MTTR and Its Importance in a SOC
MTTR is an important metric for evaluating SOC efficiency, but be sure you’re comparing apples to apples.
Speed is the whole game in security operations. In 2025, the average time for an attacker to move from an initial foothold to a second system inside a network (the “breakout time”) fell to just 29 minutes, and the fastest observed breakout was 27 seconds (CrowdStrike 2026 Global Threat Report). If your response is measured in hours, the attacker has already won. That’s why MTTR is an important metric for security operations centers (SOCs), and why understanding what the number actually measures matters just as much.
What is MTTR?
MTTR (mean time to remediate) is the average time a security operations center takes to fully resolve a security incident, from when an alert is generated to when the threat is contained, eradicated, and closed out. It’s a core measure of how efficiently and effectively a SOC turns detection into a resolved outcome, not just an acknowledged alert.
The basic MTTR formula divides total remediation time by the number of incidents.
MTTR = total time spent remediating incidents ÷ number of incidents
For example, a team that spends a combined 10 hours resolving 20 incidents has an MTTR of 30 minutes.
One note that trips up a lot of buyers. MTTR is defined in several different ways across the industry, including mean time to remediate, respond, resolve, repair, or recover. Each describes a slightly different endpoint. When you see an MTTR figure, always check which one a vendor means and where their clock starts and stops.
What does MTTR stand for? MTTR vs. MTTD, MTTA, and MTTC
MTTR is one of a family of “mean time to” metrics that each measure a different stage of an incident. Understanding the difference is essential, because a number in seconds and a longer end-to-end number can both be true at once. They’re measuring different things.
| Metric | Stands for | What it measures |
| MTTD | Mean Time to Detect | Time from when an attack begins to when the SOC detects it |
| MTTA | Mean Time to Acknowledge | Time from detection to when an analyst (or system) begins working the alert |
| MTTC | Mean Time to Contain | Time from detection to stopping the attacker’s ability to do further damage |
| MTTR | Mean Time to Remediate/Resolve | Time to fully resolve the incident end to end, including eradication and closeout |
The distinction that matters most is simple. Containment (MTTC) stops the attack from spreading. Remediation (MTTR) is the full cleanup that follows, through investigation, eradication, and partner notification.
A SOC can contain a credential attack in seconds and still spend additional time closing it out completely. Both figures are legitimate. They just describe different points on the same timeline.
What does MTTR measure in a SOC?
In a SOC, MTTR can span several stages of responding to an incident.
- Detecting and validating a threat
- Investigating the activity
- Determining the appropriate response
- Containing the threat
- Eradicating malicious activity
- Remediating affected systems or accounts
- Communicating the outcome to the customer
The exact start and end points depend on the SOC’s methodology, which is why comparing MTTR across different SOCs or managed detection and response (MDR) providers is often not an apples-to-apples comparison.
A metric that measures only containment time isn’t directly comparable to one that includes investigation and remediation. Before you trust a number, ask two things: (1) what actions are included, and (2) when does the measurement begin and end?
What is a good MTTR?
There’s no single MTTR number that qualifies as “good” for every SOC, because the answer depends on what’s being measured, the type of incident, the environment being protected, and where the clock starts and stops. An MTTR that includes investigation, containment, remediation, and customer notification will naturally look different from one that measures containment alone.
The more useful benchmark is external rather than internal. Your response has to be faster than the attacker’s breakout time. With average breakout time now at 29 minutes and the fastest at 27 seconds, a response measured in hours is functionally too slow, regardless of what a vendor’s average looks like on paper.
The strongest signal of an effective SOC isn’t a single headline number. It’s a fast time to contain, backed by evidence of full remediation and a clear account of what’s included in the figure.
Why is reducing MTTR important?
Reducing MTTR helps limit the amount of time a threat remains active in an environment.
Once an attacker gains access, they may attempt to escalate privileges, move laterally, steal credentials, access sensitive information, or deploy additional malicious tools. The longer that activity continues, the more opportunity an attacker has to expand the incident.
A faster response can help security teams:
- Limit an attacker’s opportunity to move through an environment
- Reduce the potential impact of a compromised account or endpoint
- Contain threats before they spread to additional systems
- Reduce the time security analysts spend managing an active incident
- Restore affected systems and accounts more quickly
For MSPs, response speed is particularly important because security teams may be responsible for multiple client environments at the same time. A SOC needs processes and technology that can scale across those environments without relying entirely on manual intervention.
How do SOCs reduce MTTR?
Reducing MTTR takes more than adding analysts. A SOC needs the detection, context, automation, and expertise to move quickly from an alert to an informed response.
- High-fidelity detection. The faster a SOC identifies a legitimate threat, the sooner response can begin, and the less time analysts waste investigating benign activity.
- Automation. Removing manual steps lets a SOC act without waiting for an analyst to complete every task. This matters more as attackers use AI to move at machine speed.
- Context and threat intelligence. Signals from endpoints, identities, and network activity help analysts understand the behavior behind an alert and decide faster.
- Experienced analysts. Automation doesn’t remove the need for expertise. Humans investigate the unusual, handle what falls outside automated response, and own the decisions that need judgment.
