Mean time to detect (MTTD) is a security operations metric: the average time between when a threat or incident begins in an environment and when it is detected by the organization’s people or tools. It is one of the most common ways to describe how quickly a security team or managed provider notices attacks, and it is often reported alongside response and recovery metrics. A lower MTTD generally means attackers have less time to cause damage before someone knows they are there.
At a glance
- MTTD measures how long threats go unnoticed, averaged across incidents over a period.
- The start time is often established only after investigation, so MTTD is an estimate rather than a stopwatch reading.
- Definitions vary between organizations and vendors, which makes cross-provider comparisons unreliable.
- Detection coverage, monitoring hours and threat hunting all influence it.
- It is usually reported with response metrics, since detecting quickly helps only if someone acts.
What problem it solves
Attackers do most of their damage in the time between getting in and being noticed. That is when they steal credentials, find backups, copy data and prepare ransomware. A company that detects intrusions in hours has a very different risk profile from one that finds them after weeks, even if both own similar tools.
MTTD gives leadership and security teams a way to talk about that window in numbers. It helps answer whether investments in monitoring are working, whether a managed detection and response (MDR) provider is performing, and where detection gaps are. Without some measure of detection speed, security reporting tends to fall back on counts of blocked threats, which say little about the attacks that were not blocked.
How it works
Define the clock. The start point is usually the first malicious activity, such as the initial compromise; the end point is when an alert fires or a person identifies the threat. Some teams measure from the first related event in logs instead. Whatever definition you choose, write it down and use it consistently.
Collect incident data. For each confirmed incident, investigators reconstruct a timeline and record the start and detection times. This relies on logs being collected and retained, often in a security information and event management (SIEM) platform.
Calculate and report. Average the detection times for the period, often with the median as well, since a few long-running incidents can skew the mean. Report the trend and the number of incidents behind it.
Improve. Detection speed improves with broader data coverage, around-the-clock monitoring by a security operations center (SOC) or MDR provider, tuned detection rules and proactive threat hunting for activity that alerts miss.
When it matters for buyers
- When comparing MDR or managed SOC providers. Ask how each defines and measures detection time, rather than comparing headline numbers.
- When negotiating contracts. Understand whether the service level agreement (SLA) covers detection, notification, response or only some of these.
- When reporting to the board. MTTD and response metrics, with clear definitions, tell a better story than counts of blocked attacks.
- After an incident. A long gap between compromise and detection is a strong sign that coverage or monitoring needs work.
Our managed detection and response overview covers what to look for in provider commitments.
Questions to ask vendors
- How do you define and measure detection time, and what are the start and end points?
- Do you report MTTD for our environment specifically, or only across all customers?
- What does your SLA commit to: detection, notification, response, or containment?
- Which data sources do you monitor, and which gaps would slow detection in our environment?
- Is monitoring staffed 24/7, and does detection time differ at night or on weekends?
- How often do you hunt for threats that did not trigger alerts?
How it differs from MTTR
MTTD measures how long it takes to notice a threat. MTTR measures what happens next, but the letters are used for several different metrics: mean time to respond, to remediate, to recover or, in IT operations, to repair. In security reporting it usually means the time from detection to containment or resolution. When a vendor quotes MTTR, ask which one they mean. The two metrics work together: fast detection with slow response still leaves attackers time to act, and a fast response helps only once the threat has been detected.
