. The accounting workstation should not share a flat network with the receptionist's laptop. A basic VLAN on a small-business firewall (Fortinet, Sophos, or Mikrotik) breaks the easy lateral path. We find this missing in roughly 8 of 10 SMB engagements.
The third is a 30-minute monthly conversation. We call it the security standup. The MSP, the owner, and one operator review three things: who has access to what, which alerts fired in the past 30 days, and which payments above PHP 100,000 went to a new bank account. That last question alone catches most BEC fraud before the wire clears. The 11-day-to-11-hour shift comes from operational discipline, not new spend.
04 What a red team hands you
A red team assessment gives you a real number for your business, not an average from a report. We start where an attacker starts: an open-source view of your firm, your domain's mail records, your staff's LinkedIn presence, and any of your credentials already leaked in past breaches (we check every Filipino SMB against HaveIBeenPwned and the dark-web equivalents). From there we attempt initial access with the same tradecraft a real adversary would use.
You walk away with a written report built on three numbers that matter. How many ways an attacker can get in. How long they can stay before any of your existing tools fire. What they reach once inside. The controls come ranked by cost-to-impact, and our team joins a working session with your MSP to put them in place.
We run this exact scope two weeks from kickoff to delivered report. We have run it for a 12-person logistics firm in Pasig and a 70-person BPO in Cebu. The findings differ. The structural pattern is uncomfortably consistent. Set the cost of finding out against the IBM 2024 average breach cost of USD 4.88 million, or the Manila bookkeeping firm we know that lost 18 months of operating margin to a single fraudulent wire, and an honest map of your attack surface is the cheaper problem to have IBM 2024 . Start with a free audit and we'll scope the rest from there.
- Microsoft 365 audit logs and Defender for Office 365 alerts switched on
- Anomalous mailbox forwarding rules set to alert within minutes
- Accounting workstation split onto its own VLAN, off the flat network
- Payments above PHP 100,000 to new bank accounts held for a second approver
- Reused passwords reset and two-factor turned on for every account
References
Sources
- Mandiant. M-Trends 2025. Google Cloud / Mandiant, 2025. mandiant.com
- Verizon. 2024 Data Breach Investigations Report (DBIR). Verizon Business, 2024. verizon.com
- IBM Security. Cost of a Data Breach Report 2024. IBM Corporation, 2024. ibm.com
- Bangko Sentral ng Pilipinas. Memorandum M-2022-013 on Cybersecurity. BSP, 2022. bsp.gov.ph