MTTR and MTTD (Mean Time to Respond and Detect)
Mean time to detect (MTTD) is the average time taken to identify a security incident after it begins. Mean time to respond (MTTR) is the average time taken to contain or remediate it once detected. Together they are core metrics for measuring the effectiveness of a security operations centre or detection and response programme: lower is better.
Mean time to detect and mean time to respond are the two headline metrics used to judge how quickly an organisation catches and deals with security incidents. MTTD measures the gap between an incident starting and someone realising it is happening. MTTR measures the gap between detection and containment or full remediation. Because the damage an attacker can do grows with every hour they remain undetected and unchecked, driving both numbers down is a central goal of any detection and response programme.
The distinction between the two is important because they point to different problems. A high mean time to detect indicates gaps in monitoring and detection coverage: the organisation cannot see the attack. A high mean time to respond indicates problems in process, staffing or authority: the organisation sees the attack but is slow to act. Measuring them separately tells a security team whether to invest in better detection or in faster, better-rehearsed response.
These metrics are frequently cited in the context of dwell time, the total period an attacker remains in an environment before being evicted. Industry reporting has historically put dwell time at weeks or months for many breaches, which is the difference between a contained incident and a catastrophic one. A mature security operations centre aims to compress dwell time from months to hours by shrinking both MTTD and MTTR.
Several related measures round out the picture. Mean time to acknowledge tracks how long an alert waits before an analyst begins working it. Mean time to contain focuses specifically on stopping the spread, as distinct from full recovery. Organisations choose the mix of measures that reflects their priorities, but the underlying principle is constant: speed limits damage.
Improving these metrics is a combination of technology and discipline. Better telemetry and tuned detections reduce detection time. Automation and orchestration reduce response time by handling repetitive containment steps instantly. Rehearsed incident-response playbooks and clear decision authority reduce the hesitation that slows human response. Reducing alert fatigue matters too, because analysts buried in false positives are slower to spot and act on the real thing.
These metrics are only as meaningful as the definitions behind them. Two organisations can report very different figures simply because one measures response as containment and the other as full recovery, or because one starts the clock at detection and the other at the first alert. The value is less in the absolute number than in tracking a consistently defined measure over time and driving it down through better detection, automation and rehearsed response.
Precursor tracks detection and response times as core measures of its managed SOC, and uses purple team exercises to test and improve them against realistic attack scenarios rather than reporting them in the abstract.