The Clock Is the Measure. Here Is How It Is Read.
Temporal advantage is this framework’s decisive measure of effectiveness, and the only one it publishes that can be honestly lost: the defender’s decision loop, measured, against the adversary’s dwell, estimated, as a ratio with a declared threshold. Everything below is how each half of that ratio is produced, what a deficit obliges, and which of the 154 cataloged techniques move it at all — 56 of them, on the framework’s own reckoning.
The model is real. The reading is an archetype’s, and no agency was measured to produce it.
The measurement definitions, the ratio and the controls are the framework as published. The numbers in the worked reading — 14 days of loop against a 21-day dwell estimate — belong to the Federal Reference Agency, the same illustrative estate at the same maturity as the coverage baseline and the case studies.
They are consistent with that baseline by construction rather than by coincidence: an agency that scores almost nothing on deception and delay has no mechanism to shorten detection or to lengthen dwell, and this reading is what that looks like when it is timed. Do not use it as a benchmark — a loop time borrowed from an archetype is exactly the kind of unsourced number the dwell rules below warn against.
Adversary Dwell, Divided by Defender Loop.
Two quantities of different kinds: one measured from the agency’s own records, one estimated from intelligence with a stated basis. Keeping them apart is what makes the ratio arguable — a reader can reject the numerator without rejecting the measurement.
Temporal advantage is adversary dwell divided by defender loop. Above 1, the loop closes inside the adversary’s budget; below 1, the adversary finishes first in the median case. The threshold is where the agency decides how much margin it needs above 1, and a reading below the threshold is a deficit whether or not anything has yet gone wrong.
Sector reporting for credential-driven intrusion against civilian federal records estates, moderate confidence, revised this cycle.
Detect, decide and contain, summed. Measured from the cycle’s closed incidents rather than from a target.
Set by the Authorizing Official against the defensive intent: containment must complete well inside the adversary’s expected budget, because a ratio near 1 means the median case is a coin toss and the worst case is a loss.
Three Segments, Each with a Start Point That Has to Be Defensible.
Almost every dishonest tempo number comes from moving a start point rather than from arithmetic. Each segment below carries the specific way it gets flattered, because naming the counterfeit is the only reliable defense against it.
Starts. The first observable the adversary generated that the agency’s own telemetry recorded — whether or not anybody looked at it at the time.
Stops. An analyst holds a finding that names the activity as hostile, at a stated confidence.
Made of. Time the evidence sat in a log nobody queried. On an estate that detects by signature, this segment is measured in weeks, and almost none of it is analysis.
Shortened by. Deception, because a decoy interaction has no benign explanation and needs no baseline to be believed; and behavioral baselining on the identity plane, because it converts a legitimate-looking action into a deviation.
Counterfeit. Starting the clock at alert triage rather than at first observable. That measures how fast the SOC works on what it was handed, and says nothing about the fortnight before it was handed anything.
Starts. The finding exists and is attributable to a named owner.
Stops. A containment action is authorized — not taken, authorized.
Made of. Waiting on authority. Where the action is outside the pre-authorized set this segment is an escalation queue, and its length is a property of the rules of engagement rather than of the analysis.
Shortened by. Pre-authorization. Settling in advance which actions may be taken without asking removes the queue from the critical path, and it is the cheapest hour on the whole loop to buy.
Counterfeit. Recording the decision timestamp as the moment the approver replied, when the request had been waiting since the previous evening. The gap between decision and effect is where authority latency hides.
Starts. The action is authorized.
Stops. The adversary’s access to the affected terrain is actually severed — verified, not requested. A revocation that a live session survives has not stopped this clock.
Made of. Whether the action is one system or forty. Isolating a host is minutes; revoking a token estate-wide, or severing a segment, is only fast if it was built to be.
Shortened by. Isolation and retrograde capability — the ability to fail a service secure, sever a segment or quarantine an account as a single deliberate action rather than as a project.
Counterfeit. Stopping the clock when the containment ticket closes. The measurement is the adversary’s loss of access, and the two are the same thing only when somebody checked.
An Estimate That Has to Carry Its Basis with It.
The elapsed time an adversary of the relevant class expects to hold access before being evicted — the budget they plan against. It is the numerator of the ratio, it is an estimate rather than a measurement, and it has to carry its basis with it.
