Skip to main content
Category: Metrics & Reporting

Mean Time to Detect

Also known as: MTTD, Mean Time to Detect (MTTD)
Simply put

Mean Time to Detect (MTTD) is a metric that measures the average amount of time it takes an organization to discover a security threat, incident, or problem after it begins. In simple terms, it shows how long an issue exists before anyone notices it. A shorter MTTD generally indicates faster discovery, though the metric only measures detection, not how quickly the issue is then resolved.

Formal definition

Mean Time to Detect (MTTD) is a security operations metric that quantifies the average elapsed time between the onset of malicious activity, a security incident, or a failure and the point at which it is discovered by the responsible team, such as a SOC. It is typically used alongside Mean Time to Respond (MTTR), which measures response duration rather than detection. MTTD reflects detection efficiency but does not, on its own, indicate remediation speed or overall program effectiveness; from a governance perspective, a virtual CISO may use MTTD to advise on monitoring and detection maturity, while operational measurement and improvement of the metric generally remain the responsibility of the internal or contracted security operations function.

Why it matters

Mean Time to Detect matters because the length of time a threat goes unnoticed often shapes the scope of potential damage. An issue that exists undetected can persist, spread, or escalate before anyone begins to respond, so MTTD serves as an early indicator of how effective an organization's monitoring and detection capabilities actually are. It measures the gap between when a problem begins and when it is found, which is a distinct question from how well the organization then handles what it discovers.

Because MTTD only measures detection, it is easy to misread in isolation. A low MTTD does not by itself indicate a mature or effective security program; it must be interpreted alongside Mean Time to Respond (MTTR), which measures response duration rather than detection. An organization could detect issues quickly but still remediate slowly, or vice versa. Treating MTTD as a proxy for overall program effectiveness is a common mistake that an experienced security leader would push back on, since detection speed is one dimension of a broader operational picture.

From a governance standpoint, MTTD is useful as a conversation starter about detection and monitoring maturity rather than as a guaranteed outcome. A virtual CISO may reference MTTD when advising on where detection coverage is thin or where investment in monitoring could reduce dwell time, but the value of the metric depends heavily on how consistently and accurately it is measured. Poorly defined start points, incomplete logging, or gaps in coverage can make the number misleading, so context matters more than the figure alone.

Who it's relevant to

Security Operations Teams and SOC Analysts
SOC and internal security operations teams own the day-to-day measurement of MTTD, since they operate the monitoring and detection tooling that surfaces threats. For these teams, MTTD is a practical indicator of detection coverage and efficiency, most useful when paired with MTTR and interpreted with an understanding of the limits of establishing an accurate incident start time.
Virtual and Fractional CISOs
A virtual or fractional CISO may use MTTD as a governance lens to advise on detection and monitoring maturity, identify coverage gaps, and guide investment decisions. This is typically an advisory function; the vCISO directs strategy rather than operating detection tooling, and accountability for measuring and improving MTTD generally remains with the internal or contracted security operations function and the client's officers.
Executives and Business Risk Owners
Executives and organizational leaders benefit from understanding MTTD as a business risk signal, since the time a threat goes undetected can influence potential impact. Leaders should treat it as one dimension of program health rather than a guarantee of security outcomes, recognizing that the metric reflects detection speed alone and does not, on its own, indicate remediation speed or overall effectiveness.
Compliance and Audit Stakeholders
Teams responsible for audit and compliance reporting may reference MTTD as evidence of detection capability maturity. Its usefulness in this context depends on consistent, well-defined measurement, and it should not be overstated as proof of compliance or as a substitute for the broader controls that a given framework or standard expects.

Inside MTTD

Detection Window
The elapsed time between when a security incident or compromise begins and when it is first detected by tools, analysts, or automated alerting. MTTD is calculated as an average across incidents over a defined measurement period.
Time of Compromise (Start Point)
The point at which the malicious activity or condition actually began. This is often estimated retrospectively during investigation and may vary in accuracy, which can affect the reliability of the MTTD figure.
Time of Detection (End Point)
The moment the incident is confirmed or flagged as suspicious. Depending on how an organization defines detection, this may be the initial alert, the point of triage confirmation, or the point of analyst acknowledgment, and definitions vary by provider and program.
Measurement Scope and Baseline
The set of incidents, environments, or detection sources included in the calculation. A consistent scope and baseline are needed for the metric to be comparable over time; changing what is counted can distort trends.
Relationship to Related Metrics
MTTD is typically tracked alongside metrics such as mean time to respond and mean time to remediate. It reflects detection capability specifically and does not by itself describe how quickly an incident is contained or resolved.
Governance and Reporting Context
In a virtual or fractional CISO engagement, MTTD is often used as a governance indicator to advise on detection maturity and risk, rather than a task the security leader personally executes. The underlying data usually depends on the client's operational tooling and teams.

