Government agencies and the contractors that support them are not facing the same adversary as a typical business. Advanced persistent threats (APTs), well-resourced, often state-sponsored groups, are patient, methodical, and willing to sit inside a network for weeks before making a move. Defending against them takes a different playbook than stopping opportunistic cybercrime: faster detection, realistic adversary simulation, and compliance frameworks built specifically for this threat model.
What Makes an APT Different From Ordinary Cybercrime
CISA (the Cybersecurity and Infrastructure Security Agency) distinguishes nation-state and state-sponsored actors from cybercriminals by motive and patience: APTs conduct campaigns "targeted and aimed at prolonged network/system intrusion" in pursuit of espionage, intellectual property theft, or disruption and destruction, not the quick financial payout that drives most cybercrime (CISA).
That patience shows up in the numbers. Mandiant's M-Trends 2025 report puts the global median dwell time (how long an intruder sits undetected inside a network) at 11 days, up slightly from 10 the year before. The gap between good and bad outcomes is stark: intrusions discovered because an external party notified the victim averaged 26 days of undetected access, while cases where the attacker notified the victim directly (as with ransomware) averaged just 5 days (Google Cloud / Mandiant). For a government network, that's weeks of quiet reconnaissance, credential harvesting, and lateral movement before anyone notices.
Once an intrusion does tip into action, it can move fast. CrowdStrike's 2026 Global Threat Report clocked average breakout time (how quickly an attacker starts moving laterally after initial access) at 29 minutes across the eCrime activity it tracks, down from 48 minutes in 2024, with the fastest observed breakout at 27 seconds. That figure covers cybercrime broadly rather than APTs specifically, but it's a useful reminder of how little time a detection team has once an intrusion shifts from dormant to active.
Who's Actually Behind These Attacks
Public advisories name several groups actively targeting government and critical-infrastructure networks:
- Volt Typhoon (China-linked): pre-positions inside US critical infrastructure IT networks using living-off-the-land techniques, apparently to enable future disruptive access into operational technology (CISA AA24-038a).
- Salt Typhoon (China-linked): an espionage campaign against telecommunications and critical-infrastructure providers, the subject of a joint advisory from CISA, the NSA, the FBI, and international partners (CISA AA25-239a).
- APT28 / Fancy Bear (Russia, linked to the GRU): a long-running group targeting governments, embassies, military organizations, and energy companies; its known aliases and techniques are catalogued on MITRE ATT&CK.
- APT29 / Cozy Bear (Russia, linked to the SVR): another long-running Russian group associated with espionage against government, defense, and think-tank targets (MITRE ATT&CK).
CISA has also tracked additional China-linked activity built around large-scale compromised-device botnets used to stage and obscure intrusions, and Russia's GRU-linked Sandworm group has a long history of destructive operations against critical infrastructure, a reminder that for public-sector targets, the objective isn't always data theft. Sometimes it's disruption. These aren't hypothetical adversaries for agencies and contractors. They're the threat model our government and public-sector clients plan around every day.
Detecting Attackers Who Are Built to Stay Hidden
Because APT groups favor stealth over speed, detection can't lean on signature-based tools alone. MITRE ATT&CK, a public knowledge base of adversary tactics, techniques, and procedures, is built for exactly this problem. Security teams use it to map detection rules to attacker behavior rather than brittle indicators of compromise, run gap-analysis heatmaps in ATT&CK Navigator, and structure purple-team and red-team exercises around real group tradecraft (CrowdStrike).
In practice, that means:
- Map detection coverage to ATT&CK techniques, not static indicators, so alerts fire on behavior that survives a change in tooling or infrastructure.
- Test against realistic APT tradecraft. A red team engagement modeled on named-actor techniques tests whether your team would actually catch a living-off-the-land intrusion, not just a generic scan-and-exploit exercise.
- Prioritize the quiet stuff. With median dwell times measured in days, the bigger risk is missed low-and-slow reconnaissance and credential harvesting, not just noisy exploitation attempts.
