Mean time to contain is the only security metric your board will feel

Detection counts and patch percentages do not translate to the boardroom. The interval between compromise and containment does.

Most security reporting to boards fails in the same way. It is accurate, comprehensive, and completely unactionable to the audience. A slide showing 2.4 million blocked events, 97% patch compliance, and a green posture score answers a question nobody in the room asked.

The question they are actually asking is simpler and harder: if something gets in, how bad does it get before we stop it?

Why containment time is the right proxy

Nearly every consequence a board cares about scales with dwell time. Data exfiltration volume, lateral movement reach, ransomware encryption scope, regulatory notification obligations, and recovery cost all grow as a function of how long an intruder operates unimpeded.

An organization that detects and contains in two hours and one that takes three weeks may run identical tooling and score identically on a maturity assessment. Their outcomes from the same initial compromise are not remotely comparable.

Mean time to contain (the interval from initial compromise to the point where the adversary can no longer act) collapses that into one number that moves, that benchmarks against peers, and that a non-technical director can reason about without a glossary.

Blocked-event counts measure how busy your tools were. Containment time measures what would actually happen to the business.

Measuring it honestly

The metric is only useful if the measurement is disciplined, and there are three places it commonly goes soft.

Start from compromise, not from alert. The clock starts when the adversary gained access, not when your tooling noticed. Measuring from first alert produces flattering numbers that hide the detection gap entirely, and that gap is usually the largest component of the interval.

Contained means contained, not ticketed. The clock stops when the account is disabled, the host is isolated, or the credential is revoked, not when an analyst assigned the case. The gap between triage and action is frequently where the hours go, and it is exactly the gap that better tooling alone will not close.

Report the distribution, not just the mean. One three-week incident and forty-nine twenty-minute ones average to something reassuring and meaningless. The 95th percentile is closer to the number that describes your actual exposure.

What moves the number

In our experience, containment time is dominated by three factors, in descending order of impact:

  • Whether anyone is watching at 3am. Coverage gaps are the single largest contributor. An incident starting on a Friday evening in an environment monitored business-hours-only has a floor of roughly sixty hours before anyone begins. No detection engineering overcomes that.
  • Whether the responder can act. If isolating a host requires waking a system owner, raising a change request, and getting approval from someone who is asleep, the technical containment time is irrelevant. Pre-agreed containment authority, documented and with defined limits, is often worth more hours than any tooling upgrade.
  • Whether identity is instrumented. Endpoint detection catches the initial foothold. Most of the damaging dwell time happens after the adversary has valid credentials and looks like a normal user. Without directory-layer detection, that phase is effectively invisible.

Bringing it to the board

A defensible containment-time report has four parts: the current median and 95th percentile, the trend across the last four quarters, the largest single contributor to the current number, and the specific investment that would reduce it.

That structure works because it turns a security update into a familiar business conversation: here is the exposure, here is the trend, here is the constraint, here is what it costs to relieve it. Boards are good at that conversation. They are not good at evaluating whether 97% patch compliance is adequate, and they should not have to be.

Related practice

Secure Identity

Directory design and migration, identity governance, RBAC, privileged access, and B2B/B2C, built to survive an audit and a bad Tuesday.