Parameter

What is MTTD / MTTR?

Mean time to detect and mean time to respond

What MTTD and MTTR measure, how to calculate them, the traps in using them, and how to bring both down.

01Introduction

Two numbers summarize how a security team performs under attack: how long threats go unnoticed and how long they take to shut down. Boards, auditors and MDR contracts all ask for them.

02What is MTTD / MTTR?

Mean time to detect (MTTD) is the average time between an incident starting and the security team identifying it. Mean time to respond (MTTR) is the average time from detection to containment or resolution. In vulnerability management, MTTR often instead means mean time to remediate a finding.

Both are averages across incidents, so they are best tracked by severity and alongside medians. They are the core outcome metrics of the SOC and of purple team programs.

03How MTTD / MTTR works

Calculating them is simple; getting clean timestamps is the work.

  1. 1.

    Record timestamps

    Capture when the activity began, when it was detected, when it was contained and when it was resolved.

  2. 2.

    Compute

    MTTD is the total detection delay divided by the number of incidents; MTTR is the total response time divided by the same count.

  3. 3.

    Segment

    Split by severity, source and asset type so one long incident doesn't hide a trend.

  4. 4.

    Drive down

    Improve telemetry and detections to lower MTTD, and automate playbooks with SOAR to lower MTTR.

04Threats and risks

The metrics can mislead if handled carelessly.

  • Undetected incidents

    MTTD only counts what was found; missed attacks don't appear at all.

  • Gaming the clock

    Closing tickets early improves MTTR without reducing risk.

  • Averages hide outliers

    A single months-long breach matters more than dozens of quick false positives.

  • Inconsistent definitions

    Teams disagree on when the clock starts and stops, so numbers aren't comparable.

05How Parameter helps

Parameter shortens the remediation side of the clock and removes incidents before they start.

  • Faster time to remediate

    Findings arrive proven and with a fix, so engineers don't spend days reproducing them.

  • Automatic retest

    The pentesting agents confirm each fix, giving a precise close timestamp.

  • Earlier than production

    Sentinel catches flaws in pull requests, before any clock starts.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your MTTD / MTTR program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.