Mean Time to Detect (MTTD)

Mean Time to Detect (MTTD) is the average time elapsed between the start of a cyber incident and its detection by the security team, serving as a key operational indicator of detection capability and program effectiveness.

Why MTTD Matters

Adversary dwell time is a primary driver of incident severity. Attacks discovered quickly typically produce smaller losses than attacks that persist undetected for extended periods. MTTD measures how quickly detection actually happens, providing a defensible indicator of one dimension of program effectiveness.

Industry data consistently shows that longer detection times correlate with larger loss outcomes, particularly for data breach and ransomware scenarios.

MTTD as a Program Metric

MTTD is useful as an operational metric but has limits as a risk metric. It captures average detection performance, not tail performance. A program with a low MTTD average but occasional very long detection times may still be exposed to significant loss.

Quantified programs treat MTTD as an input to loss modeling rather than as a standalone risk indicator. The distribution of detection times, not just the mean, informs modeled severity.

MTTD and Related Metrics

MTTD is one of a family of "mean time to X" indicators. MTTR (Mean Time to Respond) measures response speed after detection. Mean Time to Contain and Mean Time to Recover extend the same idea further into the incident lifecycle. Reported together, they characterize the operational tempo of the security program.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.