Track MDR performance across five connected areas: incident lifecycle times, alert handling, coverage and visibility, alert quality, and response outcomes. Keep separate clocks for provider handling and customer-dependent response, and read speed metrics alongside coverage and incident quality. An SLA pass rate alone cannot show whether the service is effective.
Which MDR performance metrics should security teams track?
Build a scorecard that measures both what the provider does and what happens to the incident. For each metric, specify its unit—alert, incident, affected asset, or response task—and report the numerator and denominator where applicable. Providers may group multiple alerts into one incident, so agree on the counting method before comparing results.
- Incident lifecycle: detection, identification, containment, resolution or remediation, and recovery.
- Alert handling: acknowledgement, triage completion, investigation, and notification.
- Coverage and visibility: monitored assets and data sources, telemetry availability, and detection coverage for relevant threat techniques.
- Alert quality: false-positive ratios by detection use case, validated incidents and severity, and recurring tuning or suppression changes.
- Response outcomes: containment and remediation progress, customer actions pending, recovery, completed response tasks, and recurrence prevention.
FIRST’s CSIRT Services Framework includes detection coverage against threat TTPs and false-positive ratios per detection use case. Those measures make alert volume easier to interpret: fewer alerts may reflect better filtering, but they may also reflect weaker visibility.
How should teams define incident and alert clocks?
Use a written start event and stop event for every time metric. CISA’s FY 2025 CIO FISMA Metrics, Version 1.1 distinguishes mean time to detect, identify, recover, and resolve. In its definitions, detection is discovery of an incident; identification measures the period between receipt and investigation of an alert; recovery ends when operations return to normal; and resolution means full remediation, including recurrence prevention and post-incident analysis.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
| Milestone | What to measure | Definition or boundary |
|---|---|---|
| Detection | Time to detect | Incident start to discovery or detection, using the agreed incident-start convention; CISA defines the measure as mean time to discover or detect an incident. |
| Identification | Time to identify | Alert receipt to investigation, as defined by CISA; specify the exact provider event timestamps used. |
| Acknowledgement | Time to acknowledge | Alert firing or delivery to provider acknowledgement; document which event starts the clock. |
| Triage | Time to complete triage | Separate the start of triage from completion. One published MDR SLA defines triage time as alert firing until an analyst acknowledges it and begins triage; that is not the same as completed investigation. |
| Investigation and notification | Investigation time and time to notify | Record when investigation begins and ends and when the customer is notified. A public service definition distinguishes acknowledgement, triage completion, and investigation; response execution may require customer approval. |
| Containment | Time to contain | Incident start or agreed response trigger to containment. Separate provider work from time awaiting customer approval or action. |
| Resolution | Time to resolve or remediate | Measure through full remediation, not merely alert closure; CISA’s resolution definition includes recurrence prevention and post-incident analysis. |
| Recovery | Time to recover | Incident start to return to normal operations under CISA’s definition. |
These milestones are not interchangeable. Provider triage time is not end-to-end incident response time. NIST’s incident-handling lifecycle in SP 800-171 Rev. 3 spans preparation, detection and analysis, containment, eradication, and recovery; a scorecard limited to alert handling leaves much of that work unmeasured.
What should an MDR SLA include?
Make the service agreement measurable enough that both parties can reproduce its results. For each commitment, write down:
Rank #2
- Every page is grease and tear-proof & FULL color
- Portable and fits into the pocket -take it everywhere!
- It is wiro layflat bound so it stays open unassisted
- Metric Sizing, 3rd Edition, Handbook/Pocket Size
- Free set of self-adhesive index tabs
- The event that starts and stops the clock, including source system and timestamp.
- Severity definitions and how quickly severity can be reclassified.
- Service hours and whether the commitment applies around the clock or only during specified windows.
- Exclusions, clock pauses, and whether customer approval, access, or action delays count.
- The provider’s authority to isolate devices, disable accounts, block indicators, or take other response actions without approval.
- Reporting cadence, evidence available for each case, numerator and denominator for attainment, and how missed commitments are handled.
Report acknowledgement, triage completion, investigation, notification, containment, remediation, and recovery as separate clocks. Publish pauses and time waiting on the provider or customer rather than blending them into one result. Published vendor SLA values are examples of contract terms, not universal performance benchmarks.
How do you measure MDR effectiveness, not just speed?
Pair elapsed-time measures with evidence that the service can see relevant activity, distinguish meaningful threats, and drive incidents toward a safe outcome.
Recommended Free Tools
Coverage and telemetry health
Measure the share of in-scope assets and data sources actually monitored, along with source or sensor availability. Track detection coverage for relevant use cases or threat TTPs, document material blind spots, and record scope changes. A fast response time for alerts cannot establish effectiveness if important systems or telemetry are absent.
Alert quality and validated incidents
Review false-positive ratios by detection use case, validated incident volume and severity, repeat alert patterns, and tuning or suppression changes. Include suppressed and customer-reported events in quality reviews where the data allows; false-positive and escalation rates alone cannot measure missed threats. Read alert counts against coverage and telemetry health so a falling volume is not mistaken automatically for improvement.
Rank #4
Response outcomes and learning
Track containment and remediation status, response tasks completed, customer actions still pending, recovery, and measures taken to prevent recurrence. Microsoft’s MDR reporting documentation describes incident trends and managed-response task volume and median completion time as examples of provider reporting. Ask for case evidence and action tracking so aggregate figures can be tied to actual work and follow-up.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should teams analyze and compare MDR metrics?
Use consistent definitions across providers and examine trends over a stated population and time window. For skewed time data, show severity-stratified medians or percentiles as well as averages; a mean can conceal a small number of unusually long investigations. State how many incidents or eligible alerts are included.
Free tools Windows power users keep installed
One-click scans. No signup required.
Compare providers across the same dimensions rather than relying on one headline SLA:
- Speed: acknowledgement, triage, investigation, notification, containment, remediation, and recovery.
- Scope: covered platforms, endpoints, cloud and identity sources, telemetry health, and detection use cases.
- Quality: false positives by use case, validated incident handling, repeat alerts, and documented tuning.
- Action and accountability: provider authority, customer approval gates, escalation quality, and time waiting on each party.
- Outcomes and learning: containment, full remediation, recovery, recurrence prevention, and changes made to detections or response plans.
- Reporting: cadence, case evidence, clear denominators, trend segmentation, and follow-up action tracking.
Set targets from organizational risk tolerance, business impact, threat model, and agreed service scope, then revise them against measured baselines. CISA and NIST provide useful measurement definitions and lifecycle structure, but the cited sources establish no universal MDR efficacy statistic or sector-wide target.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