- Staff detection around the clock. A dwell-time advantage only closes if someone is watching continuously; a SOC as a Service capability provides the 24/7 monitoring and response most agencies and contractors can't staff internally.
Aligning With the Frameworks Auditors Expect
NIST CSF 2.0, published in February 2024, broadened the framework's scope beyond critical infrastructure and added a new "Govern" function covering supply-chain, cloud, and zero-trust practices (NIST NCCoE). Underneath it sits SP 800-53, the control catalog behind FISMA and FedRAMP baselines, including the continuous-monitoring control family that's directly relevant to catching APT dwell activity before it turns into a breach (CSF Tools).
For defense contractors, CMMC (Cybersecurity Maturity Model Certification) adds another layer on top: it structures the security controls and independent assessment that protect sensitive defense information across a tiered maturity model. We build and test detection, monitoring, and control coverage that maps to CMMC practices, so the defenses behind a certification actually hold up against APT tradecraft rather than just satisfying an audit.
A Practical Checklist
- Segment networks so a compromised IT system can't become a path into operational technology, the exact pattern CISA has warned about with Volt Typhoon.
- Patch and monitor internet-facing infrastructure aggressively; living-off-the-land techniques abuse legitimate admin tools, so prevention matters as much as detection.
- Map detection rules to MITRE ATT&CK and validate them against realistic APT tradecraft through red-teaming.
- Maintain continuous monitoring, not periodic assessment: NIST CSF's Govern function and SP 800-53's continuous-monitoring controls both point the same direction.
- Map controls and detection to CMMC practices so the security work behind certification stands up to real APT tradecraft, not just an audit.
- Build or buy 24/7 detection and response capacity. Dwell time only shrinks if someone is watching around the clock.
Nation-state adversaries have the patience and resources to wait you out. The agencies and contractors that hold up best are the ones that pair compliance with real, tested detection and response, not one or the other. If you need help assessing where your program stands, talk to our team.
Frequently Asked Questions
What is an APT (advanced persistent threat)?
An APT is a well-resourced, typically state or state-sponsored group that conducts prolonged, targeted intrusions into a network (aiming for espionage, intellectual property theft, or disruption) rather than the quick financial payout that drives most cybercrime.
How is an APT different from the cybercrime most businesses worry about?
Ordinary cybercrime is largely opportunistic and financially motivated: ransomware, fraud, credential theft for resale. APTs are patient and objective-driven, often willing to stay hidden inside a network for days or weeks to reach a specific target, such as sensitive government data or critical infrastructure access.
What is "dwell time" and why does it matter?
Dwell time is how long an attacker remains undetected inside a network after initial access. Industry reporting puts the global median around 11 days, though it varies widely by how the intrusion is discovered. Longer dwell time means more opportunity for reconnaissance, credential theft, and lateral movement before a defender ever notices.
What frameworks should government agencies and contractors follow?
NIST CSF 2.0 and SP 800-53 are the common baseline for federal risk-management and continuous-monitoring programs. Defense contractors working with sensitive information also build toward CMMC, which centers on independent assessment of the controls that protect that information. In practice these frameworks overlap heavily: the continuous monitoring and behavior-based detection that catch APT dwell activity are what all three are ultimately measuring.
What does a CMMC readiness engagement actually cover?
It scopes the systems that handle sensitive defense information, maps your existing controls to the CMMC practices, closes the gaps, and validates detection and monitoring against realistic APT tradecraft, so a certification reflects defenses that genuinely work, not just documentation.
How can we actually test our defenses against APT-style attacks?
Generic vulnerability scanning won't tell you whether you'd catch a patient, living-off-the-land intrusion. A red team engagement that simulates named-actor tradecraft, paired with 24/7 monitoring that maps to MITRE ATT&CK, gives a realistic picture of whether your detection and response would hold up.



