Threat Response & Compliance SLA Generator
How to read this report. Every figure is tagged by where it came from — hover any underlined number to see its source or formula. A full breakdown of every value is in the appendix.
You entered this Calculated from your inputs Calculated, leans on an assumption Assumption (not from your data)
Executive Summary
Detection speed is the primary defense against adversaries with the persistence and patience of nation-state actors — and this program has made measurable, board-reportable progress. Mean time to detect fell from 384 hours to 240 hours, a 37.5% reduction year-over-year, moving toward but not yet reaching the internal target of 168 hours. The composite risk score stands at 71.3, reflecting a program that has improved materially but carries active structural gaps that require directed action in the next operating period.
- Headline gain, not yet victory: MTTD improved 37.5% and MTTR improved 42.9% — both meaningful reductions in the window nation-state actors exploit for lateral movement and data staging. Neither metric has reached its target, and the gap to target is the operative board concern.
- Internal detection share is rising but below parity: 46% of intrusions are now detected internally, up 9.0% percentage points from 37%. For an APT-exposed organisation, every point of external detection share is an incident the program did not catch first — reducing that residual 54% is the structural objective.
- Vulnerability exposure is the most urgent gap: 18 critical vulnerabilities remain open at an average age of 22 days against a 14-day SLA target. Nation-state actors routinely exploit known vulnerabilities within days of disclosure; this gap directly extends effective dwell time.
- Detection coverage and false positive rate are both off-target: Coverage at 61.0% against a 75.0% target means adversary techniques exist in the environment with no detection logic. A false positive rate of 28.0% — nearly double the 15.0% target — degrades analyst capacity and masks real signals in noise.
- Patch compliance at 81.0% is insufficient for this threat profile: The 95.0% target is a hygiene floor, not an aspiration. The current 74.0% closure rate means one in four vulnerabilities identified is not remediated in the operating cycle.
Security KPI Scorecard
Five of eight KPIs are off-target; MTTD and MTTR show the strongest year-over-year improvement but remain above their targets.
MTTD & MTTR Quarterly Trend
MTTD has fallen 37.5% over eight quarters but remains 72 hours above the 168-hour target — the gap that nation-state actors can still exploit.
Methodology note: Quarterly values are modeled as a linear interpolation from the baseline to the current observed value. They represent a required-path trajectory, not independently observed quarterly actuals. The Q8 endpoint is an observed value; intermediate quarters are synthetic. Target MTTD is shown as a reference line.
Risk Tier Heat Map
The Critical quadrant (Likelihood 4–5, Impact 4–5) is the APT-relevant zone — this is where nation-state intrusion scenarios cluster given the current detection coverage gap.
Incident Response SLA Matrix
P1 Critical incidents require detection within 42 hours and containment within 72 hours — both tighter than the program’s current MTTD and MTTR, meaning P1 SLAs are structurally at risk today.
Key Recommendations
Ranked by estimated impact on composite risk score reduction, then feasibility within the next operating quarter.
1. Accelerate critical vulnerability remediation to close the 18-open-critical gap.
The security operations lead must implement a dedicated critical-vulnerability war-room cadence targeting zero open criticals above 14 days, within the next 60 days. Closing the 18 open criticals and lifting the closure rate from 74.0% to 90.0% directly removes the most exploitable attack surface for persistent adversaries, and carries the highest weight in reducing the composite risk score from 71.3. At the current threat profile, an open critical vulnerability at 22 days average age is an active invitation — not a risk to be deferred.
2. Expand detection logic to close the 14-percentage-point coverage gap.
The SOC detection engineering team must map and fill the delta between current 61.0% coverage and the 75.0% target within two quarters, prioritising technique categories most associated with initial access and lateral movement in APT playbooks. Detection coverage carries a weight of 0.25 in the composite risk model — closing this gap is the second-largest lever available to the program this year. The 54% of intrusions not caught internally are predominantly cases where no detection logic exists for the adversary’s chosen technique.
3. Halve the false positive rate to restore analyst signal fidelity.
The detection tuning lead must systematically suppress or retire alert rules producing false positives, targeting a reduction from 28.0% to 15.0% within one quarter. Analyst time spent on false alerts is time not spent validating real detections — at a 28.0% rate, nearly three in ten alerts are noise, directly compressing the human capacity needed to sustain the MTTD gain of 37.5%. The false positive weight of 0.15 in the composite score understates the operational impact: analyst burnout and alert fatigue are the mechanism by which detection coverage gaps become dwell-time gains for adversaries.
4. Drive MTTD from 240 hours toward the 168-hour target through structured quarterly reduction commitments.
The CISO must present the board with a quarterly MTTD reduction commitment — 18 hours per quarter — so the target is reached within four quarters, moving this from trajectory to commitment. The 37.5% improvement achieved year-over-year is a credible foundation, but the remaining 240-hour current value still exceeds the internal target by 72 hours — a window that defines how long an undetected nation-state actor can operate unchallenged. Formalising a reduction schedule converts an observed trend into a board-level accountability structure.
