Mean Time to Detect (MTTD) measures how long a threat goes unnoticed inside your environment. Mean Time to Respond (MTTR) measures how long it then takes to contain it. Together they define your total exposure window, and that window has a price. IBM’s 2025 research put the average breach lifecycle at 241 days, and breaches that ran past the 200-day mark cost dramatically more than those caught early. For a financial institution, where the sector average breach runs $5.56M, the difference is not academic.
This guide gives you the formulas, current benchmarks for what “good” looks like, and the specific steps a modern Security Operations Center (SOC) uses to bring both numbers down. The through-line is a shift away from counting alerts and toward outcomes your board and your cyber insurer can actually verify.
MTTD is the average time between an intrusion starting and an analyst confirming it as a real incident. MTTR is the average time from that confirmation to full containment and remediation. Add them together and you get the attacker’s total dwell time.
Formula
Track the median alongside the mean. A single advanced persistent threat with a months-long dwell time will distort an average and hide otherwise strong performance.
One definitional caution. MTTR is used inconsistently across the industry. Some teams measure it to the first containment action, others to full service restoration. Pick one definition, document it, and hold it constant, otherwise your trend line measures your bookkeeping rather than your performance.
There is no universal number; targets shift by industry, threat tier, and SOC maturity. The table below shows widely referenced reference points.
Metric | Best-in-class (CMMI L4-5) | Developing (CMMI L2-3) | Ad-hoc (CMMI L1) |
MTTD (critical threats) | Under 1 hour | Hours to 1 day | Days to weeks |
MTTR (critical threats) | Under 4 hours | Hours to 1 day | 72+ hours, variable |
The financial stakes behind these tiers are well documented. IBM’s 2025 report found that organizations using AI and automation extensively saved close to $1.9M per breach compared with those that did not, largely by compressing detection and response times. Moving from an ad-hoc posture toward Level 4-5 consistency is, in cost terms, one of the highest-return security investments available.
A fast MTTD means nothing if your response playbook takes six hours to run. Ransomware can encrypt a domain in under an hour from first foothold.
Reducing MTTD is fundamentally about improving the signal-to-noise ratio so real threats surface fast. Three moves do most of the work.
Where MTTD is a detection problem, MTTR is primarily a process problem. The clock runs from analyst confirmation to full containment, and delay usually creeps in at the handoffs.
A commitment to outcome metrics changes how you scale. Rather than adding staff or tools to absorb rising alert volume, mature SOCs attack the components that drive high MTTD and MTTR: manual enrichment, missing runbooks, and tool silos. Automating repetitive tasks and rehearsing response converts the work from low-value triage into high-value incident handling, and it does so without growing the payroll.
The shift in one line From “how many alerts did we close?” to “how fast did we detect and contain the ones that mattered?” |
The final payoff is regulatory. Frameworks like NIST CSF 2.0 and the SEC cybersecurity disclosure rules expect demonstrable evidence of a functioning program, and abstract alert counts do not provide it. A consistent downward trend in MTTD and MTTR does. It lets you move from asserting “we are compliant” to showing, with data, how effective your controls are at reducing real risk.
Reported to the board, these metrics elevate the conversation from technical detail to business resilience. They also translate directly for cyber insurers, who increasingly price coverage on demonstrated response capability rather than stated intent.
The alert-driven SOC has had its day. To align security with business resilience and satisfy modern regulators and insurers, the focus has to move to measurable outcomes. By rigorously defining, measuring, and working to reduce Mean Time to Detect and Mean Time to Respond, you transform your SOC from a reactive cost center into a data-driven asset that demonstrably shrinks risk, and proves the value of every security dollar to the enterprise.
This FAQ seeks to answer some of the most common questions and confusions about this topic.
MTTD measures the time to detect a threat; MTTR measures the time to contain and remediate it once detected. Combined, they equal an incident’s total dwell time.
For critical threats, leading SOCs target containment in under four hours. Less mature programs often measure MTTR in days. Set targets per service tier rather than as one organization-wide figure.
Sum the detection time across all incidents in a period, then divide by the number of incidents. Track the median alongside the mean so long-dwell outliers do not distort the picture.
Frameworks such as NIST CSF 2.0 and the SEC disclosure rules expect demonstrable evidence of effective controls. Trending these metrics gives auditors, boards, and cyber insurers concrete, data-driven proof of due diligence.
Automation delivers the fastest gains. SOAR-driven triage, alert enrichment, and pre-approved containment actions remove manual delay without adding headcount.
Rakesh Asthana is the founder of World Informatix Cyber Security and a veteran technology and security leader with over 40 years of experience safeguarding complex global institutions. As a former Senior IT Director and CIO for the World Bank, he led large-scale IT and cybersecurity transformations, strengthening resilience across highly regulated environments. Notably, he played a pivotal role in the incident response and digital forensics during the Bangladesh Bank cyber heist. This experience continues to shape his pragmatic, risk-driven approach to securing financial systems worldwide.