PartnersTrust CenterInvestorsCareers

CAELION Insights

MTTI Is the Metric That Matters: Rethinking SOC Measurement

Every SOC reports mean time to respond. Almost none can tell you where inside that number the hours actually went. MTTR is an aggregate of three very different activities — detecting, investigating, and responding — and averaging them together hides the one that dominates the total. If you want a metric that changes behavior, tooling decisions, and board conversations, measure the investigation on its own.

What MTTR actually aggregates

Mean time to respond, as most SOCs compute it, runs from the moment a detection fires to the moment the incident is contained or closed. Inside that window sit three phases with different owners, different bottlenecks, and different economics. Detection is largely a machine problem: rules, models, and telemetry coverage determine how fast a signal appears. Response is largely a procedural problem: once you know what happened, containment is a runbook — isolate the host, revoke the session, reset the credential. Between them sits investigation: establishing what the alert actually means, what it touched, and whether it is real.

Detection completes in seconds. Response, once a verdict exists, completes in minutes. Investigation is measured in hours — pulling logs from six systems, reconstructing a timeline, checking the user's normal behavior, correlating with the other forty alerts in the queue. A single averaged number cannot distinguish a SOC with slow detection from one with slow investigation, and so it cannot tell you what to fix. Worse, the queue itself distorts the number: an alert that waited eleven hours for an analyst and was investigated in one records twelve hours of "response time" against a phase that never had the chance to be fast.

Investigation is where the hours hide

Investigation is the phase that scales worst, because it is the phase performed by people. Every new log source, every new SaaS application, every new identity provider adds a place an analyst must look. The work is serial, interrupt-driven, and repetitive — the same enrichment queries, the same pivot patterns, the same timeline assembly, alert after alert. When volume exceeds capacity, SOCs do not investigate faster; they investigate less. Triage tiers, severity thresholds, and auto-close rules are all mechanisms for deciding which alerts will not be investigated at all — a quiet risk-acceptance exercise that never appears in the MTTR report, because uninvestigated alerts never enter the denominator.

A SOC that measures only MTTR will optimize the parts of response that were already fast — and never see that the investigation is where the risk compounds.

Defining MTTI cleanly

Mean time to investigate is the elapsed time from alert creation to a defensible verdict — a determination of true or false positive, with scope, root cause, and supporting evidence attached. Two boundary decisions make the definition useful rather than decorative:

  • Start the clock at alert creation, not analyst pickup. Queue time is investigation latency from the adversary's point of view. Excluding it turns MTTI into a measure of analyst diligence rather than SOC performance.
  • Stop the clock at an evidenced verdict, not a closed ticket. "Closed — benign, probably" is not a verdict. The end state is a conclusion that a second analyst, or an auditor, could check against the attached evidence without redoing the work.
  • Report it with coverage. MTTI over the 8% of alerts you chose to investigate is a vanity number. Pair it with the fraction of alerts that received a full investigation.

Defined this way, MTTI is honest in a way MTTR is not. It cannot be gamed by auto-closing, because auto-closed alerts count as uninvestigated. It cannot be flattered by fast containment, because it ends before containment begins. It measures exactly one thing: how long your organization takes to know the truth about a signal.

What measuring MTTI changes

Metrics direct spend. A SOC managed on MTTR buys faster response: SOAR playbooks, containment automation, on-call tooling. Useful — but those investments compress minutes from a total dominated by hours. A SOC managed on MTTI asks a different procurement question: what removes hours from investigation itself? That reframing favors architectures that investigate every alert automatically, attach evidence to every verdict, and reserve human time for judgment on the escalations — the model platforms like Trace8 are built around, and the standard explored in Every Alert Investigated.

It also changes the board conversation. "MTTR is 9 hours" invites the wrong question: why aren't you responding faster? "MTTI is 6 hours on the 12% of alerts we investigate" invites the right ones: what happens to the other 88%, and what would it take to investigate everything? Boards understand coverage and latency as risk terms. They cannot act on a blended average, but they can act on a statement like "we intend to investigate 100% of alerts with a verdict inside 15 minutes, and here is the architecture gap between us and that number." MTTI turns SOC reporting from an operational curiosity into a risk-posture statement.

The measurement set

MTTI does not stand alone. The minimal set that gives leadership a truthful picture of investigative performance:

MetricWhat it tells youTarget direction
MTTD (mean time to detect)Telemetry and detection-engineering qualityDown
MTTI (mean time to investigate)Alert creation to evidenced verdict — the true bottleneckDown, toward minutes
Investigation coverageShare of alerts receiving a full investigation, not triage-and-closeUp, toward 100%
Verdict overturn rateShare of verdicts reversed on review — the quality check on speedDown, and independently sampled
Evidence completenessShare of verdicts a reviewer can validate from the attached case file aloneUp, toward 100%
MTTC (mean time to contain)Response-procedure efficiency after the verdictDown — but weight it last

Two cautions. First, never report MTTI without the overturn rate; speed purchased with wrong verdicts is worse than slowness. Second, resist the temptation to collapse the set back into one number for the executive summary. The whole failure of MTTR was the averaging.

Start measuring it this quarter

You do not need new tooling to begin. Timestamp alert creation and verdict delivery in your existing case system, compute the distribution — median and p90, not just the mean — and count what fraction of alerts ever reached a verdict at all. Most SOCs that run this exercise find the same two facts: investigation is 80% or more of elapsed incident time, and the majority of alerts were never investigated. Those two facts, stated plainly, justify more architectural change than any vendor deck.

CAELION built Trace8 around the metric this article argues for: an AI-native SOC platform whose agents investigate every alert to an evidenced, adversarially verified verdict — collapsing MTTI from hours to minutes at 100% coverage. To see your own alert data measured this way, request a briefing.

Related

Continue reading

Security Operations

Every Alert Investigated: The Standard SOCs Stopped Believing Was Possible

July 21, 2026

Security Operations

SOC Burnout Is a Design Flaw, Not a Staffing Problem

June 9, 2026

Security Operations

The AI SOC Buyer's Guide: Ten Questions That Separate Copilots From Platforms

May 12, 2026