TL;DR: Security metrics built around MTTR, MTTD and alert volume lose value when AI systems can process thousands of alerts at once and execute responses autonomously, because defenders are now measured against attacker execution windows, according to Mate. The meaningful test is whether attacks are stopped before they complete, not how efficiently individual alerts are handled.
NHIMG editorial — based on content published by Mate: key takeaways on why traditional security metrics lose relevance with AI
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: How should security teams measure MTTR in AI-driven SOC workflows?
A: Measure MTTR as a set of stages, not one number.
Q: Why do AI-driven systems make traditional SOC metrics less useful?
A: Because AI removes the human bottleneck those metrics were built around.
Q: What do security teams get wrong about appsec alert volume?
A: They often treat more findings as more security, when the real problem is whether the findings are true, reachable, and worth fixing.
Practitioner guidance
- Replace MTTR with attack-window coverage metrics Build a metric set that compares defender containment time against the real execution time of each critical attack path.
- Map identity attack paths to real timelines Use threat intelligence and red-team data to document how long common identity abuse paths take from exposure to objective.
- Report win rate by technique Track containment success by MITRE ATT&CK technique category, not just by incident count.
What's in the full article
Mate's full article covers the operational detail this post intentionally leaves for the source:
- The exact metric formulas the vendor uses to compare attacker execution time with defender containment time.
- The attack-path examples used to convert theory into a board-ready business case for AI-assisted security operations.
- The vendor's approach to mapping win rate across specific MITRE ATT&CK techniques and outcome categories.
- The operational guidance for shifting analysts from triage work into threat hunting and detection engineering.
👉 Read Mate's analysis of why AI security metrics need attack-window accountability →
AI security metrics: what should replace MTTR and alert volume?
Explore further
AI security metrics now need an attack-window model: the old SOC vocabulary assumes defenders and attackers move at different human speeds, but AI collapses that assumption. The decisive question is no longer how many alerts were processed, but whether the attacker’s path to objective was interrupted. That pushes programme owners toward outcome-based governance and away from activity-based reporting.
A question worth separating out:
Q: What should organisations prioritise when attackers can move faster than humans can respond?
A: They should prioritise limiting blast radius before investing further in faster detection. That means narrower privileges, stronger segmentation, and identity boundaries that prevent one foothold from becoming an enterprise-wide event. The goal is not to eliminate every intrusion, but to keep a compromise from becoming a business outage.
👉 Read our full editorial: AI-driven security metrics need attack-window accountability, not MTTR