Common questions

Answers to the questions practitioners most commonly ask about MTTD.

Does hiring a virtual CISO automatically lower our Mean Time to Detect?
Not directly. MTTD is an operational detection metric that depends on tooling, monitoring coverage, alerting configuration, and the people who watch and triage alerts, such as a SOC. A virtual CISO typically advises on detection strategy, sets targets, and helps prioritize investments that can influence MTTD over time, but they generally do not perform hands-on monitoring or incident triage unless that is explicitly contracted. Any improvement usually depends on the organization implementing the recommended changes and on the maturity of existing detection capabilities.
Is a low MTTD the same as being secure or breach-proof?
No. MTTD measures how quickly threats are detected, not whether they are prevented or how effectively they are contained. A short detection time is valuable but does not guarantee an organization is secure, and no engagement type can guarantee breach prevention. MTTD is one indicator among several, often considered alongside metrics such as time to respond and time to contain. Interpreting it in isolation can create a false sense of assurance, which is a distinction an experienced security leader would insist on clarifying.
How can a virtual CISO help us start measuring MTTD if we don't track it today?
A virtual CISO can typically help by defining what constitutes a detectable event, clarifying the start and end points of the measurement, and identifying which data sources and logs are required. In many engagements they focus on governance and process, helping the organization establish baselines and reporting cadence, while the operational instrumentation is handled by internal teams or a monitoring provider. The value of this work often depends on stakeholder cooperation and access to the systems and telemetry needed to measure detection reliably.
How should MTTD targets be set for our organization?
Targets often vary by organizational maturity, threat profile, regulatory context, and the criticality of specific systems. A virtual CISO commonly helps translate business risk tolerance into practical detection targets rather than applying a universal benchmark. It is generally advisable to set targets that reflect current capability and improve them incrementally as monitoring coverage and processes mature. Accountability for accepting the associated risk typically remains with the client organization and its officers.
Where does MTTD fit relative to frameworks like NIST CSF or SOC 2?
MTTD relates most closely to detection and monitoring activities, which map conceptually to functions such as Detect within the NIST Cybersecurity Framework and to monitoring controls that may be relevant in SOC 2 examinations. A virtual CISO can support readiness by helping align detection practices with these frameworks, but tracking MTTD does not by itself assert certification or attestation. Achieving certification depends on a formal assessment or audit conducted by the appropriate independent party.
Who is responsible for acting on MTTD data once it is collected?
Responsibility for operational response to detected events typically rests with the SOC, incident response team, or a contracted service provider, not with a virtual CISO in a standard advisory scope. The virtual CISO commonly reviews MTTD trends, reports them to leadership, and recommends improvements, while accountability for security decisions and for allocating resources to act on the data generally remains with the client organization. Clarifying these boundaries in the engagement scope helps avoid the common mistake of assuming the vCISO replaces an operational team.

Common misconceptions

A lower MTTD guarantees that breaches are being prevented.
MTTD measures how quickly incidents are detected, not whether they occur. A strong detection time does not prevent compromise and should not be presented as a guarantee of breach prevention; it is one indicator among several of program effectiveness.
A virtual CISO improves MTTD by directly monitoring the environment and running detection tools.
A virtual or fractional CISO typically advises on strategy, governance, and program design rather than performing hands-on SOC monitoring, tool administration, or alert triage unless those operational tasks are explicitly contracted. Actual detection work generally remains with the client's team or a separate managed service provider.
MTTD is an objective, universally comparable number across organizations.
MTTD depends heavily on how an organization defines the start and end points, what incidents are in scope, and the accuracy of retrospective compromise-time estimates. These definitions often vary by provider and program, so figures may not be directly comparable between organizations.

Best practices

Define the start point (time of compromise) and end point (time of detection) explicitly and document these definitions so the metric remains consistent and defensible over time.
Track MTTD alongside related metrics such as time to respond and time to remediate, since detection speed alone does not describe containment or resolution.
Establish a stable measurement scope and baseline, and avoid silently changing what is counted, which can distort trends and undermine comparisons.
Use MTTD as a governance and risk-communication indicator for leadership discussions rather than treating it as proof of breach prevention or a purely technical score.
Clarify accountability in the engagement: a virtual or fractional CISO can advise on improving MTTD and interpret the data, but responsibility for the operational detection work and accountability for security decisions typically remain with the client organization unless the contract specifies otherwise.
Recognize that the value of MTTD depends on organizational maturity, data quality, and client cooperation, and qualify reported figures accordingly rather than presenting them as absolutes.