Metrics
Definitions from pp. 445 to 446. Iteration count is mine.
| Metric | Measured from | This incident |
|---|---|---|
| Mean time to detect | Incident start to detection | |
| Mean time to respond | Detection to resolution | |
| Time to containment | Detection to attacker activity stopped | |
| Time to eradication | Containment to persistence removal complete | |
| Time to full recovery | Detection to all systems restored | |
| Total lifecycle | Initial compromise to verified resolution | |
| Systems affected | Servers, workstations, cloud resources | |
| Accounts affected | Compromised or requiring reset | |
| Data exposure | Record count, classification, regulatory categories | |
| Business impact | Disruption duration, revenue effect | |
| Effort and cost | Personnel hours, external services, tooling, any ransom paid | |
| Iterations | Passes through the response actions loop |
Record these the same way every time. Comparison across incidents is what shows whether the team is improving, and the numbers are what fund the improvement plan. Iteration count is here because it shows whether scoping caught things early or late, and nothing else in the set does.