Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

MTTR (Mean Time to Respond / Resolve)

MTTR is a metric that measures the average time it takes to respond to or resolve an incident, from detection to resolution. In security, it captures how quickly a team contains and recovers from an attack; in operations, how fast it restores a failed service. A lower MTTR means faster recovery and less damage.

In practice

MTTR is one of a family of related metrics, alongside mean time to detect (MTTD) and mean time to acknowledge (MTTA). Tracking each separately shows whether your bottleneck is noticing the problem or fixing it.

In a breach, MTTR maps directly to cost: the longer an attacker dwells, the more data is exposed and the larger the cleanup. Preparation, clear runbooks, and a retainer with a named responder are what actually move the number down.

// how traztech helps

traztech delivers incident response that lowers MTTR for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

MTTR shows up in two very different conversations: incident response, where it measures how quickly you contain and resolve, and vulnerability management, where it measures how quickly you remediate against your stated SLA.

For compliance the number matters less than the consistency. An auditor comparing your policy to your evidence cares whether you met the timeframe you committed to, not whether the timeframe is impressive.

MTTR (Mean Time to Respond / Resolve): common questions

What is a good MTTR?

There is no universal figure. What matters is that it is measured, that it matches what your policy commits to, and that the trend is visible.

Is MTTR mean time to respond or to resolve?

Both are used, which is why the metric is frequently ambiguous. Define which one you mean in your own policy and stay consistent, because an auditor will compare the definition to the evidence.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.