The strongest SOCs combine all four, cutting manual work while keeping human judgment available for complex threats.
How the Blackpoint SOC keeps MTTR low
Blackpoint keeps MTTR low through a human-led, AI-accelerated SOC. The AI contains validated threats at machine speed, backed by human analysts who set the boundaries, own the full remediation, and are always reachable by phone.
Blackpoint’s 24/7 SOC has historically reported a 27-minute MTTR, measured from alert ingestion through threat elimination and partner notification, plus a roughly seven-minute response time for cloud incidents. Several things drive that speed:
- High-fidelity detection logic
- Fast access to relevant telemetry and metadata
- Automated processes
- Experienced SOC analysts
Today, Blackpoint is using AI to compress that timeline even further.
Autonomous containment in seconds. For validated threat classes, Blackpoint’s AI SOC Agent acts without waiting for manual approval. It contains identity threats across Microsoft 365 and Google Workspace in under two minutes, and in as little as 21 seconds by suspending the account, cutting active sessions, and forcing a password reset. Early results show a 98% reduction in containment processing time. And because the AI acts only on high-confidence threats within analyst-defined guardrails, speed doesn’t come at the cost of accuracy.
Human-led remediation and closeout. Containment is the first move, not the last. Blackpoint’s SOC owns the full remediation, including deeper investigation, eradication, and the partner phone call that happens every time. Patented endpoint and lateral movement detection, built for multi-tenant MSP environments, gets analysts the right metadata faster, and cloud identity alerts route straight to senior analysts instead of waiting in a general queue.
MTTR vs. AI containment time
It’s easy to see “27-minute MTTR” next to “21-second containment” and assume they contradict each other. They don’t. They measure different things.
- The 27-minute MTTR is a broad, end-to-end incident-resolution figure. The clock starts when an alert enters the SOC queue and stops after the threat is eliminated and the partner is notified.
- The under-two-minute AI containment time measures a single stage. It’s how quickly the AI SOC Agent contains a qualifying identity threat after detection, with some contained in as little as 21 seconds.
In other words, AI-powered containment dramatically shortens the most dangerous stage of an incident, the gap between detection and stopping the attacker, without replacing the broader MTTR measurement. When you evaluate any provider, a containment time and an overall MTTR should never be treated as interchangeable.
That layered model of machine-speed containment plus human-owned remediation is what gives Blackpoint the industry’s fastest response and highest efficacy, and keeps MSP partners first in cybersecurity.
How to compare MTTR across MDR providers
MTTR is useful when evaluating an MDR provider, but it shouldn’t be the only metric, and it’s only meaningful once you know what each provider actually measures. Before comparing numbers, ask these questions.
- What starts the clock? Alert generation, arrival at the SOC, or when an analyst begins investigating?
- What stops it? Detection, containment, remediation, or complete resolution?
- What’s included? Investigation, eradication, remediation, customer notification?
- How much is automated, and what’s the scope? Automation cuts response time, but only for the actions it actually covers.
- What happens when automation isn’t enough? Complex threats need human investigation, and a provider’s ability to escalate fast directly affects overall response time.
- Does the metric apply to the threats you care about? A provider may publish an overall MTTR and separate containment times for specific environments, so make sure you know which number you’re looking at.
Looking at the methodology behind the number gives you a far more useful comparison than the number alone.
Frequently asked questions about MTTR
What does MTTR stand for?
MTTR most commonly stands for mean time to remediate (or resolve). It’s also expanded as mean time to respond, repair, or recover, so it’s worth confirming which definition a given source is using.
What is a good MTTR in cybersecurity?
There’s no universal benchmark, because providers measure MTTR differently. The practical standard is that your time to contain must beat attacker breakout time, now averaging 29 minutes, so the goal is containment measured in minutes or seconds, backed by full remediation.
What’s the difference between MTTR and MTTD?
MTTD (mean time to detect) measures how quickly a SOC identifies that an attack is underway. MTTR (mean time to remediate) measures how quickly it fully resolves the incident once detected. MTTD is the front of the timeline, and MTTR is the whole timeline.
Why does MTTR vary so much between providers?
Because there’s no fixed standard for which response actions are counted or where the clock starts and stops. One provider’s MTTR may end at containment while another’s includes full eradication and customer notification, so always ask what’s included before comparing numbers.
How can a SOC reduce MTTR?
By compressing each stage. High-fidelity detection cuts time to detect, autonomous containment on validated threat classes cuts time to contain, and skilled analysts plus tuned processes cut time to full remediation. Blackpoint combines all three in a human-led, AI-accelerated SOC.
The Bottom Line on MTTR
MTTR is one of the clearest signals of how well a SOC turns detection into a resolved outcome, but the number only means something once you know what it measures. Ask where the clock starts and stops, whether it covers containment or full remediation, and how much is automated versus human-led.
For MSPs racing a 29-minute breakout window, the goal isn’t just a low number on a slide. It’s containment in seconds, full remediation you can verify, and a human accountable for the outcome.
Ready to see responses measured in seconds instead of hours? Request a demo to see MDR and ITDR in the CompassOne platform. We measure security by threats stopped, not alerts generated.
DATE PUBLISHEDApril 30, 2024
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours