MTTD and MTTR: the two SOC KPIs that count

Mean Time to Detect (MTTD) measures how fast a SOC spots an attack. Mean Time to Respond or Contain (MTTR, MTTC) measures how fast it is stopped. Together they are the only credible evidence that a SOC is working, not just running.

All

How this compares to neighbouring topics

This page explains SOC KPIs. For the operating unit see What is a SOC. For the distinction from managed services see SOC vs. MDR. For the economic case behind these times see SOC ROI. For the platform that produces these times, read What is XDR.

Short definitions

  • MTTD (Mean Time to Detect): average time from the first malicious signal to the confirmed alert.
  • MTTR (Mean Time to Respond): average time from the alert to the first response action.
  • MTTC (Mean Time to Contain): average time until the attacker can no longer cause further damage.
  • MTTI (Mean Time to Investigate): optional intermediate measure, common in KPI sheets but operationally secondary.

Realistic targets

MetricWithout SOCWith modern managed SOC
MTTDMedian 14 days per Mandiant M-Trends 2026Around the clock, typically much shorter than without a SOC
MTTR24 to 72 hoursunder 60 minutes for critical cases
MTTCdays to weekstypically 1 to 4 hours for critical cases
On comparability

Targets depend on environment, response rights and stack. Numbers without a stated measurement basis are marketing, not SLAs.

Why alert count is not a metric

Providers advertising 'number of alerts handled' measure effort without showing impact. Two SOCs with the same alert count can deliver completely different MTTD and MTTC. For the economic case behind these differences, see SOC ROI.

How to anchor the numbers in the contract

  • Ask for an MTTC target per severity in addition to targets per alert type.
  • Require monthly evidence that includes raw data alongside any summary sheet.
  • Clarify when the clock starts: first signal timestamp or first alert generation.
  • Define response rights in the contract. Without them, every MTTC target is fiction.

Frequently asked questions

Is an MTTD of zero seconds realistic?

An MTTD of zero seconds is unrealistic. Even automated detection needs signal time, correlation and context. Sub-second numbers in marketing decks usually describe rule triggers alone, before alert confirmation.

Are MTTR and MTTC the same thing?

MTTR and MTTC measure different stages: MTTR measures the first response, while MTTC measures when containment stops the attacker. A SOC can respond in minutes yet take hours until the attacker can do no more damage.

How do response rights affect these numbers?

Response rights strongly affect these numbers. Without permission to isolate endpoints and lock accounts, a SOC can only forecast its MTTC, with no commitment. Specify response rights in the contract; documenting them in a ticket is insufficient.

How long do attackers stay undetected?

According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. Your own value can be higher or lower; the order of magnitude shows why continuous detection matters.

How often should these numbers be reviewed?

Review the numbers in monthly reports and quarterly business reviews that cover trends and recalibrate targets. An annual review is not enough because attackers and environments change faster.

Continue reading in this cluster
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.
What is XDR? Extended Detection and Response explained
Extended Detection and Response (XDR) is a detection platform that correlates telemetry from endpoint, identity, email, cloud and network in one data model. XDR replaces many functions of a classic SIEM, but it does not replace a team. Only combined with a SOC or MDR does it turn into security.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.