Skip to content
MSPagenda

Mean Time to Detect (MTTD)

In the world of managed services, we often talk about 'uptime,' 'tickets closed,' and 'response times.' These are the metrics that keep the lights on. However, when a client’s business is under threat from a cyberattack, those metrics take a back seat to a much more critical number: Mean Time to Detect (MTTD).

Also known as
MTTD
Category
operations
Source
MSP Agenda editorial methodology

In the world of managed services, we often talk about "uptime," "tickets closed," and "response times." These are the metrics that keep the lights on. However, when a client’s business is under threat from a cyberattack, those metrics take a back seat to a much more critical number: Mean Time to Detect (MTTD).

At its core, MTTD measures how long a threat remains invisible within a client’s environment before your team or your tools flag it. For an MSP, this isn't just a technical data point. It is a direct reflection of your service quality, your risk management strategy, and ultimately, your commercial value to the client.

Luis Navarro, the founder of MSP Agenda, spent over 15 years building Totality Services into a highly profitable MSP with operations in London and Johannesburg. During that journey, which culminated in an eight-figure acquisition, Luis learned that clients don't care about the intricacies of log analysis. They care about how quickly you can stop a problem before it becomes a catastrophe.

Key Takeaways

  • Visibility is the Foundation: You cannot detect what you cannot see. MTTD relies heavily on comprehensive monitoring across all client endpoints and cloud environments.
  • Commercial Impact: Lowering MTTD reduces the potential "blast radius" of an attack, saving clients from costly downtime and protecting your MSP’s reputation.
  • Signal vs. Noise: Effective detection isn't about more alerts; it’s about better alerts. Alert fatigue is the primary enemy of a low MTTD.
  • Process Over Tools: While software is necessary, the human processes and triage workflows within your SOC or helpdesk are what truly drive speed.
  • Client Communication: MTTD is a powerful metric for QBRs (Quarterly Business Reviews) to demonstrate why security investments are working.

What is Mean Time to Detect (MTTD)?

Mean Time to Detect (MTTD) is a cybersecurity metric that calculates the average time it takes for an organisation to become aware of a potential security incident or threat. It is the duration between the moment an attacker gains access or a system failure occurs and the moment the incident is identified by security tools or personnel.

  • Starts at: The moment of initial compromise or incident occurrence.
  • Ends at: The moment the alert is validated as a legitimate security event.
  • Goal: To minimise this window to prevent lateral movement and data exfiltration.
Metric ComponentDescriptionMSP Significance
Incident StartThe timestamp when the threat first entered the environment.Often identified via forensic logs after the fact.
Detection PointWhen the MSP is first alerted to the suspicious activity.Reflects the effectiveness of your SIEM/EDR stack.
ValidationConfirming the alert is a "True Positive" rather than noise.Reflects the skill and speed of your technical team.

Calculating MTTD: The Formula

To calculate Mean Time to Detect (MTTD), you take the sum of the time it took to detect each incident during a specific period and divide it by the total number of incidents. It’s a straightforward average, but the data inputs must be accurate to mean anything.

For example, if you had three incidents last month:

  • Incident 1: Detected in 10 minutes.

  • Incident 2: Detected in 50 minutes.

  • Incident 3: Detected in 120 minutes.

Your MTTD would be (10 + 50 + 120) / 3 = 60 minutes.

The Challenge of "Hidden" Start Times

The hardest part of this calculation for MSPs is identifying the exact "Incident Start." Attackers are experts at staying quiet. This is why standardising your security stack is vital. When every client is on the same EDR and logging platform, you have a consistent baseline to measure these timestamps accurately.

Common Barriers to a Low MTTD

In his 15 years building Totality Services, Luis Navarro saw that technical hurdles were rarely the biggest problem. The real barriers to speed are usually found in the gaps between tools and people. If your team is overwhelmed or your tools are misconfigured, your detection speed will suffer.

1. Alert Fatigue

If your helpdesk is receiving 500 "Critical" alerts a day, they will eventually start ignoring them. This is the "boy who cried wolf" syndrome of cybersecurity. When a real threat arrives, it gets buried under a mountain of low-value notifications about expired passwords or routine software updates.

2. Lack of Centralised Visibility

Many MSPs suffer from "siloed data." One tool monitors the firewall, another monitors the endpoints, and a third monitors Microsoft 365. If these tools don't talk to each other, you have to manually piece together the story. That manual work adds hours or days to your MTTD.

3. Complex Client Environments

We all have that one client with a "legacy" server in the corner that no one wants to touch. These unmanaged or non-standardised assets are blind spots. You cannot detect a threat on a machine that isn't reporting into your central management console.

Practical Steps to Improve MTTD

Improving MTTD isn't about buying the most expensive tool on the market. It’s about building a structured approach to visibility and triage. You want your team to work smarter, not just harder.

Standardise Your Security Stack

Standardisation is the secret to MSP profitability and security. If you are supporting five different antivirus products across your client base, your team will never be experts in any of them. By moving everyone to a single, high-quality EDR (Endpoint Detection and Response) solution, you ensure that your team knows exactly how to interpret and validate alerts quickly.

Implement MDR or SOC-as-a-Service

For many small to mid-sized MSPs, running a 24/7 Security Operations Centre (SOC) is financially impossible. However, threats don't wait for business hours. Leveraging a 24/7 Managed Detection and Response (MDR) provider allows you to lower your MTTD overnight. They do the heavy lifting of watching the screens while your team focuses on high-value client relationships.

Automate the Triage

Use automation to filter out the noise. If an alert can be automatically closed because it matches a known safe pattern, do it. The goal is to ensure that when a human finally looks at an alert, it is because that alert genuinely requires human intuition and decision-making.

Improving Detection Through Better Client Conversations

Sometimes the best way to improve MTTD is to convince the client to remove the risk entirely. If a client is using an outdated, unpatchable application, your ability to detect threats on that system is limited. Use your Security Reviews to explain that "the risk of this legacy system is that we might not see a breach until it's too late."

Using MTTD in Your Commercial Strategy

MSP Agenda is built on the belief that great technology alone isn't enough. Clients need to understand the risk. MTTD is one of the best ways to bridge the gap between technical reality and business logic.

During the Sales Process

When pitching to a new prospect, don't just talk about "security." Talk about time. Ask them, "If a hacker got into your system today, how long would it take for you to find out?" Most business owners have no idea. When you explain that your average Mean Time to Detect (MTTD) is measured in minutes while the industry average is months, you are selling peace of mind, not just software.

In Quarterly Business Reviews (QBRs)

A common complaint from MSP owners is that clients don't see the value of their security spend because "nothing ever happens." Use MTTD data to show them what almost happened.

"Last quarter, we detected three attempts to bypass your multi-factor authentication. Our average detection time was 4 minutes, allowing us to lock the accounts before any data was accessed." This turns a "quiet" quarter into a win for the MSP.

MTTD and the Cybersecurity Journey

Every MSP is at a different stage of maturity. Some are just starting to move beyond basic antivirus, while others are managing complex, multi-layered security environments. Improving MTTD is a journey, not a destination.

  • Level 1: Reactive. Detection happens when the client calls the helpdesk because their files won't open. MTTD is days or weeks.
  • Level 2: Proactive. You have basic monitoring in place. You get alerts for failed logins or virus detections. MTTD is hours.
  • Level 3: Managed. You have a centralised SIEM/EDR and 24/7 monitoring. You are hunting for threats before they trigger a major alert. MTTD is minutes.

Luis Navarro’s experience building Totality Services showed that moving from Level 1 to Level 3 is what allows an MSP to scale. It moves you away from being a "reactive vendor" and toward being a "strategic partner." This shift is what ultimately drives enterprise value and makes a business attractive for acquisition.

Common Misconceptions About MTTD

There are several myths that can lead MSPs down the wrong path when trying to optimise their detection times. Let's clear those up.

"Zero MTTD is the Goal"

In a perfect world, we would detect every threat instantly. In reality, some sophisticated attacks are designed to mimic legitimate user behaviour. Aiming for "zero" can lead to over-sensitive tools that generate thousands of false positives, which actually increases your real-world detection time by burying the team in noise.

"MTTD is Only for Big Companies"

Small businesses are often targeted because hackers know they have weaker detection capabilities. For an MSP serving the SMB market, MTTD is arguably more important because these clients lack the financial cushion to survive a prolonged breach.

"More Tools Equals Lower MTTD"

Adding more tools often leads to more complexity and slower detection. The best MSPs focus on a "lean" stack where every tool is fully integrated and every team member knows exactly how to use it. Efficiency beats volume every time.