Three Bases for a Dwell Estimate, and What Each One Gets Wrong
| Basis | What it is good for | Where it misleads |
|---|---|---|
| The agency’s own closed incidents | Directly relevant, and the only basis derived from this estate’s actual ground. Reconstructing dwell after the fact is itself a cataloged technique. | Survivorship. It measures the adversaries who were caught, which biases the estimate toward the fast and clumsy ones and says nothing about the patient one still resident. |
| Sector and government reporting | Covers adversaries this agency has not yet met, and is the basis a reviewer can check independently. | Aggregated across estates that do not resemble this one. A civilian records agency and an operational-technology-heavy one do not share a dwell profile. |
| Intelligence assessment of a named campaign | Specific to the adversary the intelligence requirements actually name, which is the only kind of specificity the threshold can be defended with. | Perishable and confidence-bearing. Used without its confidence level it becomes a precise number resting on a judgment nobody restated. |
The agency’s own closed incidents
- What it is good for
- Directly relevant, and the only basis derived from this estate’s actual ground. Reconstructing dwell after the fact is itself a cataloged technique.
- Where it misleads
- Survivorship. It measures the adversaries who were caught, which biases the estimate toward the fast and clumsy ones and says nothing about the patient one still resident.
Sector and government reporting
- What it is good for
- Covers adversaries this agency has not yet met, and is the basis a reviewer can check independently.
- Where it misleads
- Aggregated across estates that do not resemble this one. A civilian records agency and an operational-technology-heavy one do not share a dwell profile.
Intelligence assessment of a named campaign
- What it is good for
- Specific to the adversary the intelligence requirements actually name, which is the only kind of specificity the threshold can be defended with.
- Where it misleads
- Perishable and confidence-bearing. Used without its confidence level it becomes a precise number resting on a judgment nobody restated.
- Differentiate by adversary class where the threat profile warrants it. A fraud ring and a state collector do not budget the same time, and one ratio computed against a blended average describes neither.
- State the estimate’s confidence next to it, every time. A ratio built on a low-confidence numerator is a low-confidence ratio, and the reader is entitled to know which half is soft.
- Revise on evidence, not on the calendar. An incident that provides direct evidence of dwell is worth more than a year of unchanged reporting.
- Never adjust the estimate because the ratio came out badly. Moving the numerator to clear a deficit is the single most damaging thing that can be done to this metric.
One Cycle, Read End to End.
Held as three segment measurements. Every other figure in this section — the shares, the ratio, the shortfall, the counterfactual — is arithmetic on those three, so none of them can drift from the measurement they describe.
The Defender Decision Loop, by Segment
- Detect11 days · 78.6%
Median across the cycle’s closed incidents, clocked from first recorded observable. The estate detects by signature and by third-party notification; nothing on it is designed to make an adversary announce themselves.
- Decide2.4 days · 17.3%
Dominated by two escalations that crossed a weekend. The pre-authorized set covers host isolation and little else, so anything touching identity or a shared service waits for the Authorizing Official.
- Contain0.6 days · 4.2%
Fast where the action is host isolation, slow where it is estate-wide session revocation — which on this estate is a sequence of manual steps rather than one action.
- The computation
- 504 hours of estimated dwell ÷ 336 hours of measured loop = 1.5×, against a declared threshold of 3×. That is a deficit of 1.5.
- What closing it would take
- Holding the dwell estimate fixed, the loop would have to fall to 7 days — from 14. That is not a tuning exercise; it is a different detection posture.
- The counterfactual worth doing
- Pre-authorization is the cheapest hour on this loop to buy. Remove the decide segment entirely — every containment action authorized in advance — and the ratio moves to 1.8×. Still a deficit. Detection is 78.6% of this loop, and that is where the deficit lives.
Which is exactly what the coverage baseline predicts. The forms that shorten detection are deception and screening; the forms that lengthen dwell are delay and isolation. On this estate M5, M6, M7 carry the most clock-moving cells — M5 at 11.1%, M6 at 11.1%, M7 at 27.8% supplied. A program cannot buy tempo out of the segment that is already fast.
What Being Behind Obliges.
A deficit is a reportable condition, not a bad quarter. The distinction is the whole reason tempo is a control family rather than a dashboard tile: a metric with no escalation consequence is a statistic.
A deficit that is noticed and absorbed inside the SOC is indistinguishable from one that was never measured. The control makes it travel to the authority that can fund or accept it.
Adjusting the threshold to clear the deficit converts the metric into a description of current performance, which is precisely what it was built not to be. The defense changes or the risk is accepted explicitly.
A deficit is an argument for the specific cells that shorten the loop or lengthen dwell, ahead of work that improves neither. It is the framework’s answer to "everything is a priority".
A branch that assumes containment inside four hours is not executable by a program whose measured loop is two weeks. The deficit is what makes that visible before the branch is needed rather than during it.
