---
title: "IDECSI: Why the big Mean-Time-To-Detection?"
description: 197 days is the 2018 figure for Mean-Time-To-Detection (MTTD). Why does it take so long to identify breaches, and are we even identifying all of them?
image: https://blog.idecsi.com/hubfs/Blog%20Images/WEBSITE-BLOG-MTTD-2.png
---

[![Logo-Idecsi-Black-tagline](https://blog.idecsi.com/hs-fs/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-Black-tagline.png?width=1010&height=319&name=Logo-Idecsi-Black-tagline.png)](https://www.idecsi.com/)

- Solutions

  DETOX® pour M365
  
  Audit, Remediation & ROI
  
  [Discover DETOX](https://info.idecsi.com/detox-m365?hsLang=en)
  
  ![Audit, Remediation & ROI](https://blog.idecsi.com/hubfs/ILLU-4.png)

  Solutions
  
  IDECSI gives security and IT teams full control over their data — across DSPM, Data Access Governance, Human Risk Management, and Data Volume Management.

    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) M365 Data Security Platform](https://www.idecsi.com/solution/mydatasecurity/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Data storage optimization](https://www.idecsi.com/solution/mydatamanagement/)
- Challenges

  M365 Checklist
  
  15 Warning Signs Your M365 Data Is at Risk
  
  [Get the checklist](https://info.idecsi.com/checklist-15-warningsigns?hsLang=en)
  
  ![Checklist risques M365](https://blog.idecsi.com/hubfs/Frame-2147255341.png)

  Your 2026 Challenges
  
  Address your most critical data security and governance challenges - across your M365 environment

    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility accross M365](https://www.idecsi.com/challenges/visibility-microsoft-365)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Get Ready For Copilot M365](https://www.idecsi.com/challenges/m365-copilot/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Control external user access](https://www.idecsi.com/challenges/external-access-microsoft-365/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Prevent Sensitive Data Exposure](https://www.idecsi.com/challenges/sensitive-data-m365/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility across Microsoft 365](https://www.idecsi.com/challenges/visibility-microsoft-365/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Ensure regulatory compliance](https://www.idecsi.com/challenges/compliance-m365/)
- Resources

  Is Your Tenant Ready for Copilot?
  
  A Security & Governance Playbook
  
  [Download](https://info.idecsi.com/whitepapper_copilot?hsLang=en)
  
  ![Copilot guide](https://blog.idecsi.com/hubfs/Frame-2147255339.png)

  Our resources
  
  Check out our useful resources for improving data protection

    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Blog](https://blog.idecsi.com)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Help Center](https://help.idecsi.com/)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) Ressources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [![download\_done](https://blog.idecsi.com/hubfs/download_done.svg) About us](https://www.idecsi.com/about-us/)
- [Customers](https://blog.idecsi.com/resources-customer?hsLang=en)

Search

[Request a demo](https://info.idecsi.com/demo-idecsi?hsLang=en)

Security

08 November 2018

# Why the big Mean-Time-To-Detection?

![Mean time to detection illustration](https://f.hubspotusercontent40.net/hubfs/4272098/Blog%20Images/WEBSITE-BLOG-MTTD-2.png)

- [Home](https://www.idecsi.com/)
- [Blog](https://blog.idecsi.com)
- Why the big Mean-Time-To-Detection?

## “197 days: The average length of time it takes for organisations to identify a data breach” 1

This statistic Mean-Time-To-Detection (MTTD) comes up every year. 197 days is the 2018 figure, but it’s always quite big. It is marginally up on the previous year, up from 191 days. This begs two questions: why does it take so long to identify breaches, and are we even identifying all of them?

There are two ways to identify a breach:  

1. Spot some type of unusual behaviour in the network, on our devices, or in our applications, and track this down to malicious activity. 
2. The results of the breach become public. 

The first of these, spotting unusual behaviour, typically requires highly sophisticated tools, be that log centralisation, SIEM, Intrusion Detection and Prevention Software, etc. And just as important as these tools is the resource to manage them. Breach detection is a highly sophisticated activity, and the more sophisticated tools require more sophisticated users and analysts. And even with the best tools and the best people, there are still a huge number of alerts to analyse every day. (And don’t forget that most companies can’t afford state-of-the-art, and cannot recruit, never mind retain, top analysts.) It’s not at all surprising that companies do not spot everything. 

Which means it’s quite common for breaches to be detected by somebody outside, who then reports it to the company. According to a 2018 report2, in 38% of breaches, **the company finds out from an external source**. That seems like a high number, but in fact it’s significantly down from 2017 when it was 53%. Often, this will simply be users who have discovered their data is public – be that commercial customers or private users – and they will tell the company who will then investigate and identify the breach.

All of which leads to an inexorable conclusion: it is likely that **large numbers breaches go completely undetected**. In some cases, it may never be noticed that the data was stolen. In other cases, stolen data may be in the public domain, but it will not be clear from where it was stolen. At this point, I’m sure you’d like me to provide some wisdom on how we address this. Unfortunately, there is no silver bullet.

That said, I, and in fact, we at IDECSI, do think that breach detection can be improved. Way too much monitoring and detection depends on smart people and deep (and expensive) technology. However, we think you can be more precise in breach detection, identifying things at a user and application level which allows almost instant identification of breaches. It’s a very different approach from the AI of some [SIEM](https://blog.idecsi.com/optimise-siem-office365-alerts?hsLang=en)and IDPS solutions, but also very effective. You can find out more by reading about the IDECSI MyDataSecurity. 

