PPIVTR-D

Metrics

Definitions from pp. 445 to 446. Iteration count is mine.

MetricMeasured fromThis incident
Mean time to detectIncident start to detection
Mean time to respondDetection to resolution
Time to containmentDetection to attacker activity stopped
Time to eradicationContainment to persistence removal complete
Time to full recoveryDetection to all systems restored
Total lifecycleInitial compromise to verified resolution
Systems affectedServers, workstations, cloud resources
Accounts affectedCompromised or requiring reset
Data exposureRecord count, classification, regulatory categories
Business impactDisruption duration, revenue effect
Effort and costPersonnel hours, external services, tooling, any ransom paid
IterationsPasses through the response actions loop

Record these the same way every time. Comparison across incidents is what shows whether the team is improving, and the numbers are what fund the improvement plan. Iteration count is here because it shows whether scoping caught things early or late, and nothing else in the set does.