# What is Mean Time to Detect (MTTD)?

> Mean time to detect is the arithmetic average time between a defined starting event and the point at which an organization detects it.

- Canonical URL: https://yellowcube.eu/glossary/mean-time-to-detect/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

In security reporting, the event may be an intrusion, control failure, or other harmful condition. MTTD is meaningful only when the measurement states what starts the clock, what counts as detection and which cases are included.

Possible start points include the first malicious action, first observable evidence, or onset of impact. The endpoint might be the first alert, analyst validation, or formal incident declaration. Those choices produce different numbers, so comparisons across teams or organizations are usually invalid unless their definitions, populations, and data quality match.

### Key points

- **Define the measure:** Document start and end events, time source, population, exclusions, treatment of pauses, and handling of incidents discovered retrospectively.
- **Report the distribution:** Pair the mean with a median, percentiles, sample size, and segmentation by incident type or severity; a few long cases can dominate an average.
- **Interpret carefully:** Changes can reflect improved telemetry or investigation, but also reclassification, case-mix shifts, missing timestamps, or reporting practices.
- **Important limitation:** MTTD includes only events eventually discovered and recognized. Undetected incidents are absent, creating survivorship bias, while recently opened cases may not yet have complete timelines.

### Related terms

[Mean time to respond (MTTR)](<https://yellowcube.eu/glossary/mean-time-to-respond/>) · [Dwell time](<https://yellowcube.eu/glossary/dwell-time/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Security metrics](<https://yellowcube.eu/glossary/security-metrics/>)

### Sources

[NIST glossary: mean time to detect](https://csrc.nist.gov/glossary/term/mean_time_to_detect) · [NIST SP 800-55 Vol. 1](https://csrc.nist.gov/pubs/sp/800/55/v1/final) · [NIST SP 800-55 Vol. 2](https://csrc.nist.gov/pubs/sp/800/55/v2/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

