
Rex says
Money math without the spreadsheet headache. Plug in your numbers and I'll show you exactly where the dollars land.
Try a scenario
Click to load — tweak from there.Inputs
Result
Estimated annual savings
$1,765,619
Savings per incident
$441,405
Estimated cost per incident (current)
$553,877
Estimated cost per incident (target)
$112,472
Current MTTD + MTTR (days)
28

Psst — share this and help Rex grow
One click, a permanent link with your numbers baked in.
How to use this
- 1Enter estimated cost per day of undetected/unresolved access.
- 2Enter current mttd.
- 3Enter current mttr.
- 4Enter target mttd.
- 5Enter target mttr.
- 6Enter estimated incidents per year.
- 7Read your estimated annual savings on the right — it updates as you type.
- 8Hit Share to keep the scenario or send it to someone.
About this calculator
Mean time to detect (MTTD) and mean time to respond (MTTR) are the two clocks that determine how expensive an incident becomes. Every additional day an attacker has undetected access increases the odds of data exfiltration, lateral movement, and secondary compromise, and every additional hour of response time extends business disruption. This calculator uses a daily cost-of-dwell rate, derived from asset value and blast radius, applied across your current MTTD plus MTTR versus a target state after investing in better detection tooling or a faster runbook. It's built to answer the question SOC managers get asked constantly: 'if we cut MTTD from 21 days to 5, what's that actually worth?' The answer is rarely intuitive because cost doesn't scale linearly with dwell time; risk of exfiltration and lateral spread compounds, so this model applies a modest compounding factor rather than a flat daily rate to reflect that a threat actor's fifteenth day inside a network is more dangerous than their first.
Worked example
Using the values the calculator loads with:
Inputs
- Estimated cost per day of undetected/unresolved access: 12000
- Current MTTD: 21
- Current MTTR: 7
- Target MTTD: 5
- Target MTTR: 2
- Estimated incidents per year: 4
Results
- Estimated annual savings: $1,765,619
- Savings per incident: $441,405
- Estimated cost per incident (current): $553,877
- Estimated cost per incident (target): $112,472
- Current MTTD + MTTR (days): 28
What each field means
Inputs
- Estimated cost per day of undetected/unresolved access
- The estimated cost per day of undetected/unresolved access used in the calculation. Starts at 12000 so you have a working example on load.
- Current MTTD
- The current mttd used in the calculation. Starts at 21 so you have a working example on load. Accepted range: 0–365.
- Current MTTR
- The current mttr used in the calculation. Starts at 7 so you have a working example on load. Accepted range: 0–365.
- Target MTTD
- The target mttd used in the calculation. Starts at 5 so you have a working example on load. Accepted range: 0–365.
- Target MTTR
- The target mttr used in the calculation. Starts at 2 so you have a working example on load. Accepted range: 0–365.
- Estimated incidents per year
- The estimated incidents per year used in the calculation. Starts at 4 so you have a working example on load. Accepted range: 0–200.
Results
- Estimated annual savings
- Returned as a money amount in US dollars and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Savings per incident
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Estimated cost per incident (current)
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Estimated cost per incident (target)
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Current MTTD + MTTR (days)
- Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
FAQ
Why use a compounding factor instead of a flat daily rate?
Real breach data shows cost doesn't scale linearly with dwell time; the risk of data exfiltration, ransomware deployment, and lateral movement increases the longer an attacker sits undetected, so day 20 is meaningfully more expensive than day 2. A mild exponent (1.15 here) reflects that acceleration without wildly overstating it.
What's a realistic MTTD for a mid-size company today?
Industry reports put median dwell time somewhere between 16 and 24 days depending on sector and whether you have a managed detection service, though top-quartile organizations with mature SIEM and EDR tuning get this under 5 days. If you don't know your own number, that's the first gap to close before optimizing further.
How does this connect to SOC staffing decisions?
Faster MTTD and MTTR usually come from better tooling (EDR, SIEM correlation) and adequately staffed shifts rather than working harder with the same tools. Run this calculator alongside the SOC staffing coverage tool to see whether the savings from faster response justify adding headcount or upgrading detection tooling.
Does this account for regulatory notification timelines?
Not directly. Faster detection also matters because many breach notification laws (like state 30/45/60-day rules and GDPR's 72-hour requirement) start their clock at detection, so extended MTTD can itself trigger compliance penalties independent of the direct dwell cost modeled here.
Accuracy and limitations
- Results are estimates before tax, fees, and inflation unless an input explicitly covers them.
- Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.
- This is educational maths, not financial advice. Check anything contractual with the lender or your accountant.
Related tools
SOC Staffing Coverage Calculator
Figure out how many analysts you need for 24/7 or business-hours coverage.
Data Breach Cost Calculator
Estimate total breach cost from records exposed, industry, and detection speed.
SIEM Log Ingestion Cost Calculator
Estimate monthly SIEM cost from log volume, sources, and retention period.
Cite this calculator
Writing about this topic? Grab a citation — every link helps keep these tools free.
RevenueLab. (2026). MTTD/MTTR Cost Impact Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact" target="_blank" rel="noopener">MTTD/MTTR Cost Impact Calculator — RevenueLab</a> (2026).</p>
Source: [MTTD/MTTR Cost Impact Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/mttd-mttr-cost-impact) (2026).
