Skip to content

MTTD / MTTR

Definition

Mean Time to Detect and Mean Time to Respond: the two primary operational KPIs for a SOC. MTTD measures the gap between a compromise occurring and an alert firing; MTTR measures the gap between alert and containment. Both are shortened by tight tool integration.

Full names
Mean Time to Detect, Mean Time to Respond
Field
SOC / SIEM operations
MTTD measures
Compromise to alert
MTTR measures
Alert to containment

Common questions

Why are MTTD and MTTR tracked as separate metrics rather than one combined number?+

Detection and response depend on different capabilities: MTTD reflects how well the SIEM's detection rules and log coverage surface an intrusion, while MTTR reflects analyst workflow efficiency and playbook maturity, so separating them lets a SOC diagnose which stage of its process needs improvement.

What kinds of tool integration typically improve MTTD and MTTR?+

Centralised log ingestion with correlation rules shortens MTTD by surfacing multi-source patterns automatically, while SOAR playbooks that automate containment actions such as isolating a host shorten MTTR by removing manual steps from the response chain.

Do lower MTTD and MTTR values always mean better security outcomes?+

Generally yes, but the metrics can be gamed by tuning alert thresholds to catch only easy, low-impact events quickly while missing sophisticated intrusions, so SOC maturity assessments look at MTTD/MTTR alongside detection coverage and false-negative rate, not in isolation.

Related terms

EDR (Endpoint Detection and Response)
An agent-based security tool deployed on individual endpoints (workstations, servers, mobile devices) that monitors process execution, file changes, network connections, and registry...
SIEM (Security Information and Event Management)
A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
SOAR (Security Orchestration, Automation, and Response)
A platform that receives alerts from the SIEM and other sources, executes automated playbooks to enrich and triage them, and integrates with...
STIX / TAXII
Structured Threat Information eXpression (STIX) is a standardised language for describing threat intelligence objects. Trusted Automated eXchange of Intelligence Information (TAXII) is...
Threat Intelligence Platform (TIP)
A system that ingests indicator feeds from external providers and internal sources, deduplicates and scores them, and exports curated indicators of compromise...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.