TL;DR: MTTD, MTTC and MTTR can look better than reality because MTTD only measures incidents that were investigated, while the average enterprise SOC handles 4,330 alerts a day and investigates 37% of them, according to Crogl. The real governance issue is coverage, because unworked alerts can leave threats undetected until damage forces a second look.
NHIMG editorial — based on content published by Crogl: MTTD, MTTC, and MTTR: The SOC Metrics That Measure Detection
Questions worth separating out
Q: What breaks when MTTD is measured without alert coverage?
A: MTTD can look strong while the SOC ignores a large share of the queue.
Q: Why does low alert coverage increase security risk?
A: Low coverage leaves weak signals uninvestigated, which gives attackers more time to operate before the SOC sees a pattern.
Q: How can security teams reduce MTTD without hiring more analysts?
A: Shrink the wait between an alert firing and a human investigating it.
Practitioner guidance
- Measure alert coverage alongside MTTD Publish the percentage of alerts investigated in the same dashboard as MTTD, MTTC and MTTR so leadership can see whether the SOC is measuring the whole queue or only the worked subset.
- Rebaseline metric definitions Fix the start and stop points for detection, containment and response, then keep those definitions stable across reporting periods so trend lines stay comparable.
- Automate first-pass investigation Use enrichment and autonomous investigation to reduce the wait between alert arrival and analyst review, especially for repeated identity and authentication signals.
What's in the full article
Crogl's full blog covers the operational detail this post intentionally leaves for the source:
- How the MTTD, MTTC and MTTR formulas are applied across an actual SOC reporting period
- Crogl's explanation of why coverage belongs next to time-to-detect in executive reporting
- The autonomous investigation model used to reduce alert wait time and backlog pressure
- The supporting research context behind the 4,330 daily alerts and 37% investigation rate
👉 Read Crogl's analysis of MTTD, MTTC and MTTR and the SOC coverage gap →
MTTD and coverage gaps: is your SOC measuring the right thing?
Explore further
Coverage, not just speed, is the decisive SOC control variable. A low MTTD can coexist with a weak detection programme if the team only investigates a minority of alerts. That means governance has to measure the queue, not only the cases that reached closure. For identity-led attacks this is especially relevant, because the first sign of abuse may be a low-priority auth event or privilege anomaly. The practitioner conclusion is simple: report detection coverage beside time-to-detect, or the metric will flatter the programme.
A question worth separating out:
Q: What should SOC leaders report to show detection performance honestly?
A: Report MTTD, MTTC and MTTR next to the percentage of alerts investigated in the same period. That combination shows whether speed gains came from better detection operations or from simply working a smaller slice of the queue. It is the cleanest way to keep the metric meaningful for leadership decisions.
👉 Read our full editorial: MTTD, MTTC and coverage: the SOC metric blind spot