Skip to main content
July 3, 2026

MTTD, MTTC, and MTTR: The SOC Metrics That Measure Detection

MD

Mike Dupuis

Director of Marketing, Crogl

MTTD, MTTC, and MTTR dashboard cards showing 18:47, 2:41:32, and 8:19:10 with a before/after timeline comparing an unchanged detect-contain-resolve sequence against one where every alert is investigated on arrival, cutting the time before the clock even starts

MTTD, MTTC, and MTTR are the three clocks a SOC runs against: mean time to detect, to contain, and to respond. Every security leader reports them, and most report them flatteringly, because of one thing the dashboard does not surface. Your MTTD is an average over the alerts you investigated, and in the average enterprise SOC that is a minority of them.

MetricFull nameWhat it measuresBasic formula
MTTDMean time to detectTime from when a threat is active to when the SOC detects ittotal detection time / number of incidents
MTTCMean time to containTime from detection to containmenttotal containment time / number of incidents
MTTRMean time to respond (or resolve)Time from detection to full response or recoverytotal response time / number of incidents

Why MTTD sets the ceiling

Containment and response cannot start before detection, so MTTD caps what the other two can achieve. A fast MTTC on a threat you detected late is a fast clock on a fire that has been burning for a week. Dwell time, the interval an attacker operates undetected, is where the loss compounds, and MTTD is the number that governs it.

The denominator nobody puts on the slide

Here is the blind spot. MTTD averages the incidents you detected and worked. It is silent on the alerts that fired and were never investigated, and in the ninety minutes it takes to clear one routine alert, a lot of them pile up unworked.

Crogl's 2026 State of SecOps research, run through the Ponemon Institute, found the average enterprise SOC takes in 4,330 alerts a day and investigates 37% of them. For any real threat sitting in the other 63%, the true time to detect runs until the damage forces a second look, however many days that takes. So MTTD has a partner metric almost no one reports: coverage, the share of the queue you investigate at all. A four-hour MTTD across the whole queue is a healthier program than a one-hour MTTD across a third of it.

How to calculate MTTD, MTTC, and MTTR

Each is an average across a set of incidents over a period:

  • MTTD = total time from threat onset to detection, divided by number of incidents.
  • MTTC = total time from detection to containment, divided by number of incidents.
  • MTTR = total time from detection to full response or recovery, divided by number of incidents.

Two rules keep them honest. Fix your start and stop points and hold them steady, or the trend lies. And report coverage next to MTTD, so a shrinking denominator cannot pass for progress.

How to actually reduce MTTD

The constraint on MTTD is rarely the detection rule. It is the wait between an alert firing and a human having time to investigate it. Headcount does not scale to close that gap, and playbook automation only covers the alerts someone scripted ahead of time.

The gap closes when every alert is investigated on arrival. That is the model behind autonomous investigation: work each alert as it lands, gather context from the tools where the data already lives with no normalization step, and hand the analyst a documented finding. Because investigations are not metered per alert or per seat, the whole queue stays in reach instead of the fraction a team has hours for. A Fortune 100 financial institution running this way cut analyst triage time by more than 70%, which moves MTTD for a plain reason: alerts get worked when they arrive, and the coverage denominator finally reaches 100%.

Related reading

Frequently asked questions

What is MTTD? MTTD, mean time to detect, is the average time between when a threat becomes active in your environment and when your SOC detects it. It sets the ceiling for every downstream metric, and it only reflects the alerts you actually investigated, so read it next to your coverage rate.

What does MTTD stand for? MTTD stands for mean time to detect. Its companions are MTTC (mean time to contain) and MTTR (mean time to respond or resolve).

What is the difference between MTTD and MTTR? MTTD measures how long a threat goes undetected. MTTR measures how long from detection to full response or resolution. MTTC sits between them, covering time to contain. Detection comes first, so MTTD gates both.

How do you calculate MTTD? Add the time from threat onset to detection across all incidents in a period, then divide by the number of incidents. Keep the start and stop definitions consistent, and note what share of your alert queue those incidents represent.

How do you reduce MTTD? Close the wait between an alert firing and a human investigating it. Hiring and scripted playbooks only go so far; the durable move is investigating every alert on arrival so nothing sits unworked, which also lifts coverage toward 100%.

What is a good MTTD? There is no universal number. A good MTTD is a downward trend on a consistent definition, measured across the whole alert queue rather than the slice you had time to investigate. Coverage is the figure that keeps it honest.

Download Crogl free.