Mean Time to Detect
Mean Time to Detect (MTTD) is a metric that measures the average amount of time it takes an organization to discover a security threat, incident, or problem after it begins. In simple terms, it shows how long an issue exists before anyone notices it. A shorter MTTD generally indicates faster discovery, though the metric only measures detection, not how quickly the issue is then resolved.
Mean Time to Detect (MTTD) is a security operations metric that quantifies the average elapsed time between the onset of malicious activity, a security incident, or a failure and the point at which it is discovered by the responsible team, such as a SOC. It is typically used alongside Mean Time to Respond (MTTR), which measures response duration rather than detection. MTTD reflects detection efficiency but does not, on its own, indicate remediation speed or overall program effectiveness; from a governance perspective, a virtual CISO may use MTTD to advise on monitoring and detection maturity, while operational measurement and improvement of the metric generally remain the responsibility of the internal or contracted security operations function.
Why it matters
Mean Time to Detect matters because the length of time a threat goes unnoticed often shapes the scope of potential damage. An issue that exists undetected can persist, spread, or escalate before anyone begins to respond, so MTTD serves as an early indicator of how effective an organization's monitoring and detection capabilities actually are. It measures the gap between when a problem begins and when it is found, which is a distinct question from how well the organization then handles what it discovers.
Because MTTD only measures detection, it is easy to misread in isolation. A low MTTD does not by itself indicate a mature or effective security program; it must be interpreted alongside Mean Time to Respond (MTTR), which measures response duration rather than detection. An organization could detect issues quickly but still remediate slowly, or vice versa. Treating MTTD as a proxy for overall program effectiveness is a common mistake that an experienced security leader would push back on, since detection speed is one dimension of a broader operational picture.
From a governance standpoint, MTTD is useful as a conversation starter about detection and monitoring maturity rather than as a guaranteed outcome. A virtual CISO may reference MTTD when advising on where detection coverage is thin or where investment in monitoring could reduce dwell time, but the value of the metric depends heavily on how consistently and accurately it is measured. Poorly defined start points, incomplete logging, or gaps in coverage can make the number misleading, so context matters more than the figure alone.
Who it's relevant to
Inside MTTD
Common questions
Answers to the questions practitioners most commonly ask about MTTD.