5. Lift patch compliance from 81.0% to the 95.0% target through monthly compliance reporting with owner accountability.
The vulnerability management lead must institute owner-level monthly patch compliance attestation, targeting 95.0% within two quarters. Patch compliance carries the lowest weight (0.1) in the composite risk model because it is a hygiene baseline — but for an APT-exposed organisation, the 19% of systems below the compliance line represent the lowest-effort initial access path for adversaries who pre-position on unpatched known vulnerabilities. This recommendation is the most operationally straightforward and the fastest to demonstrate to the audit committee as a concrete control improvement.
Appendix — Where every number came from
| Value | Amount | Source |
|---|---|---|
mttd_hours_baseline |
384 | M-Trends 2024: MTTD baseline 384 hours |
mttd_hours_current |
240 | M-Trends 2024: MTTD current 240 hours |
internal_detection_share_baseline_pct |
37% | M-Trends 2024: internal detection 37% in 2022 |
internal_detection_share_current_pct |
46% | M-Trends 2024: internal detection 46% in 2023 |
| Value | Amount | Basis |
|---|---|---|
mttr_hours_baseline |
168 | Typical SOC MTTR for APT-exposed orgs, hours |
mttr_hours_current |
96 | Managed-maturity improvement trajectory |
vuln_closure_rate_pct |
74.0% | Managed maturity, APT context, below best practice |
critical_vuln_count |
18 | APT-exposure org, active remediation in progress |
avg_vuln_age_days |
22 | Elevated given nation-state threat profile |
false_positive_rate_pct |
28.0% | EDR/NDR at managed maturity, above target |
detection_coverage_pct |
61.0% | MITRE ATT&CK coverage, managed-maturity EDR/NDR |
patch_compliance_pct |
81.0% | Below 90% threshold, APT-exposure risk context |
target_mttd_hours |
168 | Internal target: halve industry 2022 baseline |
target_mttr_hours |
72 | P1 containment within 72 hours, industry practice |
target_vuln_closure_rate_pct |
90.0% | NIST CSF 2.0 Respond/Recover best practice |
target_critical_vuln_count |
5 | Aspirational ceiling for APT-exposed environment |
target_avg_vuln_age_days |
14 | 14-day SLA standard for critical vulnerabilities |
target_false_positive_rate_pct |
15.0% | SOC efficiency target, managed-maturity programs |
target_detection_coverage_pct |
75.0% | MITRE ATT&CK coverage goal, EDR/NDR roadmap |
target_patch_compliance_pct |
95.0% | NIST CSF 2.0 Protect function benchmark |
w_mttd |
0.35 | MTTD weighted most: primary objective metric |
w_coverage |
0.25 | Detection coverage: structural APT exposure driver |
w_fp |
0.15 | False positives degrade analyst effectiveness |
w_vuln |
0.15 | Unpatched criticals amplify dwell time risk |
w_patch |
0.1 | Patch compliance: baseline hygiene signal |
| Value | Amount | Grounding |
|---|---|---|
mttd_improvement_pct |
37.5% | ✓ re-checked from your inputs |
mttr_improvement_pct |
42.9% | leans on: mttr_hours_baseline, mttr_hours_current |
internal_detection_share_gain_pct |
9.0% | ✓ re-checked from your inputs |
composite_risk_score |
71.3 | leans on: w_mttd, target_mttd_hours, w_coverage, detection_coverage_pct, w_fp, false_positive_rate_pct, w_vuln, critical_vuln_count, target_critical_vuln_count, w_patch, patch_compliance_pct |
The grouped figures behind the report’s charts, scorecards, and scenario tables. Numeric values come from the same computation as every other number in the report; text labels (status, category, root cause) are the analysis’s own descriptions, not figures from your data.
