Data as of Aug 25, 2026 · Based on 300 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Your brand can be here too.
If you’re choosing between two MDR providers, **don’t let any one of these three metrics decide the purchase**. I’d weight them roughly: 1. **MTTR / containment speed — 40%** 2. **MTTD — 30%**
If you’re choosing between two MDR providers, don’t let any one of these three metrics decide the purchase. I’d weight them roughly:
But the important caveat is that the definitions behind the numbers matter more than the headline numbers. MTTD and MTTR can be calculated from very different starting and ending points, making vendor claims difficult to compare directly.
| Metric | What it tells you | Weight | What to demand |
|---|---|---|---|
| MTTR | How quickly the MDR actually limits damage | 40% | Time from confirmed detection → containment/remediation, not merely analyst acknowledgment |
| MTTD | How long an attacker can operate before discovery | 30% | Time from malicious activity → genuine detection, preferably by severity/use case |
| False-positive rate | How much analyst/customer attention is wasted on noise | 30% | False-positive rate of customer escalations, not just raw SIEM alerts |
MTTR gets the highest weight because detection without effective containment doesn't prevent much damage. A provider that detects ransomware in five minutes but takes two hours to isolate affected endpoints may be less valuable than one that detects it in ten minutes and contains it in fifteen. Faster detection generally reduces the window for lateral movement and impact.
MTTD is still extremely important, particularly for stealthy attacks. But ask vendors to break it down by attack type and severity rather than giving you one average. An overall five-minute MTTD can conceal much slower detection of identity attacks, cloud compromise, or hands-on-keyboard activity.
False-positive rate is the quality-control metric. A provider can achieve spectacular MTTD simply by firing alerts on everything. High false-positive rates create alert fatigue and consume your team's time. Detection accuracy and coverage should therefore accompany FPR.
I'd actually make Mean Time to Contain (MTTC) a contractual KPI alongside MTTR. It answers the business-critical question: How long until the attacker is actually stopped? MTTD → response → containment is a more meaningful lifecycle than MTTD + generic "resolution."
And I'd add detection coverage/accuracy as a fourth dimension. Otherwise, Vendor A can win your scorecard by being extremely fast on the threats it detects while missing more threats than Vendor B. FIRST's detection-engineering metrics specifically distinguish MTTD/MTTR from detection coverage and detection fidelity.
Don't ask:
"What is your average MTTD?" Ask:
"For the last 12 months, provide P50/P90 MTTD and MTTC for P1/P2 incidents, calculated from the first observable malicious event through detection and containment. Provide the methodology, exclusions, sample size, and results separately for ransomware, credential compromise, lateral movement, and data exfiltration." Also require a live proof-of-value. Give both vendors the same simulated attack scenarios and measure:
attack begins → detection → analyst validation → customer notification → containment → remediation
That will tell you considerably more than vendor-reported averages.
Bottom line: If forced to choose based only on the three metrics you named, I'd prioritize MTTR first, MTTD second, and false-positive rate third. But for an actual MDR procurement, I'd make the decision based on MTTC + MTTD + detection coverage/accuracy + escalation quality, with FPR acting as a quality and efficiency check.
When evaluating Managed Detection and Response (MDR) providers, weighing metrics like **Mean Time to Detect (MTTD)**, **Mean Time to Respond (MTTR)** , and **False Positive Rate (FPR)** requires a balance between speed, accuracy, and business impact. Not all metrics are created equal, and vendors often game them. Here…
When evaluating Managed Detection and Response (MDR) providers, weighing metrics like Mean Time to Detect (MTTD), Mean Time to Respond (MTTR) , and False Positive Rate (FPR) requires a balance between speed, accuracy, and business impact. Not all metrics are created equal, and vendors often game them.
Here is how these metrics stack up and which ones should actually drive your decision:
Which metric should drive the decision?
To help narrow down your choice, tell me:
No sources cited
For an MDR selection, I would **not let one of the three metrics win by itself**. The best decision framework is: 1. **MTTD — important, but only after validating detection quality** 2. **MTTR — arguably the most important operational metric**
For an MDR selection, I would not let one of the three metrics win by itself. The best decision framework is:
The catch is that vendor-reported numbers often aren't apples-to-apples: vendors may start and stop their clocks at different points, and “MTTR” might mean containment, customer notification, or full remediation.
| Metric | Suggested weight | What it tells you |
|---|---|---|
| MTTR / containment time | 40% | How quickly the provider limits damage once a real threat is identified |
| MTTD | 30% | How quickly the provider recognizes malicious activity |
| False-positive rate | 20% | How much analyst time/noise the MDR generates |
| Detection quality & coverage | 10% | Whether the provider is actually finding the threats that matter |
I'd actually treat the last category as a gating criterion, rather than allowing excellent speed to compensate for poor coverage.
