Research · 5 min read
A 5.6-Minute Average Is a Promise the Response Tail Doesn’t Keep
Response reporting needs a target-hit rate, upper-tail percentiles, cancellations, and missing arrivals beside the average.
“Average response: 5.6 minutes.” Every security proposal carries a number like that — including ours. Here’s what ours doesn’t say: one in ten arrivals took longer than 10.1 minutes, and one in twenty longer than 12.3. The average is not wrong. It is simply the wrong number to plan from.
Our analysis of 1,827 dispatches; 1,721 valid recorded arrivals, July 1, 2025 through June 30, 2026.
Key takeaways
- Half of 1,721 valid arrivals were at or under 5.0 minutes and 36.7% within four, but one in ten took over 10.1 minutes and one in twenty over 12.3.
- The distribution has a cohort: 1,827 dispatches, of which 93 were cancelled and 13 had no valid arrival timestamp — 94.2% were usable.
- The clock starts at dispatch order, not at the initial alert, so it excludes the time between alert and dispatch decision.
- Pick the wait you can tolerate, then report the percentage that met it. An average cannot answer that question; a distribution can.
What does a 5.6-minute average response time leave out?
Among 1,721 valid recorded arrivals from July 1, 2025 through June 30, 2026, half landed within 5.0 minutes and 36.7% within four — but one in ten took longer than 10.1 minutes and one in twenty longer than 12.3. Another 93 dispatches were cancelled and 13 had no valid arrival timestamp. Plan from the distribution and the cohort, not the mean.
The numbers behind the answer
Selected measures only. Denominators and interpretation stay attached so the headline cannot stand alone.
5.0 min
Median valid arrival
Half of 1,721 dispatches with valid recorded arrivals were at or below five minutes.
10.1 min
90th-percentile arrival
One in ten valid arrivals took longer than 10.1 minutes.
36.7%
Arrived within 4 minutes
The complement—63.3%—took longer than the four-minute threshold.
The 5.6-minute average hides a wait twice as long for one in ten arrivals
The mean and median here are close — 5.6 and 5.0 minutes — which makes the average look trustworthy. The tail is where the plan lives. The 75th percentile is 7.3 minutes, the 90th is 10.1, and the 95th is 12.3. If your property tolerates a six-minute wait, the interesting question isn’t the average — it’s what share of arrivals beat six minutes, and what the slowest tenth looked like.
That’s the fix: report a target-hit rate beside the average. Pick the wait you can tolerate, then ask what percentage made it. Averages can’t answer that question. Distributions can.
The gap between the mean and the tail is the whole story. A 5.6-minute average sounds like a promise that every arrival lands in about five or six minutes. The distribution says a third of arrivals took longer than five, a tenth took longer than ten, and the slowest twentieth took more than twelve — a wait more than twice the headline. Both facts come from the same 1,721 arrivals.
Planning number
Choose the tolerated wait first, then report the percentage that met it.
A threshold curve shows the experience an average cannot
Read the ladder directly. 36.7% of valid arrivals made it inside four minutes. Half made five, and three quarters made 7.3. Nine in ten made 10.1 minutes; nineteen in twenty made 12.3. Each rung is a planning decision — the tighter your tolerance, the smaller the share that meets it.
One scope note that matters when comparing providers: this clock starts at dispatch order. It doesn’t include the time between the initial alert and the dispatch decision. Anyone quoting arrival times should say where their clock starts.
The ladder’s shape is the argument against the average. Between four and six minutes the share barely moves — 36.7% to roughly half — but between six and ten it climbs steeply, which means a lot of arrivals cluster just past the tolerance many properties would set. A property that demands six minutes is planning against a coin flip; one that accepts ten is planning against a nine-in-ten event. The same fleet produces both outcomes.
Evidence visual
Arrival-time percentile ladder
Percentiles use the 1,721 dispatches with valid recorded arrivals. Cancellations and missing arrival times remain outside this distribution and are reported separately.
Dispatch-to-arrival is not alert-to-arrival
The single easiest way to flatter a response number is to move where the clock starts. Ours begins at dispatch order and stops at first arrival — 5.0-minute median, 10.1-minute 90th percentile. It does not include the time from the initial alert to the dispatch decision, which for a monitored property may include detection, verification, and a call to a responder.
That segment is not trivial, and it is visible in public data. In Seattle’s 2024 call records, the median dispatch delay was 1.48 minutes for priority-1 calls but 14.78 for priority-2 — the queue, not the drive, dominated. Any provider quoting an arrival time should be asked to state both ends of its clock. Two systems can post identical five-minute medians and entirely different alert-to-arrival experiences.
106 dispatches do not enter the arrival-time distribution
The distribution has a denominator: 1,827 dispatches. 93 were cancelled. 13 never got a valid arrival timestamp. The percentiles come from the remaining 1,721 — 94.2% of the cohort.
Cancellations shouldn’t be assigned invented durations — but they shouldn’t vanish either. A provider whose average quietly excludes cancelled and missing arrivals is grading their own homework. Keep the excluded rows visible beside the curve.
