{
  "slug": "mttd-mttr-cost-impact",
  "title": "MTTD/MTTR Cost Impact Calculator",
  "heading": "MTTD & MTTR Cost Impact Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact",
  "summary": "See how faster detection and response times translate into dollars saved.",
  "description": "Mean time to detect (MTTD) and mean time to respond (MTTR) are the two clocks that determine how expensive an incident becomes. Every additional day an attacker has undetected access increases the odds of data exfiltration, lateral movement, and secondary compromise, and every additional hour of response time extends business disruption. This calculator uses a daily cost-of-dwell rate, derived from asset value and blast radius, applied across your current MTTD plus MTTR versus a target state after investing in better detection tooling or a faster runbook. It's built to answer the question SOC managers get asked constantly: 'if we cut MTTD from 21 days to 5, what's that actually worth?' The answer is rarely intuitive because cost doesn't scale linearly with dwell time; risk of exfiltration and lateral spread compounds, so this model applies a modest compounding factor rather than a flat daily rate to reflect that a threat actor's fifteenth day inside a network is more dangerous than their first.",
  "formula": "Cost of incident ≈ daily dwell cost × (MTTD + MTTR) × compounding factor. Savings = cost(current) − cost(target).",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=mttd-mttr-cost-impact",
  "inputs": [
    {
      "id": "dailyDwellCost",
      "label": "Estimated cost per day of undetected/unresolved access",
      "kind": "number",
      "hint": null,
      "default": 12000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "currentMttdDays",
      "label": "Current MTTD",
      "kind": "number",
      "hint": null,
      "default": 21,
      "unit": null,
      "min": 0,
      "max": 365
    },
    {
      "id": "currentMttrDays",
      "label": "Current MTTR",
      "kind": "number",
      "hint": null,
      "default": 7,
      "unit": null,
      "min": 0,
      "max": 365
    },
    {
      "id": "targetMttdDays",
      "label": "Target MTTD",
      "kind": "number",
      "hint": null,
      "default": 5,
      "unit": null,
      "min": 0,
      "max": 365
    },
    {
      "id": "targetMttrDays",
      "label": "Target MTTR",
      "kind": "number",
      "hint": null,
      "default": 2,
      "unit": null,
      "min": 0,
      "max": 365
    },
    {
      "id": "incidentsPerYear",
      "label": "Estimated incidents per year",
      "kind": "number",
      "hint": null,
      "default": 4,
      "unit": null,
      "min": 0,
      "max": 200
    }
  ],
  "outputs": [
    {
      "id": "annualSavings",
      "label": "Estimated annual savings",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "savingsPerIncident",
      "label": "Savings per incident",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "currentCost",
      "label": "Estimated cost per incident (current)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "targetCost",
      "label": "Estimated cost per incident (target)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "currentTotal",
      "label": "Current MTTD + MTTR (days)",
      "format": "number",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Estimated cost per day of undetected/unresolved access: 12000",
      "Current MTTD: 21",
      "Current MTTR: 7",
      "Target MTTD: 5",
      "Target MTTR: 2",
      "Estimated incidents per year: 4"
    ],
    "outputs": [
      "Estimated annual savings: $1,765,619",
      "Savings per incident: $441,405",
      "Estimated cost per incident (current): $553,877",
      "Estimated cost per incident (target): $112,472",
      "Current MTTD + MTTR (days): 28"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter estimated cost per day of undetected/unresolved access.",
      "Enter current mttd.",
      "Enter current mttr.",
      "Enter target mttd.",
      "Enter target mttr.",
      "Enter estimated incidents per year.",
      "Read your estimated annual savings on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "dailyDwellCost": 7000,
        "currentMttdDays": 13,
        "currentMttrDays": 4,
        "targetMttdDays": 3,
        "targetMttrDays": 1,
        "incidentsPerYear": 2
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "dailyDwellCost": 12000,
        "currentMttdDays": 21,
        "currentMttrDays": 7,
        "targetMttdDays": 5,
        "targetMttrDays": 2,
        "incidentsPerYear": 4
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "dailyDwellCost": 19000,
        "currentMttdDays": 34,
        "currentMttrDays": 11,
        "targetMttdDays": 8,
        "targetMttrDays": 3,
        "incidentsPerYear": 6
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Why use a compounding factor instead of a flat daily rate?",
      "a": "Real breach data shows cost doesn't scale linearly with dwell time; the risk of data exfiltration, ransomware deployment, and lateral movement increases the longer an attacker sits undetected, so day 20 is meaningfully more expensive than day 2. A mild exponent (1.15 here) reflects that acceleration without wildly overstating it."
    },
    {
      "q": "What's a realistic MTTD for a mid-size company today?",
      "a": "Industry reports put median dwell time somewhere between 16 and 24 days depending on sector and whether you have a managed detection service, though top-quartile organizations with mature SIEM and EDR tuning get this under 5 days. If you don't know your own number, that's the first gap to close before optimizing further."
    },
    {
      "q": "How does this connect to SOC staffing decisions?",
      "a": "Faster MTTD and MTTR usually come from better tooling (EDR, SIEM correlation) and adequately staffed shifts rather than working harder with the same tools. Run this calculator alongside the SOC staffing coverage tool to see whether the savings from faster response justify adding headcount or upgrading detection tooling."
    },
    {
      "q": "Does this account for regulatory notification timelines?",
      "a": "Not directly. Faster detection also matters because many breach notification laws (like state 30/45/60-day rules and GDPR's 72-hour requirement) start their clock at detection, so extended MTTD can itself trigger compliance penalties independent of the direct dwell cost modeled here."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/soc-staffing-coverage",
    "https://www.revenuelab.fyi/toolbox/breach-cost-per-record",
    "https://www.revenuelab.fyi/toolbox/siem-log-ingestion-cost"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — MTTD/MTTR Cost Impact Calculator (https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact)"
}