Don't compare averages alone. Ask both providers for:
This matters because a provider can advertise an impressive MTTD while measuring only the point at which an alert reaches an analyst—or use a very narrow definition of “detected.”
Suppose:
I'd generally choose B, assuming detection coverage and response quality are comparable.
Why? A five-minute detection advantage is unlikely to compensate for taking 18 additional minutes to contain the attack, while the lower false-positive rate also means less operational noise.
Conversely, if A's five-minute MTTD comes with substantially better detection coverage and B's fast response is achieved by aggressively suppressing alerts, A could easily be the better security outcome.
Bottom line: optimize for risk reduction, not the lowest headline number. I would prioritize MTTR/containment + detection coverage, use MTTD as the next differentiator, and use false-positive rate to measure the operational burden. The three metrics should be evaluated together because speed without detection accuracy can produce a misleadingly good MDR score.
If you're building an actual MDR vendor scorecard, a 100-point weighted model with specific pass/fail thresholds for these metrics is usually much more useful than simply asking vendors for their “best” MTTD/MTTR.
All three metrics are critical, but **Mean Time to Respond (MTTR)** should drive your decision. While detection is important, containment stops the damage. Here is how to weigh each metric during your evaluation. 🥇 1. Mean Time to Respond (MTTR) — The Primary Driver
All three metrics are critical, but Mean Time to Respond (MTTR) should drive your decision. While detection is important, containment stops the damage.
Here is how to weigh each metric during your evaluation.
🥇 1. Mean Time to Respond (MTTR) — The Primary Driver
MTTR is the most critical metric because it measures how fast the provider stops an active threat.
🥈 2. Mean Time to Detect (MTTD) — The Baseline
MTTD measures the provider's visibility and speed in spotting anomalies.
🥉 3. False Positive Rate — The Efficiency Metric
This measures the provider's ability to filter out noise and only escalate real threats.
📋 The Deciding Questions
When interviewing the MDR vendors, ask these specific questions to validate their metrics:
If you want to narrow down your choices, tell me:
I can help you build a custom scorecard or vendor questionnaire based on your setup.
No sources cited
If you’re choosing between two MDR providers, **don’t let any one of these three metrics decide the deal**. I’d weight them roughly: Metric | Suggested weight | Why --- | --- | ---
If you’re choosing between two MDR providers, don’t let any one of these three metrics decide the deal. I’d weight them roughly:
| Metric | Suggested weight | Why |
|---|---|---|
| MTTR / time to contain | 40% | Ultimately, you want the provider to stop an attack, not merely identify it. |
| MTTD | 30% | Earlier detection reduces attacker dwell time and limits lateral movement/exfiltration. |
| False-positive rate | 20% | Determines analyst trust, alert fatigue, and how much work gets pushed back to your team. |
| Detection quality/coverage | 10% | Prevents a provider from looking great simply by being fast on the threats it happens to detect. |
The important caveat: I'd treat detection coverage and containment success as guardrails, not just another score. A provider with a 5-minute MTTD that misses important attacks is worse than one with a 15-minute MTTD that consistently detects and contains them. The UK NCSC makes essentially this point: the meaningful outcome is whether attacks are detected and responded to in a timely manner, and recommends adversary simulation/red teaming to test that capability.
1. MTTR — highest priority
Ask exactly what "response" means. Vendor A might measure from SOC notification → analyst action, while Vendor B measures initial compromise → containment. Those aren't comparable. Even published MDR comparisons show vendors defining MTTR differently.
For procurement, define your own clock:
Detection → validated incident → containment → remediation I'd especially score time to containment separately from full remediation. If an endpoint can be isolated in 5 minutes, that's more security-critical during an active ransomware attack than whether the endpoint is completely cleaned up in 90 minutes.
2. MTTD — important, but don't optimize it blindly
Low MTTD is valuable, but a provider can game it by generating lots of low-quality alerts. MITRE's managed-services evaluations illustrate why methodology matters: even "MTTD" can mean the time until the provider sends an alert to the customer, rather than the underlying platform's detection time.
So ask for MTTD by severity and attack stage, not just one average:
3. False-positive rate — use it as a quality/productivity metric
A low false-positive rate is valuable because it means your team can trust an MDR escalation rather than investigate endless noise. CIS explicitly highlights eliminating false positives as a way to reduce alert fatigue and focus attention on actionable threats.
