What is Mean Time to Detect (MTTD)?
Mean Time to Detect (MTTD) measures the average time it takes to identify a security incident or threat after it has occurred. It reflects the effectiveness of monitoring and detection capabilities.
MTTD is influenced by tools such as SIEM, EDR, and Threat Intelligence, as well as processes like Threat Hunting.
What is MTTD used for?
MTTD is used to evaluate detection efficiency and improve visibility into threats. Lower MTTD reduces the dwell time of attackers and limits potential damage.
Organizations track MTTD alongside MTTA and MTTR to optimize Incident Response (IR) and strengthen Security Posture through faster detection and response.