What Is MTTD (Mean Time to Detect)?

Related problems: Not sure how quickly we would notice an attack; Comparing MDR providers' detection speed claims; Board asking for security metrics that mean something; Attackers found in our network long after they got in

Mean time to detect (MTTD) is a security operations metric: the average time between when a threat or incident begins in an environment and when it is detected by the organization’s people or tools. It is one of the most common ways to describe how quickly a security team or managed provider notices attacks, and it is often reported alongside response and recovery metrics. A lower MTTD generally means attackers have less time to cause damage before someone knows they are there.

At a glance

  • MTTD measures how long threats go unnoticed, averaged across incidents over a period.
  • The start time is often established only after investigation, so MTTD is an estimate rather than a stopwatch reading.
  • Definitions vary between organizations and vendors, which makes cross-provider comparisons unreliable.
  • Detection coverage, monitoring hours and threat hunting all influence it.
  • It is usually reported with response metrics, since detecting quickly helps only if someone acts.

What problem it solves

Attackers do most of their damage in the time between getting in and being noticed. That is when they steal credentials, find backups, copy data and prepare ransomware. A company that detects intrusions in hours has a very different risk profile from one that finds them after weeks, even if both own similar tools.

MTTD gives leadership and security teams a way to talk about that window in numbers. It helps answer whether investments in monitoring are working, whether a managed detection and response (MDR) provider is performing, and where detection gaps are. Without some measure of detection speed, security reporting tends to fall back on counts of blocked threats, which say little about the attacks that were not blocked.

How it works

Define the clock. The start point is usually the first malicious activity, such as the initial compromise; the end point is when an alert fires or a person identifies the threat. Some teams measure from the first related event in logs instead. Whatever definition you choose, write it down and use it consistently.

Collect incident data. For each confirmed incident, investigators reconstruct a timeline and record the start and detection times. This relies on logs being collected and retained, often in a security information and event management (SIEM) platform.

Calculate and report. Average the detection times for the period, often with the median as well, since a few long-running incidents can skew the mean. Report the trend and the number of incidents behind it.

Improve. Detection speed improves with broader data coverage, around-the-clock monitoring by a security operations center (SOC) or MDR provider, tuned detection rules and proactive threat hunting for activity that alerts miss.

When it matters for buyers

  • When comparing MDR or managed SOC providers. Ask how each defines and measures detection time, rather than comparing headline numbers.
  • When negotiating contracts. Understand whether the service level agreement (SLA) covers detection, notification, response or only some of these.
  • When reporting to the board. MTTD and response metrics, with clear definitions, tell a better story than counts of blocked attacks.
  • After an incident. A long gap between compromise and detection is a strong sign that coverage or monitoring needs work.

Our managed detection and response overview covers what to look for in provider commitments.

Questions to ask vendors

  • How do you define and measure detection time, and what are the start and end points?
  • Do you report MTTD for our environment specifically, or only across all customers?
  • What does your SLA commit to: detection, notification, response, or containment?
  • Which data sources do you monitor, and which gaps would slow detection in our environment?
  • Is monitoring staffed 24/7, and does detection time differ at night or on weekends?
  • How often do you hunt for threats that did not trigger alerts?

How it differs from MTTR

MTTD measures how long it takes to notice a threat. MTTR measures what happens next, but the letters are used for several different metrics: mean time to respond, to remediate, to recover or, in IT operations, to repair. In security reporting it usually means the time from detection to containment or resolution. When a vendor quotes MTTR, ask which one they mean. The two metrics work together: fast detection with slow response still leaves attackers time to act, and a fast response helps only once the threat has been detected.

Frequently Asked Questions

What is a good MTTD?
There is no universal benchmark, because it depends on how detection is measured and which incidents are counted. Lower is better, and the trend over time in your own environment is more meaningful than a number from someone else's report. Be wary of comparing providers' figures unless they define the metric the same way.
Can an MDR provider guarantee an MTTD in its contract?
Terms vary by provider. Because no one controls when an attack first becomes visible, commitments more often cover response or notification time after an alert fires than detection time itself. Read the SLA to see which clock it measures and whether there are remedies if it is missed.
How do you calculate MTTD?
For each incident, take the time from when the malicious activity started to when it was detected, then average across incidents for the period. Finding the start time usually requires investigation after the fact, so the figure depends on how thorough those investigations are.
Does a lower MTTD always mean better security?
Not necessarily. A team can lower its average by counting many easy, quickly caught alerts while missing slower, stealthier attacks entirely. MTTD is most useful alongside other measures such as response time, coverage of key data sources and the results of testing.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.