Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cyera: Why MTTR Is a Misleading Vulnerability Metric

Cyera
07/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


by fixing 1% of the open vulnerabilities in your environment. And the measurement would look like, wow, we're blowing it out. Meanwhile, you've got 99% of the vulnerabilities that are untouched and open to exploitation. Most people look at MTTR and they think it is a measure of how quickly the program is remediating or burning down vulnerabilities in their environment. And the faster, the better, right? That's the general consensus. But the thing is, the critical missing component is MTTR is only measuring the vulnerabilities that you remediate. It is not measuring all the vulnerabilities that are left open and unpatched, unfixed, unresolved. I think it is misunderstood and misapplied. It does have some usefulness, but what people think it's telling them is not it.

TL;DR

  • MTTR only measures vulnerabilities that have been remediated — it completely ignores the open, unpatched vulnerabilities still present in the environment.
  • A program can achieve a strong MTTR score by fixing just 1% of vulnerabilities, while 99% remain exposed and exploitable.
  • Wade Baker of the Cyentia Institute calls MTTR misunderstood and misapplied, warning that what practitioners think it measures is not what it actually reflects.

Summary

In this short clip from The Watchtower, Wade Baker, co-founder of the Cyentia Institute, challenges one of the most widely used metrics in vulnerability management: Mean Time to Remediate (MTTR). Baker argues that MTTR is fundamentally misunderstood and misapplied across security programs because it only measures the vulnerabilities that teams actually close — not the full population of open, unpatched exposures sitting in the environment. The result is a metric that can look excellent on paper while 99% of vulnerabilities remain untouched and exploitable. Baker illustrates this with a pointed example: a program that fixes just 1% of its open vulnerabilities could still post an impressive MTTR score, creating a false sense of progress. His conclusion is direct — MTTR has limited usefulness, and what most practitioners believe it is telling them about program effectiveness is simply not accurate. Security leaders relying on MTTR as a primary measure of remediation velocity should reconsider what the metric actually captures and what it systematically ignores.

Chapters

0:00 - The MTTR Illusion
0:17 - What MTTR Actually Measures
0:46 - Misunderstood and Misapplied

Key Quotes

0:00 "You can have an extremely good MTTR by fixing 1% of the open vulnerabilities in your environment."
0:11 "Meanwhile, you've got 99% of the vulnerabilities that are untouched and open to exploitation."
0:35 "MTTR is only measuring the vulnerabilities that you remediate. It is not measuring all the vulnerabilities that are left open and unpatched, unfixed, unresolved."
0:46 "I think it is misunderstood and misapplied. It does have some usefulness, but what people think it's telling them is not it."

FAQ

Why is MTTR considered a vanity metric for vulnerability programs?

Because MTTR only calculates the average time to close vulnerabilities that were actually remediated. It excludes all open, unpatched vulnerabilities from the calculation, meaning a team can post a fast MTTR by selectively fixing a small fraction of issues while the majority of exposures remain unaddressed.

Does MTTR have any value at all?

Wade Baker acknowledges that MTTR has some usefulness, but cautions that it is widely misunderstood. The problem is not the metric itself but the assumption that it reflects overall remediation program effectiveness — which it does not.


Categories:
  • » Webinar Library » Cyera
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Security Operations
  • Thought Leadership
  • short_form
  • Executive Briefing
  • MTTR
  • Security Metrics
  • Remediation Programs
  • Risk Measurement
  • CISO Strategy
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cyera: Why MTTR Is a Misleading Vulnerability Metric

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                      https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version