But clarify the denominator. "2% false positives" could mean 2% of all raw telemetry, whereas what you really care about may be:
% of MDR escalations to our team that turn out to be benign That's much more meaningful operationally.
For a head-to-head evaluation, I'd make the providers run the same simulated attacks against your environment and score:
This is much stronger than comparing vendor-reported averages. Independent testing and adversary simulation can expose whether impressive MTTD/MTTR numbers translate into actual protection.
Bottom line: If I had to choose one metric, I'd choose time to successful containment, not MTTD. But for the actual procurement scorecard, I'd use MTTR 40% + MTTD 30% + false positives 20% + detection/coverage 10%, with a requirement that neither provider fails your minimum detection-coverage or containment thresholds.
Also, require every metric to be reported using the same definitions, severity levels, start/stop timestamps, and percentile (ideally P50/P90/P95). Averages alone can hide terrible performance on the incidents that matter most.
I'd especially score time to containment separately from full remediation. If an endpoint can be isolated in 5 minutes, that's more security-critical during an active ransomware attack than whether the endpoint is completely cleaned up in 90 minutes.
2. MTTD — important, but don't optimize it blindly
Low MTTD is valuable, but a provider can game it by generating lots of low-quality alerts. MITRE's managed-services evaluations illustrate why methodology matters: even "MTTD" can mean the time until the provider sends an alert to the customer, rather than the underlying platform's detection time.
So ask for MTTD by severity and attack stage, not just one average:
When evaluating Managed Detection and Response (MDR) providers, weighing **MTTD** (Mean Time to Detect), **MTTR** (Mean Time to Respond/Remediate), and the **false positive rate** comes down to balancing **speed vs.…
When evaluating Managed Detection and Response (MDR) providers, weighing MTTD (Mean Time to Detect), MTTR (Mean Time to Respond/Remediate), and the false positive rate comes down to balancing speed vs. accuracy.
While all three matter, they do not carry equal weight. Here is how they should drive your decision, ranked and structured for a clear evaluation framework:
Key Caveats During Evaluation
To help narrow down your evaluation, could you share:
If you're choosing between two MDR providers, I would **not treat MTTD, MTTR, and false-positive rate as equally weighted KPIs**. For most companies, the priority should be: 1. **MTTR / time to containment — highest weight** 2. **MTTD — second**
If you're choosing between two MDR providers, I would not treat MTTD, MTTR, and false-positive rate as equally weighted KPIs. For most companies, the priority should be:
The key is to measure them in a way that makes the vendors genuinely comparable.
| Metric | Suggested weight | What it tells you | What to watch for |
|---|---|---|---|
| MTTR / MTTC | 40% | How quickly the provider stops an active attack | Does "response" mean containment, remediation, or merely analyst acknowledgment? |
| MTTD | 30% | How quickly an attack is recognized | Does the clock start at compromise, telemetry receipt, or alert creation? |
| False-positive rate | 15% | How much analyst/customer time is wasted on benign activity | A low FP rate can also mean the provider is being too conservative |
| Detection coverage / true-positive detection | 15% | Whether the MDR actually sees the threats that matter | Don't optimize speed at the expense of missed attacks |
Fast detection isn't useful if the provider can't contain the threat. A provider that detects ransomware in 5 minutes but takes 90 minutes to isolate affected systems can be worse than one that detects it in 10 minutes and contains it in 10.
That's why I'd actually break "MTTR" into MTTA → MTTC → remediation rather than accepting one aggregate number. Vendor metrics can be dramatically different depending on where they start and stop the clock.
For example:
MTTD: malicious activity → detection
MTTA: detection → analyst engagement
MTTC: detection → containment
MTTR: detection → full remediation
For an MDR purchase, MTTC is arguably the most business-critical number because it represents the period during which an attacker can continue causing damage.
Ask both vendors for median and 90th-percentile MTTD, not just an average.
An average "5-minute MTTD" can conceal a lot. You want something like:
And require them to break it down by critical/high-severity incidents. Otherwise, thousands of trivial alerts can make a vendor's overall MTTD look excellent.
False-positive rate matters, but its importance depends on what the MDR actually does.
If the provider's SOC investigates alerts and only escalates validated incidents, you care less about the raw number of alerts generated by the underlying platform and more about how many false incidents reach your team.
I'd therefore ask for:
False-positive rate is increasingly tracked as a detection/response KPI; a 2025 Rapid7 survey found 43% of organizations tracking it, compared with 56% tracking MTTD and 62% tracking MTTR.
