Why Security Vendors’ MTTD Metrics May Understate Detection Delays

· Original article ↗

Summary

The article argues that MTTD can look faster when its clock starts only after logs are processed. It recommends measuring from the first observable suspicious event until an alert is triggered, consistently across security tools.

Key points

  • Some providers start the MTTD clock only after logs are indexed, parsed, normalized, or searchable, excluding time when attackers may already be active.
  • The article recommends starting the clock at the first observable suspicious or malicious event and stopping it when an alert is triggered.
  • It says organizations should apply the same MTTD definition across endpoint, identity, cloud, email, network, and SIEM tools to make results comparable.
  • The article cites a 2025 fastest recorded exfiltration time of six minutes to emphasize the potential cost of detection delays.
  • Security leaders are advised to ask what starts and stops the clock, which processing delays are excluded, and whether measurement is consistent across data sources.

Article Details

Topic
Measuring Mean Time to Detect (MTTD) from the first observable suspicious or malicious event to the triggered alert

People

Vendors

Products

Related Articles