Threat Response & Compliance SLA Generator

How to read this report. Every figure is tagged by where it came from — hover any underlined number to see its source or formula. A full breakdown of every value is in the appendix.

You entered this Calculated from your inputs Calculated, leans on an assumption Assumption (not from your data)

Executive Summary

Detection speed is the primary defense against adversaries with the persistence and patience of nation-state actors — and this program has made measurable, board-reportable progress. Mean time to detect fell from 384 hours to 240 hours, a 37.5% reduction year-over-year, moving toward but not yet reaching the internal target of 168 hours. The composite risk score stands at 71.3, reflecting a program that has improved materially but carries active structural gaps that require directed action in the next operating period.

  • Headline gain, not yet victory: MTTD improved 37.5% and MTTR improved 42.9% — both meaningful reductions in the window nation-state actors exploit for lateral movement and data staging. Neither metric has reached its target, and the gap to target is the operative board concern.
  • Internal detection share is rising but below parity: 46% of intrusions are now detected internally, up 9.0% percentage points from 37%. For an APT-exposed organisation, every point of external detection share is an incident the program did not catch first — reducing that residual 54% is the structural objective.
  • Vulnerability exposure is the most urgent gap: 18 critical vulnerabilities remain open at an average age of 22 days against a 14-day SLA target. Nation-state actors routinely exploit known vulnerabilities within days of disclosure; this gap directly extends effective dwell time.
  • Detection coverage and false positive rate are both off-target: Coverage at 61.0% against a 75.0% target means adversary techniques exist in the environment with no detection logic. A false positive rate of 28.0% — nearly double the 15.0% target — degrades analyst capacity and masks real signals in noise.
  • Patch compliance at 81.0% is insufficient for this threat profile: The 95.0% target is a hygiene floor, not an aspiration. The current 74.0% closure rate means one in four vulnerabilities identified is not remediated in the operating cycle.

Security KPI Scorecard

Note

Five of eight KPIs are off-target; MTTD and MTTR show the strongest year-over-year improvement but remain above their targets.


MTTD & MTTR Quarterly Trend

Note

MTTD has fallen 37.5% over eight quarters but remains 72 hours above the 168-hour target — the gap that nation-state actors can still exploit.

Methodology note: Quarterly values are modeled as a linear interpolation from the baseline to the current observed value. They represent a required-path trajectory, not independently observed quarterly actuals. The Q8 endpoint is an observed value; intermediate quarters are synthetic. Target MTTD is shown as a reference line.


Risk Tier Heat Map

Note

The Critical quadrant (Likelihood 4–5, Impact 4–5) is the APT-relevant zone — this is where nation-state intrusion scenarios cluster given the current detection coverage gap.


Incident Response SLA Matrix

Note

P1 Critical incidents require detection within 42 hours and containment within 72 hours — both tighter than the program’s current MTTD and MTTR, meaning P1 SLAs are structurally at risk today.


Key Recommendations

Ranked by estimated impact on composite risk score reduction, then feasibility within the next operating quarter.


1. Accelerate critical vulnerability remediation to close the 18-open-critical gap.

The security operations lead must implement a dedicated critical-vulnerability war-room cadence targeting zero open criticals above 14 days, within the next 60 days. Closing the 18 open criticals and lifting the closure rate from 74.0% to 90.0% directly removes the most exploitable attack surface for persistent adversaries, and carries the highest weight in reducing the composite risk score from 71.3. At the current threat profile, an open critical vulnerability at 22 days average age is an active invitation — not a risk to be deferred.


2. Expand detection logic to close the 14-percentage-point coverage gap.

The SOC detection engineering team must map and fill the delta between current 61.0% coverage and the 75.0% target within two quarters, prioritising technique categories most associated with initial access and lateral movement in APT playbooks. Detection coverage carries a weight of 0.25 in the composite risk model — closing this gap is the second-largest lever available to the program this year. The 54% of intrusions not caught internally are predominantly cases where no detection logic exists for the adversary’s chosen technique.


3. Halve the false positive rate to restore analyst signal fidelity.

The detection tuning lead must systematically suppress or retire alert rules producing false positives, targeting a reduction from 28.0% to 15.0% within one quarter. Analyst time spent on false alerts is time not spent validating real detections — at a 28.0% rate, nearly three in ten alerts are noise, directly compressing the human capacity needed to sustain the MTTD gain of 37.5%. The false positive weight of 0.15 in the composite score understates the operational impact: analyst burnout and alert fatigue are the mechanism by which detection coverage gaps become dwell-time gains for adversaries.


4. Drive MTTD from 240 hours toward the 168-hour target through structured quarterly reduction commitments.

The CISO must present the board with a quarterly MTTD reduction commitment — 18 hours per quarter — so the target is reached within four quarters, moving this from trajectory to commitment. The 37.5% improvement achieved year-over-year is a credible foundation, but the remaining 240-hour current value still exceeds the internal target by 72 hours — a window that defines how long an undetected nation-state actor can operate unchallenged. Formalising a reduction schedule converts an observed trend into a board-level accountability structure.


5. Lift patch compliance from 81.0% to the 95.0% target through monthly compliance reporting with owner accountability.

The vulnerability management lead must institute owner-level monthly patch compliance attestation, targeting 95.0% within two quarters. Patch compliance carries the lowest weight (0.1) in the composite risk model because it is a hygiene baseline — but for an APT-exposed organisation, the 19% of systems below the compliance line represent the lowest-effort initial access path for adversaries who pre-position on unpatched known vulnerabilities. This recommendation is the most operationally straightforward and the fastest to demonstrate to the audit committee as a concrete control improvement.

Appendix — Where every number came from

Value Amount Source
mttd_hours_baseline 384 M-Trends 2024: MTTD baseline 384 hours
mttd_hours_current 240 M-Trends 2024: MTTD current 240 hours
internal_detection_share_baseline_pct 37% M-Trends 2024: internal detection 37% in 2022
internal_detection_share_current_pct 46% M-Trends 2024: internal detection 46% in 2023
Value Amount Basis
mttr_hours_baseline 168 Typical SOC MTTR for APT-exposed orgs, hours
mttr_hours_current 96 Managed-maturity improvement trajectory
vuln_closure_rate_pct 74.0% Managed maturity, APT context, below best practice
critical_vuln_count 18 APT-exposure org, active remediation in progress
avg_vuln_age_days 22 Elevated given nation-state threat profile
false_positive_rate_pct 28.0% EDR/NDR at managed maturity, above target
detection_coverage_pct 61.0% MITRE ATT&CK coverage, managed-maturity EDR/NDR
patch_compliance_pct 81.0% Below 90% threshold, APT-exposure risk context
target_mttd_hours 168 Internal target: halve industry 2022 baseline
target_mttr_hours 72 P1 containment within 72 hours, industry practice
target_vuln_closure_rate_pct 90.0% NIST CSF 2.0 Respond/Recover best practice
target_critical_vuln_count 5 Aspirational ceiling for APT-exposed environment
target_avg_vuln_age_days 14 14-day SLA standard for critical vulnerabilities
target_false_positive_rate_pct 15.0% SOC efficiency target, managed-maturity programs
target_detection_coverage_pct 75.0% MITRE ATT&CK coverage goal, EDR/NDR roadmap
target_patch_compliance_pct 95.0% NIST CSF 2.0 Protect function benchmark
w_mttd 0.35 MTTD weighted most: primary objective metric
w_coverage 0.25 Detection coverage: structural APT exposure driver
w_fp 0.15 False positives degrade analyst effectiveness
w_vuln 0.15 Unpatched criticals amplify dwell time risk
w_patch 0.1 Patch compliance: baseline hygiene signal
Value Amount Grounding
mttd_improvement_pct 37.5% ✓ re-checked from your inputs
mttr_improvement_pct 42.9% leans on: mttr_hours_baseline, mttr_hours_current
internal_detection_share_gain_pct 9.0% ✓ re-checked from your inputs
composite_risk_score 71.3 leans on: w_mttd, target_mttd_hours, w_coverage, detection_coverage_pct, w_fp, false_positive_rate_pct, w_vuln, critical_vuln_count, target_critical_vuln_count, w_patch, patch_compliance_pct

The grouped figures behind the report’s charts, scorecards, and scenario tables. Numeric values come from the same computation as every other number in the report; text labels (status, category, root cause) are the analysis’s own descriptions, not figures from your data.

rh

Likelihood Impact RiskScore Tier
1 1 1 Low
2 1 2 Low
3 1 3 Low
4 1 4 Low
5 1 5 Medium
1 2 2 Low
2 2 4 Low
3 2 6 Medium
4 2 8 Medium
5 2 10 High
1 3 3 Low
2 3 6 Medium
3 3 9 Medium
4 3 12 High
5 3 15 High
1 4 4 Low
2 4 8 Medium
3 4 12 High
4 4 16 High
5 4 20 Critical
1 5 5 Medium
2 5 10 High
3 5 15 High
4 5 20 Critical
5 5 25 Critical

risk_heatmap_df

Likelihood Impact RiskScore Tier
1 1 1 Low
2 1 2 Low
3 1 3 Low
4 1 4 Low
5 1 5 Medium
1 2 2 Low
2 2 4 Low
3 2 6 Medium
4 2 8 Medium
5 2 10 High
1 3 3 Low
2 3 6 Medium
3 3 9 Medium
4 3 12 High
5 3 15 High
1 4 4 Low
2 4 8 Medium
3 4 12 High
4 4 16 High
5 4 20 Critical
1 5 5 Medium
2 5 10 High
3 5 15 High
4 5 20 Critical
5 5 25 Critical

scorecard_df

Metric Baseline Target Current Status
MTTD (hrs) 384 168 240 Off Track
MTTR (hrs) 168 72 96 At Risk
Vulnerability Closure Rate % 74 90 74 Off Track
Critical Vuln Count 18 5 18 Off Track
Avg Vuln Age (days) 22 14 22 Off Track
False Positive Rate % 28 15 28 Off Track
Detection Coverage % 61 75 61 Off Track
Patch Compliance % 81 95 81 Off Track

sla_df

Severity Detection_SLA_Hrs Containment_SLA_Hrs Eradication_SLA_Hrs Review_Deadline Penalty
P1 Critical 42 72 144 24 hrs post-closure Executive escalation + board notification
P2 High 84 144 288 48 hrs post-closure CISO notification required
P3 Medium 168 288 576 5 business days Monthly review inclusion
P4 Low 336 576 1152 10 business days Quarterly trend reporting

trend_df

Quarter MTTD_Hours MTTR_Hours Target_MTTD
Q1 384 168 168
Q2 363.4 157.7 168
Q3 342.9 147.4 168
Q4 322.3 137.1 168
Q5 301.7 126.9 168
Q6 281.1 116.6 168
Q7 260.6 106.3 168
Q8 240 96 168

How each number was derived

Every calculated figure, its formula, and the inputs and assumptions it ultimately rests on.

Value Amount Formula Traces back to
mttd_improvement_pct 37.5% round((mttd_hours_baseline - mttd_hours_current)/mttd_hours_baseline * 100, 1) mttd_hours_baseline (input), mttd_hours_current (input)
mttr_improvement_pct 42.9% round((mttr_hours_baseline - mttr_hours_current)/mttr_hours_baseline * 100, 1) mttr_hours_baseline (assumption), mttr_hours_current (assumption)
internal_detection_share_gain_pct 9.0% internal_detection_share_current_pct - internal_detection_share_baseline_pct internal_detection_share_current_pct (input), internal_detection_share_baseline_pct (input)
composite_risk_score 71.3 round(w_mttd * (mttd_hours_current/target_mttd_hours) * 100 + w_coverage * (1 - detection_coverage_pct/100) * 100 + w_fp * (false_positive_rate_pct/100) * 100 + w_vuln * (critical_vuln_count/target_critical_vuln_count) * 10 + w_patch * (1 - patch_compliance_pct/100) * 100, 1) mttd_hours_current (input), w_mttd (assumption), target_mttd_hours (assumption), w_coverage (assumption), detection_coverage_pct (assumption), w_fp (assumption), false_positive_rate_pct (assumption), w_vuln (assumption), critical_vuln_count (assumption), target_critical_vuln_count (assumption), w_patch (assumption), patch_compliance_pct (assumption)