The Technical Side: How Modern Tools Track MTTD

For the technical teams, improving MTTD involves a deep dive into telemetry. You need to ensure you are collecting the right logs from the right places. Without these, your Mean Time to Detect (MTTD) will always be hampered by lack of data.

Key Telemetry Sources

  1. Endpoint Logs: Process executions, PowerShell commands, and file changes.
  2. Network Logs: DNS queries, unusual outbound traffic to known bad IPs, and large data transfers.
  3. Identity Logs: MFA fatigue attacks, logins from unusual locations, and privilege escalations in Azure AD (Entra ID).

By correlating these sources in a single pane of glass, you reduce the time your engineers spend switching between tabs, which is one of the simplest ways to shave minutes off your MTTD.

Conclusion: The Bottom Line on MTTD

At the end of the day, MTTD is a metric of accountability. It tells the story of how well your MSP is fulfiling its primary promise: protecting the client’s business. When you focus on lowering this number, you aren't just improving your security posture; you are building a more efficient, more profitable, and more professional services firm.

As Luis Navarro often says, "A recommendation that a client doesn't understand is unlikely to become a project." The same applies to metrics. If you can explain to a client why MTTD matters to their bank account, you will find it much easier to secure the budget for the advanced tools and services you need to keep them safe.

Frequently Asked Questions

Is MTTD more important than MTTR?

They are two sides of the same coin. You cannot respond to what you haven't detected, so MTTD is the "lead" indicator. However, a fast detection followed by a slow response still results in a breach. Both must be optimised to minimise risk.

How often should I report MTTD to my clients?

While you should track it internally in real-time, reporting it to clients is best done during your scheduled Security Reviews or QBRs. Use it as a trending metric to show how your ongoing service improvements are reducing their risk profile over time.

Does lowering MTTD increase my service costs?

Initially, it may require investment in better tools or outsourcing to a SOC provider. However, in the long run, it lowers costs by reducing the number of high-stakes security emergencies that disrupt your team’s productivity and lead to unbillable hours.

What is a "good" MTTD for an MSP?

While industry averages vary, a high-performing MSP should aim for a detection time of minutes for high-severity threats (like ransomware) and hours for lower-priority anomalies. Anything measured in days is a significant business risk.

Can automation replace humans in reducing MTTD?

Automation is excellent at identifying known patterns and "low-hanging fruit." However, sophisticated attackers use "living off the land" techniques that require human expertise to distinguish from legitimate admin work. The best approach is a hybrid of automated alerts and human triage.

How does MTTD affect my MSP's insurance?

Many cyber insurance providers are now asking for evidence of monitoring and detection capabilities. Being able to demonstrate a low MTTD and a robust detection process can help your clients secure better coverage and may even be a requirement for your own professional liability insurance.

Why MTTD Matters to Your MSP Business

Security is not discussed in isolation from business at MSP Agenda. When we look at MTTD, we aren't just looking at a stopwatch; we are looking at the health of your client relationships and your bottom line. If a threat sits in a client’s network for 200 days—the global average—the chances of a total ransomware lockout are nearly 100%.

From a commercial perspective, a high MTTD is a liability. It leads to "firefighting" mode, where your most expensive senior engineers are pulled off profitable projects to handle an emergency. This kills your effective hourly rate and erodes the trust you’ve spent years building with the client's board or finance director.

Low MTTD, conversely, is a competitive advantage. It allows you to walk into a Security Review and show the client that while they were targeted, your systems identified the threat in minutes, not months. This moves the conversation from "Why am I paying for this?" to "I’m glad we have you looking after us."

The Relationship Between MTTD and MTTR

While MTTD measures how long it takes to see the fire, Mean Time to Respond (MTTR) measures how long it takes to put it out. You cannot have a fast response without a fast detection. As an MSP, focusing solely on response without improving detection is like having the world's fastest fire truck but no smoke detectors in the building.

  • Effective Hourly RateRunning a Managed Service Provider (MSP) is often a balancing act between keeping clients happy and maintaining a healthy bottom line. While most owners focus on Top-Line Revenue or Monthly Recurring Revenue (MRR), these figures only tell half the story. To understand how profitable your business actually is, you.

Blog

MSP Cost Per Ticket

In the world of managed services, your help desk is often the heartbeat of the business.

Growth beats guesswork.

Email us

We use analytics cookies to understand which pages are useful. Nothing is measured until you choose. Cookie details