01Introduction
Two numbers summarize how a security team performs under attack: how long threats go unnoticed and how long they take to shut down. Boards, auditors and MDR contracts all ask for them.
02What is MTTD / MTTR?
Mean time to detect (MTTD) is the average time between an incident starting and the security team identifying it. Mean time to respond (MTTR) is the average time from detection to containment or resolution. In vulnerability management, MTTR often instead means mean time to remediate a finding.
Both are averages across incidents, so they are best tracked by severity and alongside medians. They are the core outcome metrics of the SOC and of purple team programs.
03How MTTD / MTTR works
Calculating them is simple; getting clean timestamps is the work.
- 1.
Record timestamps
Capture when the activity began, when it was detected, when it was contained and when it was resolved.
- 2.
Compute
MTTD is the total detection delay divided by the number of incidents; MTTR is the total response time divided by the same count.
- 3.
Segment
Split by severity, source and asset type so one long incident doesn't hide a trend.
- 4.
Drive down
Improve telemetry and detections to lower MTTD, and automate playbooks with SOAR to lower MTTR.
04Threats and risks
The metrics can mislead if handled carelessly.
Undetected incidents
MTTD only counts what was found; missed attacks don't appear at all.
Gaming the clock
Closing tickets early improves MTTR without reducing risk.
Averages hide outliers
A single months-long breach matters more than dozens of quick false positives.
Inconsistent definitions
Teams disagree on when the clock starts and stops, so numbers aren't comparable.
05How Parameter helps
Parameter shortens the remediation side of the clock and removes incidents before they start.
Faster time to remediate
Findings arrive proven and with a fix, so engineers don't spend days reproducing them.
Automatic retest
The pentesting agents confirm each fix, giving a precise close timestamp.
Earlier than production
Sentinel catches flaws in pull requests, before any clock starts.

