In security reporting, the event may be an intrusion, control failure, or other harmful condition. MTTD is meaningful only when the measurement states what starts the clock, what counts as detection and which cases are included.
Possible start points include the first malicious action, first observable evidence, or onset of impact. The endpoint might be the first alert, analyst validation, or formal incident declaration. Those choices produce different numbers, so comparisons across teams or organizations are usually invalid unless their definitions, populations, and data quality match.
Key points
Define the measureDocument start and end events, time source, population, exclusions, treatment of pauses, and handling of incidents discovered retrospectively.
Report the distributionPair the mean with a median, percentiles, sample size, and segmentation by incident type or severity; a few long cases can dominate an average.
Interpret carefullyChanges can reflect improved telemetry or investigation, but also reclassification, case-mix shifts, missing timestamps, or reporting practices.
Important limitationMTTD includes only events eventually discovered and recognized. Undetected incidents are absent, creating survivorship bias, while recently opened cases may not yet have complete timelines.