Skip to Content

Your Security Vendor May Not Be Telling You the Truth About Your MTTD – Here's Why

J'Yah Marshall

Imagine a bank robber breaks in at 8:00 p.m. They move quietly through the building for 45 minutes before the on-duty security guard notices and calls 911. Police arrive quickly, arrest the individual, and write the report, recording the break-in time as 8:45 p.m.

That would be inaccurate. The robbery did not start when the security guard called 911. It started when the attacker entered the building. Those first 45 minutes matter. They are the difference between understanding the full incident and reporting only the moment it becomes visible.

No one would accept that kind of reporting in a robbery. However, in cybersecurity, it’s happening all the time.

Many vendors often report Mean Time to Detect (MTTD) as starting after they receive the logs, rather than from the first moment attacker activity begins. That makes MTTD look faster than it really is and gives false confidence.

If MTTD is measured inaccurately, what separates a meaningful metric from a misleading one?

Why is Measuring MTTD Important?

MTTD is one of the most critical metrics in security operations. It gives leaders a clear way to measure how quickly their organization can identify threat activity before it creates business impact. When measured correctly, it helps teams reduce the time attackers have to operate.

That matters because attacker timelines are shrinking. AI gives attackers speed, scale, and a lower skills barrier, executing agentic attacks defenders may have only minutes to stop.

In 2025, the fastest recorded exfiltration time was just 6 minutes. In that window, every delay between the first sign of threat activity and the moment the team can act becomes part of the risk.

A strong MTTD gives leaders confidence in the decisions they make from it. It shows where detection is improving, where risk is increasing, and where the business may need to invest, supporting reporting, decision-making, and performance tracking.

But MTTD only provides value when it reflects the full timeline. If the metric does not capture the time between the true event and actionable detection, it gives leaders an incomplete view of risk.

To understand how fast the organization can identify and mitigate risk, security leaders must first understand how their MTTD is being measured.

Why is MTTD Being Misrepresented?

Today, many security vendors and providers report MTTD, but there’s inconsistency across all of them.

For example, some providers do not start the MTTD clock until logs are indexed, parsed, and stored, or until after data is normalized, removing real exposure time from the metric.

A technology may receive telemetry at 10:00, but normalization may not finish until 10:45. If the clock starts only when the event becomes searchable, the ingestion and processing latency disappears from the MTTD even though the attacker may already be active.

Many vendors measure MTTD differently because it makes their numbers look better. If they measured from the attacker’s first observable action, the metric would show the real delay between compromise and detection—raising hard questions about visibility, latency, and coverage. Instead, they start the clock at the point that makes their detection look fastest.

There are not multiple ways for police to report when a bank robbery started. The same standard should apply to cybersecurity.

When MTTD is measured around a vendor’s visibility instead of the attacker’s first action, the number benefits the vendor more than the customer, leaving leaders with an incomplete view of risk.

What Does a Good MTTD Look Like?

Security leaders need MTTD they can trust. That starts with a clear definition of where the detection clock starts and stops.

A strong MTTD starts from the first observable suspicious or malicious event.

If the first event happens at 10:00, the clock starts at 10:00. It should stop when the alert is triggered. That gives leaders a clear view of how long it took to detect the activity, not how long it took for data to land and become searchable or finish processing.

That definition should stay consistent across the full security stack, including endpoint, identity, cloud, email, network, and SIEM. Detection speed may vary by tool or data source, but the definition of MTTD should not. Otherwise, leaders cannot compare performance, identify gaps, or understand where exposure is created.

Knowing Your True MTTD Helps You Lower It

Measuring MTTD correctly gives teams a clear view of the full gap between first activity and detection. It shows where time is being lost and where the right capabilities are needed to reduce it.

Because ReliaQuest measures MTTD accurately, we’ve been able to develop innovative solutions to close that gap. For example, GreyMatter Transit detects threats while data is still moving, before it is indexed, parsed, or stored, helping teams accelerate detection.

This even extends to large, distributed environments like Circle K, who used GreyMatter Transit to achieve detection in as fast as 4 seconds, ultimately bringing their containment time to under 1 minute. The faster you can detect, the faster you’re able to contain.

As Pat O’Keefe, Head of Global Cybersecurity and Risk Management at Circle K, explained: “The impact of dwell time in general can be very significant, especially at our fuel terminals. If we have to wait 30 minutes to detect an incident happening at a fuel terminal, that could cost millions of dollars in lost revenue.”

What Does This Mean for Security Leaders?

MTTD should not be accepted at face value. For security leaders, that means understanding what activity starts the clock, which delays are excluded, and whether the measurement method is consistent across every tool and data source.

Those answers determine whether MTTD reflects true detection performance or only the part of the timeline a vendor can see.

Accurate MTTD gives leaders a better way to evaluate risk, architecture, and operational speed. It shows where time is being lost and where the defense needs to improve. The point of the metric is not to create a better-looking number. It is to build a faster, stronger security defense.

Learn How GreyMatter Agentic AI Scales Your Security Operations

GreyMatter is an agentic AI security operations platform with 6 agentic Teammates that use hundreds of agent skills and AI tools to work toward an objective, not just tasks.

GreyMatter dashboard active summary