Security leader proposes 'Mean Time to Adapt' as new cybersecurity KPI
A C86 executive says cybersecurity needs a 'Mean Time to Adapt' metric to measure resilience against evolving threats.
The article says MTTD and MTTR remain valuable operational measures because they show how effectively a security team performs during an incident. But the author argues they do not tell executives whether an organization is better prepared for what comes next, or whether it is learning from incidents quickly enough.
The author points to the UK government's Cyber Security Breaches Survey 2025/2026, which found that 43% of UK businesses experienced a cyber breach or attack during the previous year, to underline that incidents have become a regular reality. Responding well is important, the article says, but resilience is shaped by everything that happens before and after an incident. A business might recover quickly from an attack yet take months to review security policies, reassess supplier risk or strengthen controls. By the time those changes are made, the threat landscape has moved on, the author writes.
The proposed MTTA metric would consider how long an organization takes to recognize a meaningful change in the threat landscape and turn that recognition into action. The action could be technical, such as updating detection rules, tightening access to critical systems after a vulnerability is discovered, or studying an attack against another sector. It could also be organizational, including reviewing governance, changing how cyber risk is reported to the board, or refreshing employee awareness programs to reflect the latest attacker tactics.
The author contends that resilience depends on both technical improvements and organizational change, and that the strongest security programs combine the two. Businesses that adapt well rarely assume their current security program is complete; they expect it to evolve because the environment around them is evolving, the article says. The piece also cites the National Cyber Security Centre's Cyber Assessment Framework, which places governance, risk management and continual improvement at the heart of cyber resilience, describing security as an ongoing organizational capability rather than a one-time achievement.