One cycle is noise. The direction across cycles is the signal, and a program in deficit that is closing is in a different position from one in deficit that is widening.
Where a Deficit Actually Goes
Not asserted here — read off TA-3’s own declared outputs, so this page and the control sheet cannot disagree about where the finding travels.
- CE-7 Brief Generation and Distribution
Temporal advantage result — the framework’s headline metric
- CG-4 Findings Disposition
Deficit requiring formal disposition
- CE-5 Remediation Backlog Prioritization
Tempo-driven items entering the remediation backlog
The Five Controls That Make Tempo a Control Rather Than a Chart.
Every metric in this family is capable of reporting that the defender is behind. A tempo family whose numbers only ever improve is measuring activity, and the counts beside each control below say how much of the clock-moving catalog it actually reaches.
To make the defender's tempo a measured quantity rather than an impression, so that the numerator of temporal advantage exists at all.
Requires The organization shall measure the elapsed time from detection through decision to containment, and shall record it each cycle.
To establish the denominator of temporal advantage with an explicit, challengeable basis, so the comparison the framework rests on can be argued with.
Requires The organization shall maintain a documented estimate of adversary dwell time relevant to its threat profile, with a stated basis.
To convert the temporal advantage figure into a governed condition with an escalation consequence, so that being behind is a decision the organization has to make rather than a number it can note.
Requires The organization shall define the minimum acceptable ratio of adversary dwell to defender decision loop, and shall treat a deficit as a reportable condition.
To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
Requires Defensive actions that may be executed without escalation shall be defined in advance and approved by the accountable authority.
To plan for the periods in which tempo predictably falls, so that the measured advantage is not a statement about the organization's best hours only.
Requires Conditions under which the defender decision loop is expected to degrade shall be identified, with compensating measures defined.
The lopsidedness is the finding. TA-4 Pre-authorized Response is named by 17 of the clock-moving techniques — more than any other control in the family — because pre-authorization is what converts a capability into one that can be used inside the loop rather than after it.
Only Two Things Change the Ratio.
Get faster, or make the adversary slower. The published tempo overlay marks the cells that do either, and it is a selection rather than a judgment of the rest — the 98 techniques it does not name are necessary, they are simply not what wins the clock.
Temporal advantage is the defender detect→decide→contain tempo measured against adversary dwell. Only two things move it: getting faster, or making the adversary slower. These are the cells that do either. Everything else in the matrix is necessary, but it is not what wins the clock.
ASOM-Fed Defensive Maneuver Framework v6.1 · overlay “Temporal advantage”
1 validated, 7 partial, 13 absent — 21.4% supplied.
1 validated, 8 partial, 10 absent — 26.3% supplied.
1 validated, 5 partial, 10 absent — 21.9% supplied.
Clock-Moving Cells by Form of Maneuver, and What This Baseline Supplies
| Form | Which way it moves the clock | What the baseline supplies |
|---|---|---|
| M1 Screen / Guard6 of the form’s 15 techniques move the clock | 6 shorten the loop | 41.7% — 1 validated, 3 partial, 2 absent |
| M2 Defense in Depth1 of the form’s 18 techniques move the clock | 1 shorten the loop | 0% — 0 validated, 0 partial, 1 absent |
| M3 Envelopment4 of the form’s 20 techniques move the clock | 2 shorten the loop · 2 both | 37.5% — 0 validated, 3 partial, 1 absent |
| M4 Obstacle / Canalization5 of the form’s 17 techniques move the clock | 5 slow the adversary | 50% — 1 validated, 3 partial, 1 absent |
| M5 Ambush9 of the form’s 13 techniques move the clock | 7 shorten the loop · 2 both | 11.1% — 0 validated, 2 partial, 7 absent |
| M6 Delay9 of the form’s 10 techniques move the clock | 6 slow the adversary · 3 both | 11.1% — 0 validated, 2 partial, 7 absent |
| M7 Counterattack9 of the form’s 17 techniques move the clock | 5 shorten the loop · 4 both | 27.8% — 1 validated, 3 partial, 5 absent |
| M8 Isolation / Retrograde7 of the form’s 17 techniques move the clock | 2 slow the adversary · 5 both | 14.3% — 0 validated, 2 partial, 5 absent |
