MTTD and MTTR: the two SOC KPIs that count
Mean Time to Detect (MTTD) measures how fast a SOC spots an attack. Mean Time to Respond or Contain (MTTR, MTTC) measures how fast it is stopped. Together they are the only credible evidence that a SOC is working, not just running.
How this compares to neighbouring topics
This page explains SOC KPIs. For the operating unit see What is a SOC. For the distinction from managed services see SOC vs. MDR. For the economic case behind these times see SOC ROI. For the platform that produces these times, read What is XDR.
Short definitions
- MTTD (Mean Time to Detect): average time from the first malicious signal to the confirmed alert.
- MTTR (Mean Time to Respond): average time from the alert to the first response action.
- MTTC (Mean Time to Contain): average time until the attacker can no longer cause further damage.
- MTTI (Mean Time to Investigate): optional intermediate measure, common in KPI sheets but operationally secondary.
Realistic targets
| Metric | Without SOC | With modern managed SOC |
|---|---|---|
| MTTD | Median 14 days per Mandiant M-Trends 2026 | Around the clock, typically much shorter than without a SOC |
| MTTR | 24 to 72 hours | under 60 minutes for critical cases |
| MTTC | days to weeks | typically 1 to 4 hours for critical cases |
Targets depend on environment, response rights and stack. Numbers without a stated measurement basis are marketing, not SLAs.
Why alert count is not a metric
Providers advertising 'number of alerts handled' measure effort without showing impact. Two SOCs with the same alert count can deliver completely different MTTD and MTTC. For the economic case behind these differences, see SOC ROI.
How to anchor the numbers in the contract
- Ask for an MTTC target per severity in addition to targets per alert type.
- Require monthly evidence that includes raw data alongside any summary sheet.
- Clarify when the clock starts: first signal timestamp or first alert generation.
- Define response rights in the contract. Without them, every MTTC target is fiction.
Placement in SOC operations
SOC as a Service Switzerland explains how SOC operations achieve these times.
Frequently asked questions
Is an MTTD of zero seconds realistic?
An MTTD of zero seconds is unrealistic. Even automated detection needs signal time, correlation and context. Sub-second numbers in marketing decks usually describe rule triggers alone, before alert confirmation.
Are MTTR and MTTC the same thing?
MTTR and MTTC measure different stages: MTTR measures the first response, while MTTC measures when containment stops the attacker. A SOC can respond in minutes yet take hours until the attacker can do no more damage.
How do response rights affect these numbers?
Response rights strongly affect these numbers. Without permission to isolate endpoints and lock accounts, a SOC can only forecast its MTTC, with no commitment. Specify response rights in the contract; documenting them in a ticket is insufficient.
How long do attackers stay undetected?
According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. Your own value can be higher or lower; the order of magnitude shows why continuous detection matters.
How often should these numbers be reviewed?
Review the numbers in monthly reports and quarterly business reviews that cover trends and recalibrate targets. An annual review is not enough because attackers and environments change faster.
Related terms
- MTTD Mean Time to Detect (MTTD) is the average time from the start of an attack to its detection.
- MTTR Mean Time to Respond (MTTR) is the average time from when an incident is detected until it is contained.
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Playbook A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.