MTTD, MTTC, and MTTR: The SOC Metrics That Measure Detection
Mike Dupuis
Director of Marketing, Crogl

MTTD, MTTC, and MTTR are the three clocks a security operations center runs against. They measure how fast a team detects a threat, contains it, and resolves it. Together they turn a vague question, "are we getting better?", into a number you can track quarter over quarter.
| Metric | Full name | What it measures | Basic formula |
|---|---|---|---|
| MTTD | Mean time to detect | Time from when a threat is active to when the SOC detects it | total detection time / number of incidents |
| MTTC | Mean time to contain | Time from detection to containment (the threat can no longer spread) | total containment time / number of incidents |
| MTTR | Mean time to respond (or resolve) | Time from detection to full response or recovery | total response time / number of incidents |
Why MTTD sets the ceiling
You cannot contain or resolve what you have not detected. Every hour a threat goes unseen is dwell time, and dwell time is when an attacker moves laterally, escalates, and does the real damage. If MTTD is high, strong MTTC and MTTR numbers barely help, because the clock on the damage has already been running. Detection sets the ceiling.
There is a hidden driver behind a bad MTTD: alerts that never get investigated. When a SOC only works a fraction of its queue, its true detection time is worse than the dashboard shows, because the alert that mattered may be sitting unread. Crogl's 2026 State of SecOps research put that fraction at about 37% of roughly 4,300 daily alerts. The other 63% is unmeasured MTTD.
How to calculate each metric
Each metric is an average across a set of incidents over a period:
- MTTD = total time from threat onset to detection, divided by the number of incidents.
- MTTC = total time from detection to containment, divided by the number of incidents.
- MTTR = total time from detection to full response or recovery, divided by the number of incidents.
The trap is the start and stop points. Decide when the clock starts (threat onset, first signal, or first alert) and when it stops, then hold those definitions steady. Change them mid-quarter and the trend line lies to you.
What "good" looks like
Benchmarks swing widely by industry, tooling, and threat type, so track your own trend rather than someone else's headline number. The target that matters is an MTTD and MTTC that fall period over period. Watch for a vanity trap here. Closing alerts faster can look like progress. Detecting real threats faster is the actual goal, and the two are not the same thing.
Where AI changes the math
The bottleneck in MTTD is rarely the detection rule. It is the gap between an alert firing and a human actually investigating it. When every alert gets investigated the moment it arrives, that gap collapses.
That is the model Crogl uses. Investigate every alert on arrival, gather context from the tools where the data already lives, and hand the analyst a documented finding. Because investigations are not metered per alert or per seat, the whole queue stays in reach, not only the 37% a team has hours for. The analyst still makes the call. The clock starts sooner, and it runs against every alert, not a sample.
This holds up in production. A global financial institution using this model cut analyst triage time by more than 70%, which pulls MTTD down because alerts get investigated on arrival instead of waiting in a queue.
Frequently asked questions
What is MTTD?
MTTD, or mean time to detect, is the average time between when a threat becomes active in your environment and when your SOC detects it. Lower is better, and it sets the ceiling for every downstream metric.
What is the difference between MTTD, MTTC, and MTTR?
MTTD measures detection speed, MTTC measures how fast a detected threat is contained, and MTTR measures time to full response or resolution. Detection comes first, so MTTD gates the other two.
How do you calculate mean time to detect?
Add up the time from threat onset to detection across all incidents in a period, then divide by the number of incidents. Keep the "start" and "stop" definitions consistent so the trend is comparable.
What is a good MTTD?
There is no universal number. Good means a measurable downward trend on a consistent definition, and a detection time that reflects your whole alert queue rather than the share you had time to investigate.