| M9 Spoiling Attack4 of the form’s 9 techniques move the clock | 4 slow the adversary | 25% — 0 validated, 2 partial, 2 absent |
| M11 Reconstitution2 of the form’s 11 techniques move the clock | 2 slow the adversary | 0% — 0 validated, 0 partial, 2 absent |
M1 Screen / Guard
6 of the form’s 15 techniques move the clock
- Which way it moves the clock
- 6 shorten the loop
- What the baseline supplies
- 41.7% — 1 validated, 3 partial, 2 absent
M2 Defense in Depth
1 of the form’s 18 techniques move the clock
- Which way it moves the clock
- 1 shorten the loop
- What the baseline supplies
- 0% — 0 validated, 0 partial, 1 absent
M3 Envelopment
4 of the form’s 20 techniques move the clock
- Which way it moves the clock
- 2 shorten the loop · 2 both
- What the baseline supplies
- 37.5% — 0 validated, 3 partial, 1 absent
M4 Obstacle / Canalization
5 of the form’s 17 techniques move the clock
- Which way it moves the clock
- 5 slow the adversary
- What the baseline supplies
- 50% — 1 validated, 3 partial, 1 absent
M5 Ambush
9 of the form’s 13 techniques move the clock
- Which way it moves the clock
- 7 shorten the loop · 2 both
- What the baseline supplies
- 11.1% — 0 validated, 2 partial, 7 absent
M6 Delay
9 of the form’s 10 techniques move the clock
- Which way it moves the clock
- 6 slow the adversary · 3 both
- What the baseline supplies
- 11.1% — 0 validated, 2 partial, 7 absent
M7 Counterattack
9 of the form’s 17 techniques move the clock
- Which way it moves the clock
- 5 shorten the loop · 4 both
- What the baseline supplies
- 27.8% — 1 validated, 3 partial, 5 absent
M8 Isolation / Retrograde
7 of the form’s 17 techniques move the clock
- Which way it moves the clock
- 2 slow the adversary · 5 both
- What the baseline supplies
- 14.3% — 0 validated, 2 partial, 5 absent
M9 Spoiling Attack
4 of the form’s 9 techniques move the clock
- Which way it moves the clock
- 4 slow the adversary
- What the baseline supplies
- 25% — 0 validated, 2 partial, 2 absent
M11 Reconstitution
2 of the form’s 11 techniques move the clock
- Which way it moves the clock
- 2 slow the adversary
- What the baseline supplies
- 0% — 0 validated, 0 partial, 2 absent
Across all 56 clock-moving cells the reference agency holds 3 validated and 20 partial, for 23.2% supplied. That figure, not the tooling budget, is why the loop in the worked reading is 14 days long.
Things That Look like Tempo Improvement and Are Not.
Each of these moves a number that gets reported. None of them moves the ratio, and two of them make it worse while appearing to help.
- More alerts. Additional detection content that does not shorten the detect segment lengthens the decide segment, and the loop gets worse while the dashboard improves.
- Faster triage. Triage sits inside the detect segment and is usually the smallest part of it; halving it on an estate whose evidence sat unqueried for a fortnight moves the loop by hours.
- A shorter mean with an unchanged worst case. The incident that mattered is in the tail, and reporting only the mean is how a program stays confident while losing.
- Automation that still asks. A playbook that executes in seconds and then waits for approval has moved work out of the decide segment without moving time out of it.
- A better dwell estimate. Lowering the numerator improves nothing; it makes the same defense look worse or better depending on which report was cited, which is why the basis is a control of its own.
The 16 highest-leverage cells.
These shorten the defender’s loop and lengthen the adversary’s in the same move, which is what makes them worth more than the sum of two cells that each do one. On this baseline 10 of them are absent.
- M3.03 Continuous AuthorizationPartial
- M3.11 Session and Token Revocation PathPartial
- M5.03 Decoy CredentialsAbsent
- M5.09 Deception Alert RoutingAbsent
- M6.02 Step-Up Authentication on AnomalyAbsent
- M6.04 Session Duration Reduction Under AlertAbsent
- M6.05 Approval Gates on High-Impact ActionsAbsent
- M7.03 Automated Containment PlaybooksPartial
- M7.04 Host Isolation on ConfirmationValidated
- M7.05 Credential Reset SweepPartial
- M7.11 Eviction SequencingAbsent
- M8.01 Automated Segment SeveringAbsent
- M8.02 Estate-Wide Session RevocationPartial
- M8.05 Federation Trust SuspensionAbsent
- M8.06 Cloud Account QuarantineAbsent
- M8.07 Egress BlackholeAbsent
New to this vocabulary? Form of maneuver, technique, control and posture are different classes of thing, and swapping two of them produces work that looks correct and decides nothing. The object model states each one with the question it answers and the class it is most often mistaken for.