I'd use something closer to:
40% — Response effectiveness
25% — Detection effectiveness
15% — Signal quality
10% — Operational quality
10% — Independent validation / commercial factors
One important point: don't select the vendor with the lowest three numbers. A provider could achieve phenomenal MTTD and MTTR by aggressively alerting on everything or automatically blocking activity, creating unacceptable business disruption. Independent validation and detection coverage help prevent that tradeoff. MITRE's MDR evaluations are particularly useful because they test the managed service rather than merely the underlying security product.
Bottom line: If forced to pick just one metric, I'd choose time to containment (MTTC) over MTTD, and I'd use false-positive rate as a guardrail rather than the primary selection criterion. The winning MDR is the one that detects important attacks quickly, contains them reliably, and generates little noise—without sacrificing coverage.
When evaluating two Managed Detection and Response (MDR) providers, **Mean Time to Respond (MTTR)** and the **False Positive Rate (FPR)** should be your primary driving metrics, while **Mean Time to Detect (MTTD)** plays a supporting role.[[1]](https://expel.com/cyberspeak/good-mdr-service-providers/) Here is how to…
When evaluating two Managed Detection and Response (MDR) providers, Mean Time to Respond (MTTR) and the False Positive Rate (FPR) should be your primary driving metrics, while Mean Time to Detect (MTTD) plays a supporting role.
Here is how to weigh and analyze each metric to make the right choice for your security posture:
Key Evaluation Strategy
Instead of taking vendor SLA numbers at face value, test them during a Proof of Concept (PoC) or red team exercise. Ask for verifiable data on how they handle custom alerts versus generic signatures, and ensure their definition of "response" means actual containment , not just sending an email notification advising your team to do the work.
If you want to dive deeper, tell me:
I can help you build a custom scorecard to rank these two providers.
When evaluating two MDR providers, **do not let any single metric decide the purchase**. MTTD, MTTR, and false positive rate measure different parts of the security outcome, and vendors often define them differently. A provider with the lowest advertised detection time may not be the one that reduces your actual risk.…
When evaluating two MDR providers, do not let any single metric decide the purchase. MTTD, MTTR, and false positive rate measure different parts of the security outcome, and vendors often define them differently. A provider with the lowest advertised detection time may not be the one that reduces your actual risk.
A practical weighting model:
| Metric | Suggested weight | Why it matters | What to ask vendors |
|---|---|---|---|
| MTTR (Mean Time to Respond/Contain) | 35–40% | Usually the strongest predictor of business impact. Detecting quickly is less valuable if containment is slow. | "From confirmed malicious activity to containment, what is your median and P95 time by severity?" |
| MTTD (Mean Time to Detect) | 25–30% | Shows visibility and detection engineering quality. | "Is the clock measured from attacker activity, log ingestion, alert creation, or analyst review?" |
| False positive rate | 20–25% | Measures analyst efficiency and whether your team will drown in noise. | "What percentage of escalated incidents are ultimately benign? How do you tune detections?" |
| Detection coverage / validation | 10–20% | Prevents choosing a fast but narrow service. | "Which ATT&CK techniques do you detect? Can you show validation results?" |
1. Prioritize response quality over raw speed
2. Normalize definitions MTTD and MTTR are frequently measured from different starting points:
Do not compare numbers until both vendors agree on the same measurement method.
3. Look at false positives together with analyst action A low false-positive rate is only valuable if the provider is not missing threats. Ask for:
The strongest MDR evaluations usually include:
A simple scoring formula could be:
The key question is: "Which MDR provider reduces our expected breach impact?" rather than "Which provider advertises the fastest SOC metrics?"
When evaluating two Managed Detection and Response (MDR) providers, relying on vanity metrics or vendor-supplied SLAs can lead you astray. While **MTTD** (Mean Time to Detect), **MTTR** (Mean Time to Respond/Remediate), and **False Positive Rate** are critical, they shouldn't all carry equal…
When evaluating two Managed Detection and Response (MDR) providers, relying on vanity metrics or vendor-supplied SLAs can lead you astray. While MTTD (Mean Time to Detect), MTTR (Mean Time to Respond/Remediate), and False Positive Rate are critical, they shouldn't all carry equal weight.
Here is how these metrics should drive your decision, ranked by their strategic importance to your security posture:
Additional Real-World Factors to Weigh
If you'd like, tell me:
I can help you build a custom scorecard to evaluate these two providers side-by-side.