rh
| Likelihood | Impact | RiskScore | Tier |
|---|---|---|---|
| 1 | 1 | 1 | Low |
| 2 | 1 | 2 | Low |
| 3 | 1 | 3 | Low |
| 4 | 1 | 4 | Low |
| 5 | 1 | 5 | Medium |
| 1 | 2 | 2 | Low |
| 2 | 2 | 4 | Low |
| 3 | 2 | 6 | Medium |
| 4 | 2 | 8 | Medium |
| 5 | 2 | 10 | High |
| 1 | 3 | 3 | Low |
| 2 | 3 | 6 | Medium |
| 3 | 3 | 9 | Medium |
| 4 | 3 | 12 | High |
| 5 | 3 | 15 | High |
| 1 | 4 | 4 | Low |
| 2 | 4 | 8 | Medium |
| 3 | 4 | 12 | High |
| 4 | 4 | 16 | High |
| 5 | 4 | 20 | Critical |
| 1 | 5 | 5 | Medium |
| 2 | 5 | 10 | High |
| 3 | 5 | 15 | High |
| 4 | 5 | 20 | Critical |
| 5 | 5 | 25 | Critical |
risk_heatmap_df
| Likelihood | Impact | RiskScore | Tier |
|---|---|---|---|
| 1 | 1 | 1 | Low |
| 2 | 1 | 2 | Low |
| 3 | 1 | 3 | Low |
| 4 | 1 | 4 | Low |
| 5 | 1 | 5 | Medium |
| 1 | 2 | 2 | Low |
| 2 | 2 | 4 | Low |
| 3 | 2 | 6 | Medium |
| 4 | 2 | 8 | Medium |
| 5 | 2 | 10 | High |
| 1 | 3 | 3 | Low |
| 2 | 3 | 6 | Medium |
| 3 | 3 | 9 | Medium |
| 4 | 3 | 12 | High |
| 5 | 3 | 15 | High |
| 1 | 4 | 4 | Low |
| 2 | 4 | 8 | Medium |
| 3 | 4 | 12 | High |
| 4 | 4 | 16 | High |
| 5 | 4 | 20 | Critical |
| 1 | 5 | 5 | Medium |
| 2 | 5 | 10 | High |
| 3 | 5 | 15 | High |
| 4 | 5 | 20 | Critical |
| 5 | 5 | 25 | Critical |
scorecard_df
| Metric | Baseline | Target | Current | Status |
|---|---|---|---|---|
| MTTD (hrs) | 384 | 168 | 240 | Off Track |
| MTTR (hrs) | 168 | 72 | 96 | At Risk |
| Vulnerability Closure Rate % | 74 | 90 | 74 | Off Track |
| Critical Vuln Count | 18 | 5 | 18 | Off Track |
| Avg Vuln Age (days) | 22 | 14 | 22 | Off Track |
| False Positive Rate % | 28 | 15 | 28 | Off Track |
| Detection Coverage % | 61 | 75 | 61 | Off Track |
| Patch Compliance % | 81 | 95 | 81 | Off Track |
sla_df
| Severity | Detection_SLA_Hrs | Containment_SLA_Hrs | Eradication_SLA_Hrs | Review_Deadline | Penalty |
|---|---|---|---|---|---|
| P1 Critical | 42 | 72 | 144 | 24 hrs post-closure | Executive escalation + board notification |
| P2 High | 84 | 144 | 288 | 48 hrs post-closure | CISO notification required |
| P3 Medium | 168 | 288 | 576 | 5 business days | Monthly review inclusion |
| P4 Low | 336 | 576 | 1152 | 10 business days | Quarterly trend reporting |
trend_df
| Quarter | MTTD_Hours | MTTR_Hours | Target_MTTD |
|---|---|---|---|
| Q1 | 384 | 168 | 168 |
| Q2 | 363.4 | 157.7 | 168 |
| Q3 | 342.9 | 147.4 | 168 |
| Q4 | 322.3 | 137.1 | 168 |
| Q5 | 301.7 | 126.9 | 168 |
| Q6 | 281.1 | 116.6 | 168 |
| Q7 | 260.6 | 106.3 | 168 |
| Q8 | 240 | 96 | 168 |
How each number was derived
Every calculated figure, its formula, and the inputs and assumptions it ultimately rests on.
| Value | Amount | Formula | Traces back to |
|---|---|---|---|
mttd_improvement_pct |
37.5% | round((mttd_hours_baseline - mttd_hours_current)/mttd_hours_baseline * 100, 1) |
mttd_hours_baseline (input), mttd_hours_current (input) |
mttr_improvement_pct |
42.9% | round((mttr_hours_baseline - mttr_hours_current)/mttr_hours_baseline * 100, 1) |
mttr_hours_baseline (assumption), mttr_hours_current (assumption) |
internal_detection_share_gain_pct |
9.0% | internal_detection_share_current_pct - internal_detection_share_baseline_pct |
internal_detection_share_current_pct (input), internal_detection_share_baseline_pct (input) |
composite_risk_score |
71.3 | round(w_mttd * (mttd_hours_current/target_mttd_hours) * 100 + w_coverage * (1 - detection_coverage_pct/100) * 100 + w_fp * (false_positive_rate_pct/100) * 100 + w_vuln * (critical_vuln_count/target_critical_vuln_count) * 10 + w_patch * (1 - patch_compliance_pct/100) * 100, 1) |
mttd_hours_current (input), w_mttd (assumption), target_mttd_hours (assumption), w_coverage (assumption), detection_coverage_pct (assumption), w_fp (assumption), false_positive_rate_pct (assumption), w_vuln (assumption), critical_vuln_count (assumption), target_critical_vuln_count (assumption), w_patch (assumption), patch_compliance_pct (assumption) |