# What is Mean Time to Respond (MTTR)?

> Mean time to respond is the arithmetic average time between a defined starting point and a defined response milestone across a stated set of events or incidents.

- Canonical URL: https://yellowcube.eu/glossary/mean-time-to-respond/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

In security operations, the clock might begin at alert generation, validation, or incident declaration. It might end at acknowledgment, the first defensive action, containment, or another explicitly named outcome.

The acronym MTTR is inherently ambiguous. In security, technology, and reliability reporting it can also mean mean time to repair, recover, remediate, or resolve. Those measures answer different questions. Dashboards and reports should therefore spell out the term, define both timestamps and avoid comparing values that use different endpoints.

### Key points

- **Define the measure:** Record the starting event, response endpoint, eligible cases, clock source, exclusions, pauses, and treatment of reopened incidents.
- **Use supporting statistics:** Show the median, percentiles, sample size, and breakdowns by severity or incident class, because an average can hide both rapid responses and extreme delays.
- **Protect the objective:** Combine speed with outcome measures such as containment quality, recurrence, service impact, and safe recovery rather than optimizing a timer alone.
- **Important limitation:** A lower MTTR is not automatically safer. Incentives tied to speed can encourage premature closure, risky containment, or selecting an easily reached endpoint that does not reduce harm.

### Related terms

[Mean time to detect (MTTD)](<https://yellowcube.eu/glossary/mean-time-to-detect/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Recovery time objective (RTO)](<https://yellowcube.eu/glossary/recovery-time-objective/>) · [Security metrics](<https://yellowcube.eu/glossary/security-metrics/>)

### Sources

[NIST SP 800-55 Vol. 1](https://csrc.nist.gov/pubs/sp/800/55/v1/final) · [NIST SP 800-55 Vol. 2](https://csrc.nist.gov/pubs/sp/800/55/v2/final) · [NIST glossary: mean time to recovery](https://csrc.nist.gov/glossary/term/mean_time_to_recovery) · [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

