Mean Time to Detect and Contain: Breach Metrics Explained

Security programs often report activity: number of patches applied, emails blocked, training sessions completed. These are useful, but they do not answer the question leadership really cares about. When something goes wrong, how quickly do we notice, and how quickly do we stop it?

Two metrics answer that: mean time to detect and mean time to contain. This post defines them in plain terms and shows how a small or mid-size healthcare organization can track them without a large security team.

Why speed matters

The longer an attacker remains inside a network, the more they can see, copy and damage. Fast detection and containment limit how many systems and records are affected, which can change the scope of a HIPAA breach assessment, shorten downtime for clinical operations and reduce cost. Insurers and auditors also increasingly ask how quickly you respond.

The two measures

Mean time to detect

This is the average time between when an incident begins and when your organization becomes aware of it.

Start point: when the malicious activity first occurred, such as the first suspicious sign-in or the moment a phishing email was opened. This is often determined after the fact through log review.

End point: when someone or something identified it as a security issue, whether an alert, an employee report or a call from a vendor.

Mean time to contain

This is the average time between detection and the point at which the threat is stopped from spreading or causing further harm.

Start point: the detection time.

End point: when the affected account is disabled, the device isolated or the connection blocked, so the attacker no longer has access.

Some teams also track mean time to recover, which measures the time until normal operations resume. It is useful but a different question.

How to calculate them

For each incident in a period, record three timestamps:

T0: when it started, as best you can determine

T1: when it was detected

T2: when it was contained

Detection time is T1 minus T0. Containment time is T2 minus T1. Add the results across incidents and divide by the number of incidents to find the mean.

Be honest about the limits

T0 is often an estimate. Document how you determined it, and be consistent.

Small samples are noisy. If you have only a few incidents, one unusual case swings the average. Consider also reporting the longest and the median.

Define "incident." Decide what counts, for example confirmed compromised accounts and malware infections, but not every blocked phishing email.

Averages hide extremes. Review the worst cases individually.

Where the data comes from

Build a simple incident log that records each event, the timestamps, how it was detected, who handled it and what was done. Sources include security alerts, helpdesk tickets, user reports, system logs and your managed service provider's records. Keeping logs long enough, and centrally, makes T0 easier to find.

Improve the numbers

Detection

Turn on and review sign-in and endpoint alerts.

Make it easy and blame-free for staff to report suspicious emails and activity.

Use monitoring that covers evenings and weekends, when care operations continue but office staff are gone.

Run phishing simulations and look at how fast employees report them.

Containment

Write short, practical playbooks for common events: compromised mailbox, infected laptop, lost device.

Pre-authorize responders to disable accounts and isolate devices without waiting for committee approval.

Make sure you can isolate a device remotely.

Keep a current contact list and an out-of-band communication method.

Practice through tabletop exercises and measure how long each step takes.

Report it sensibly

Present trends quarterly, along with a short note on what changed. A decreasing trend suggests improvement, but pair numbers with context. If detection time rises because you improved log review and found older incidents, say so. Avoid targets that encourage hiding incidents or reclassifying them.

Tie to leadership decisions

If detection is slow, investments in monitoring and staff reporting make sense. If containment is slow, focus on playbooks, authority and tooling. Use the metrics to prioritize, not to assign blame.

UnityCare IT helps healthcare organizations set up incident logging, monitoring and response playbooks so these measures can be tracked and improved over time.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172