Security MTTR Calculator
Compute security mean time to respond across detect, triage, contain, eradicate and recover phases, with automation savings.
Inputs
Mean Time to Respond
20.26hours
MTTR as a Duration
20h 16m
Mean Time to Contain
10.26hours
Detect through contain — when the bleeding stops.
Minutes Saved by Automation
29minutes
Slowest Phase
Slowest phase: detect (8 h, 39.5% of MTTR)
Annual Response Effort
486.3hours/year
Step by step
Values used
Detect phase = 480 minutes; Triage and validate phase = 45 minutes; Contain phase = 120 minutes; Eradicate phase = 360 minutes; Recover and verify phase = 240 minutes; Triage and containment steps automated = 25 %; Incidents of this class per year = 24 incidents/year
Security MTTR
MTTR = detect + triage + contain + eradicate + recover, with triage reduced by the automation share and containment by 60% of it.
Mean time to contain
Mean time to contain = detect + triage + contain — the metric that tracks damage, since eradication and recovery happen after the bleeding stops.
Mean Time to Respond
= 20.26 hours
MTTR as a Duration
= 1,215.75
Mean Time to Contain
= 10.26 hours
Minutes Saved by Automation
= 29 minutes
Slowest Phase
= Slowest phase: detect (8 h, 39.5% of MTTR)
Annual Response Effort
= 486.3 hours/year
How it works
Automation is applied unevenly on purpose: SOAR enrichment and auto-closure remove most of the triage minutes, but containment still needs approvals, change windows and a human decision to isolate a production host, so only about 60% of the automation share carries through. MTTR is the headline SOC metric in most board packs, and decomposing it stops the common trap of celebrating faster triage while containment — the phase that actually limits damage — stays measured in days.
Formulas
Security MTTR
MTTR = detect + triage + contain + eradicate + recover, with triage reduced by the automation share and containment by 60% of it.
- detect
- Compromise to alert confirmed
- triage
- Alert to validated incident
- contain
- Validated to attacker action stopped
- eradicate
- Removing persistence and access
- recover
- Restoring and verifying service
Mean time to contain
Mean time to contain = detect + triage + contain — the metric that tracks damage, since eradication and recovery happen after the bleeding stops.
- MTTC
- Mean time to contain
- damage window
- Period during which the attacker still has access
Frequently Asked Questions
How is Security MTTR calculated?
MTTR = detect + triage + contain + eradicate + recover, with triage reduced by the automation share and containment by 60% of it. Automation is applied unevenly on purpose: SOAR enrichment and auto-closure remove most of the triage minutes, but containment still needs approvals, change windows and a human decision to isolate a production host, so only about 60% of the automation share carries through.
Why does Security MTTR matter?
MTTR is the headline SOC metric in most board packs, and decomposing it stops the common trap of celebrating faster triage while containment — the phase that actually limits damage — stays measured in days.
What values do I need to enter?
This calculator takes 7 inputs: Detect phase, Triage and validate phase, Contain phase, Eradicate phase, Recover and verify phase, Triage and containment steps automated, Incidents of this class per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is MTTR or MTTC the better metric?
MTTC drives risk; MTTR drives cost. Containment ends the attacker's access, so it bounds the damage, while eradication and recovery mostly consume engineering hours. Track both and never let a good MTTR hide a slow containment.
Should MTTR include out-of-hours waiting?
Yes, if that is what really happens. Excluding nights and weekends produces a flattering number that no longer describes your exposure. Measure wall-clock, then use the gap between wall-clock and working-hours MTTR as the business case for 24×7 coverage.