<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Metrics on d3soteric</title><link>https://blog.d3soteric.com/tags/metrics/</link><description>Recent content in Metrics on d3soteric</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 22 Sep 2026 07:00:00 -0600</lastBuildDate><atom:link href="https://blog.d3soteric.com/tags/metrics/index.xml" rel="self" type="application/rss+xml"/><item><title>Mean Time to What?</title><link>https://blog.d3soteric.com/mean-time-to-what/</link><pubDate>Tue, 22 Sep 2026 07:00:00 -0600</pubDate><guid>https://blog.d3soteric.com/mean-time-to-what/</guid><description>Every metric names a moment. Mean time to detect names the moment a signal exists. Mean time to respond names the moment someone acts on it. In vulnerability management we lean on mean time to resolve, which names the moment the finding is gone. These are good words, and they have served the industry well.
The trouble is not the words. It is what sits between the moments, and who does the work there.</description></item></channel></rss>