## **A few words about Ben Miller**

Ben Miller is an experienced technologist and entrepreneur with a background in mathematics and software engineering. He is focused on bringing new technologies to market, which change conventional thinking. Within cyber security, we have long been used to complaining about users, and driving more work into the security team. Ben’s particular focus today is technologies which challenge this approach and instead make user empowerment a key part of the cyber discussion.

\[1\] IBM Report "How much does a data breach cost?"  
\[2\] FireEye, Special Reports "M-Trends 2018"

 Recent articles

[Microsoft 365 SharePoint Storage Costs in 2026: What's Changing](https://blog.idecsi.com/microsoft-365-sharepoint-storage-costs-2026?hsLang=en)

[Zero Trust Data Governance for Microsoft 365: CISO Guide](https://blog.idecsi.com/zero-trust-data-governance-microsoft-365?hsLang=en)

[Cybersecurity Awareness Month: A CISO's M365 Action Plan](https://blog.idecsi.com/cybersecurity-awareness-month-ciso-action-plan-m365?hsLang=en)

[Microsoft Foundry: Complete Guide and Data Security Implications (2026)](https://blog.idecsi.com/microsoft-foundry-guide-security?hsLang=en)

 Best practices to improve Microsoft Teams security

[![Download the infographic ](https://no-cache.hubspot.com/cta/default/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f)

 Share this article

<https://twitter.com/intent/tweet?text=https://blog.idecsi.com/why-the-big-mttd> <http://www.facebook.com/sharer.php?u=https://blog.idecsi.com/why-the-big-mttd> <https://www.linkedin.com/sharing/share-offsite/?url=https://blog.idecsi.com/why-the-big-mttd>

Subscribe to our newsletter and receive new contents every month

 Our articles

These articles may   
interest you

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Microsoft%20Foundry%20_%20guide%20complet%20et%20enjeux%20pour%20la%20s%C3%A9curit%C3%A9%20%282026%29.png)

 Microsoft 365

 Security

 Microsoft Foundry: Complete Guide and Data Security Implications (2026) 

<https://blog.idecsi.com/microsoft-foundry-guide-security?hsLang=en> [Lire l'article](https://blog.idecsi.com/microsoft-foundry-guide-security?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Illus-Blog-Supervision.png)

 Microsoft 365

 Security

 Microsoft 365 Phishing: Why Oversharing Makes a Compromised Account Far More Dangerous 

<https://blog.idecsi.com/fr/phishing-microsoft-365-risques-donnees-partagees-1?hsLang=en> [Lire l'article](https://blog.idecsi.com/fr/phishing-microsoft-365-risques-donnees-partagees-1?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/image%20%2858%29.png)

 Microsoft 365

 Security

 Securing AI Agents in Microsoft 365: Best Practices for 2026 

<https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en> [Lire l'article](https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Exposition%20des%20donn%C3%A9es%20dans%20Microsoft%20365%20_%20risques%20et%20controle%202.png)

 Security

 Data Exposure in Microsoft 365: Understanding the Risks and Taking Back Control 

<https://blog.idecsi.com/microsoft-365-data-exposure?hsLang=en> [Lire l'article](https://blog.idecsi.com/microsoft-365-data-exposure?hsLang=en)

### Data protection, let's discuss your project?

 

[![Contact us](https://no-cache.hubspot.com/cta/default/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe)

![video background](https://idecsi2a-dev-idecsi.pf27.wpserveur.net/wp-content/uploads/2022/02/video-background-idecsi-responsive-1.png)

[![Logo-Idecsi-White-Ss-ES](https://blog.idecsi.com/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-White-Ss-ES.svg)](https://www.idecsi.com/)

 +33 1 84 79 38 30

- <https://twitter.com/IDECSI>
- <https://www.facebook.com/IDECSI-306865969441428/>
- <https://www.linkedin.com/company/idecsi/>

- [Why choose IDECSI?](https://www.idecsi.com/user-security/)
- [About us](https://www.idecsi.com/about-us/)
- [Join the team](https://www.welcometothejungle.com/fr/companies/idecsi)

- Solutions 
    - [Visibility](https://www.idecsi.com/challenge-data-visibility/)
    - [Detection](https://www.idecsi.com/challenge-threat-detection/)
    - [User engagement](https://www.idecsi.com/challenge-involve-user/)
    - [Access review](https://www.idecsi.com/challenge-rights-review/)
    - [Remediation](https://www.idecsi.com/challenge-remediation/)
    - [Sensitive data](https://www.idecsi.com/challenge-sensitive-data/)

- [Products](https://www.idecsi.com/solution/) 
    - [MyDataSecurity](https://www.idecsi.com/solution/mydatasecurity/)
    - [Advanced Monitoring](https://www.idecsi.com/solution/advanced-monitoring/)
    - [MyDataManagement](https://www.idecsi.com/solution/mydatamanagement/)

- Resources 
    - [Resources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [Blog](https://blog.idecsi.com)
    - [Customer success](https://blog.idecsi.com/resources-customer?hsLang=en)
    - [Extranet](https://extranet.idecsi.com?hsLang=en)

 © IDECSI

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Daniel Bénabou",
    "url" : "https://blog.idecsi.com/author/daniel"
  },
  "dateModified" : "2022-12-20T16:27:47.131Z",
  "datePublished" : "2018-11-08T14:21:00.000Z",
  "headline" : "IDECSI: Why the big Mean-Time-To-Detection?",
  "image" : [ "https://blog.idecsi.com/hubfs/Blog%20Images/WEBSITE-BLOG-MTTD-2.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.idecsi.com/why-the-big-mttd",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.idecsi.com/hubfs/Logo-Idecsi-Black-tagline.png"
    },
    "name" : "IDECSI"
  }
}
```