MTTR
Mean Time to Respond (MTTR) is the average time from when an incident is detected until it is contained.
Mean Time to Respond (MTTR) is the average time from detecting an incident to its containment. It shows how quickly a Security Operations Center stops an attack.
How it works
For each Case, the time is measured between detection and an effective countermeasure. This could be isolating a device, locking an account or blocking a connection. The average time across all Cases gives the MTTR. Analysing by severity is often more insightful because Critical Cases are handled differently from Low ones.
For example, a ransomware precursor is detected at 02:10. The affected server is isolated by 02:18. The time to respond is eight minutes. If the team had waited until morning, the encryption would probably already have run.
What to look out for
- Definition: Clarify if the provider measures to the first reaction or to containment.
- Distribution: A good average can mask individual, very slow cases. Ask for the median value and any outliers.
- After hours: Compare the MTTR during office hours with nights and weekends.
- Mandate: Without pre-approved actions, the SOC waits for a call-back. This significantly increases the MTTR.
Relationship with MTTD
MTTD measures how quickly an attack is detected. MTTR measures how quickly it is stopped. Together, they determine how much time an attacker has in the environment.
How to reduce MTTR
The biggest levers are rarely technical. A clear mandate, well-maintained playbooks and current contact lists are decisive. If the SOC knows in advance which systems it may isolate, waiting for approval is eliminated. A good asset list also helps because analysts can immediately see how critical a system is. Compare the MTTR regularly per scenario, for example for phishing, account takeover and malware.
How we implement it
For Critical Cases, we contractually commit to a response within 60 minutes, 24/7. We typically respond in under 15 minutes.