GlossarySOC and monitoring

MTTD and MTTR

Short answer

MTTD (Mean Time to Detect) is the average time between the start of a security incident and its detection. MTTR (Mean Time to Respond, or to Recover) is the average time from detection until the threat is contained or the service is restored. The lower both are, the less damage an attack can do.

Why they matter

Attackers need time: to move through the network, gain privileges, find data and launch ransomware. Every hour they remain undetected increases the damage. MTTD shows how quickly the organisation sees an attack, and MTTR how quickly it acts once it does.

How they are measured

For each incident, record when it started (often known only after investigation), when it was detected, when it was contained and when normal operations were restored. Averages over a period, or medians to avoid distortion from a single long incident, show the trend. Definitions should be agreed in advance, because MTTR is used both for response and for recovery.

What improves them

Detection improves with coverage and context: EDR on every device, logs from key systems in a SIEM and a SOC that reviews and investigates alerts. Response improves with a tested incident response plan, clear authority to act and automation of routine steps through SOAR.

Using them well

These metrics are useful for management reporting and for comparing providers, but they only make sense with consistent definitions. A low MTTD on a narrow set of monitored systems can hide large blind spots.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub