Activity 14.2: Calculating Incident Metrics
Incident metrics are essential to evaluate the effectiveness of an organization’s response to cybersecurity incidents by providing measurable insights into how quickly incidents are detected, contained, and resolved. The following activity presents you with three incident scenarios, each highlighting a different key metric.
In this activity, you will analyze the timelines of three cybersecurity incidents to calculate key incident metrics: mean time to remediate, MTTD, and mean time to respond. By working with realistic incident timelines, you will gain hands-on experience in applying these critical metrics to evaluate the efficiency of an organization’s incident response processes.
Incident 1 Timeline
The following is the timeline of an incident response process. It provides the time at which each major milestone occurred. You need to determine the mean time to remediate:
- Time when hackers breached a network...