The 106 excluded dispatches are only 5.8% of the cohort, small enough that they would not move the headline much — which is precisely why leaving them out is easy and why listing them is honest. The question for a buyer is not whether exclusions exist; every real dataset has them. It is whether they are disclosed, and whether the cancelled calls were cancelled because the situation resolved before arrival — a good outcome — or for some less flattering reason.
Define the clock, completion, target, and tail
The defensible scorecard has five parts: what starts and stops the clock; total dispatches with cancelled and missing broken out; the target-hit rate; and the median, P90, and P95. If any piece is missing, the average is doing the hiding.
One more limit: this aggregate combines mobile and posted-on-site response, and it doesn’t control for geography, traffic, severity, or concurrent demand. Comparing modes — or explaining the tail — takes separate distributions. Ask for them.
The five parts fit on one page, and that is the test. If a proposal leads with a single average and cannot immediately produce the clock definition, the cohort accounting, and the upper percentiles, the number is decoration. This aggregate is our own, and we report it this way because the same standard should apply to us.
- Clock start and stop definitions
- Total, cancelled, missing, and analyzed cohorts
- Target-hit share
- Median, P90, and P95
- Separate mobile and posted-on-site distributions
The slow tenth is a queue property of the same 1,721 arrivals
The tail is arithmetic, not anecdote. Across 1,827 dispatches, 1,721 arrivals were valid — 94.2% — after 93 cancellations and 13 missing timestamps. On those 1,721, the median was 5.0 minutes, p75 7.3, p90 10.1, and p95 12.3, and only 36.7% arrived within four. The mean, 5.6, sits close to the median and still describes almost none of the slow end.
A right tail like that is what a queue produces: when demand outruns units, waits stretch, and the same shape appears wherever response is measured. In emergency medicine, shorter ambulance response times raise survival; in policing, quasi-experimental work links faster response to higher clearance; and methodological study of computer-aided dispatch data shows triage and coding shape what a response study can even see.
So the planning number is the tolerated wait, not the mean. Pick the wait this property can live with, report the share of the 1,721 that met it, and set that tolerance with the property’s own risk and operations rather than a vendor’s average.
Queue view
The tail is a capacity and triage property; report it as one.
Questions property teams ask
Does a 5.6-minute average mean most responses took 5.6 minutes?
No. Half of valid arrivals were within 5.0 minutes, while one in ten took longer than 10.1 minutes.
Why report a target-hit rate instead of an average?
A target-hit rate answers the planning question directly: of all arrivals, what share met the wait the property can tolerate. An average cannot.
Why use the 90th percentile?
It describes the slower end directly: 90% were at or below that time and 10% were above it.
When does this response clock start?
At dispatch order. It excludes the time between the initial alert and the dispatch decision, which is a separate and often larger segment for lower-priority work.
Are cancellations counted as slow responses?
No duration is imputed. The 93 cancellations remain visible beside, but outside, the valid-arrival distribution.
Does this prove mobile or posted-on-site response is faster?
No. The current headline combines both modes; comparison requires separate distributions and operating-context controls.
Why are slow arrivals not just individual failures?
Because a queue has a long tail by construction: when demand outpaces available units, some waits stretch well past the median. The tail reflects capacity and triage, not individual failures.
Our methods, limits, and sources
How we calculated this
This is original 911 Sentinel research — we gathered the records, ran every calculation below, and published the aggregate dataset.
We measured minutes from dispatch order to valid recorded arrival across our own dispatches and kept cancellations and missing arrivals outside the duration distribution but inside cohort accounting.
- We validated dispatch order, cancellation status, response mode, and arrival timestamp.
- We separated 93 cancelled, 13 missing, and 1,721 valid-arrival records.
- We calculated the mean, percentiles, and 2/4/6/8/10/12-minute threshold shares.
- We produced response-mode distributions without inferring performance from mode counts alone.
What this analysis cannot establish
- The clock begins at dispatch order, not at the initial alert or acknowledgment.
- Cancelled and missing arrivals are excluded from duration percentiles.
- The aggregate combines mobile and posted-on-site response modes.
- Geography, traffic, severity, staffing, and concurrent demand are not controlled.
- The result describes a cohort and is not a guaranteed response time.
Sources
The raw records come from the sources below; the study design, analysis, charts, and conclusions are our own.
- Johan Holmén et al. (Journal of the American Heart Association) — Shortening Ambulance Response Time Increases Survival in Out-of-Hospital Cardiac Arrest
- Jordi Blanes i Vidal & Tom Kirchmaier (The Review of Economic Studies) — The Effect of Police Response Time on Crime Clearance Rates
- Cynthia Lum et al. (Police Quarterly) — Examining the Empirical Realities of Proactive Policing Through Systematic Observations and Computer-Aided Dispatch Data
Related questions and practical guides
No obligation · free property walk
Ask for the tail before accepting the average
A response plan should define the clock, target, escalation point, cancellation treatment, and upper-tail reporting for the property.