Alert fatigue and the math of false positives in a SOC
By Elias Lankinen11 min read
All sources and images confirmed. Writing the post now.
The alert that no one answered
On November 30, 2013, a piece of malware called back to its command server for the first time inside Target's network. The company had spent $1.6 million on a FireEye intrusion detection system, and it worked exactly as designed. It caught the malware, flagged it, and lit up a dashboard. A team of security specialists in Bangalore, watching Target's network around the clock, saw the alert and forwarded it to headquarters in Minneapolis, according to the Bloomberg Businessweek investigation that first reported the timeline. FireEye even offered to delete the malware automatically. That feature had been switched off. Then nothing happened. Over the following days FireEye flagged multiple versions of the exfiltration code, and Target's Symantec antivirus independently noticed malicious behavior on the same server, as the U.S. Senate Commerce Committee's "Kill Chain" analysis later documented. The warnings sat unanswered while the attackers pulled roughly 40 million payment card numbers and personal data on as many as 110 million people out of the network. The breach was finally discovered when the Department of Justice called Target, not when Target's own alarms were heeded. The cleanup eventually cost the company more than $200 million.
The obvious lesson is that someone screwed up. The more useful lesson is that Target's failure was not an anomaly. It was the predictable output of a system that produces far more warnings than any human team can act on, and the reason has less to do with negligence than with arithmetic.
What alert fatigue actually is
A security operations center, or SOC, is the room, sometimes physical, sometimes just a shared set of dashboards, where analysts monitor an organization's networks for signs of attack. Their raw material is the alert: an automated flag raised by a firewall, an antivirus engine, an intrusion detection system, or a SIEM (security information and event management platform, the tool that aggregates logs from everything else and applies detection rules). Alert fatigue is what happens when the volume of those flags outstrips the capacity to examine them, and analysts begin to tune out, delay, or dismiss alerts, including the ones that matter. It is a close cousin of the phenomenon hospitals know well, where nurses stop hearing monitor alarms because the alarms almost never mean anything. The numbers behind the fatigue are not subtle. A 2026 study by Omdia, commissioned by Microsoft and based on a survey of 300 SOC professionals at organizations with 750 or more employees, found that 46% of all alerts turn out to be false positives, and 42% of alerts go uninvestigated entirely. Analysts in that study worked across an average of 10.9 separate consoles, and two thirds of SOCs reported losing a fifth of their week just to stitching data together across tools. Vendor surveys put the daily flood higher still: Prophet Security's 2025 report, based on 282 security leaders, found analysts handling between 1,000 and 5,000 alerts per shift. Treat the vendor figures with some caution, because the companies publishing them sell tools that promise to fix the problem. But the direction is consistent across independent and commercial sources alike, and it points the same way: most alerts are noise, and a large fraction are never looked at.
The math nobody wants to do
Here is the part that makes alert fatigue a structural problem rather than a staffing one. Even a genuinely excellent detector, one that would impress you on any lab benchmark, produces mostly false alarms when it is pointed at a real network. The reason is a piece of probability called the base rate fallacy. The base rate is simply how common something is to begin with. Real attacks, measured against the total volume of ordinary network events, are extraordinarily rare. That rarity does something counterintuitive to the meaning of an alert. Work a concrete example. Imagine a network that generates one million security-relevant events in a day, and suppose ten of those are genuinely malicious. That is a base rate of 0.001%. Now deploy a very good detector: it correctly flags 99% of real attacks (so it catches roughly 9.9 of the 10) and it has a false positive rate of just 1%, meaning it wrongly flags 1% of benign events. One percent of 999,990 benign events is 9,999 false alarms. So the analyst's queue holds about 10,000 alerts, of which 10 are real. The chance that any given alert is a true attack is roughly one in a thousand. That is not a broken detector. A 99% catch rate and a 1% error rate would be a strong result almost anywhere else. The rarity of the target swamps it. To get even a coin-flip chance that an alert means something, the false positive rate would have to fall to around 0.001%, a hundred times better, which no general-purpose detector achieves.
This is not a new insight. In 2000, the Swedish researcher Stefan Axelsson laid it out formally in a paper titled "The Base-Rate Fallacy and the Difficulty of Intrusion Detection", published in ACM Transactions on Information and System Security. Assuming a base rate of roughly one intrusion per million audit records, Axelsson showed that to make an alarm even modestly trustworthy, an intrusion detection system needs a false alarm rate on the order of one in 100,000. He concluded that the false alarm rate, not the detection rate, is the true factor limiting intrusion detection. A 2022 review revisiting his argument found the core reasoning intact more than two decades later, while noting that real base rates vary enormously by environment, which changes the specific numbers without rescuing the principle. The uncomfortable implication: you cannot buy your way out of this with a better sensor alone. As long as attacks are rare relative to ordinary activity, precise detection is a losing battle against the sheer weight of benign events. This is the single most common misconception about SOC tooling, the belief that a smarter detector would end the false alarms. It would not. It would move the numbers a little.
The false positive tax
If most alerts are noise, someone still has to prove that each one is noise, and that proof is expensive. This is the hidden tax that alert fatigue levies on a SOC. In Microsoft Defender environments that had never been tuned, the Omdia research found that roughly 85% of alerts were false positives or low-value noise, and analysts in those environments spent up to six hours of an eight-hour shift triaging alerts that never needed a second look. Other surveys land in the same territory, with Devo's SOC Performance Report putting false positives around 53% and some environments reporting as high as 80%. Tuning helps. Analysts write suppression rules, adjust thresholds, and whitelist known-good behavior to cut the noise. But tuning has two dangers that pull in opposite directions. Tune too little and the flood continues. Tune too aggressively and you start suppressing the signal along with the noise, which is close to what happened at Target: the alert existed, but it was one flag in an environment noisy enough that a real one did not stand out. The Senate report noted that Target's team saw the FireEye warnings and judged them not worth escalating, which is exactly the failure mode fatigue produces. Not blindness, but a lowered threshold for caring. There is a compounding cost, too. When breaches do happen, they often take a long time to surface. Verizon's 2025 Data Breach Investigations Report found that the share of breaches involving a third party had doubled to 30%, and that leaked credentials committed to code repositories took a median of 94 days to remediate, leaving a long window in which the relevant alerts, if they fired at all, competed for attention with everything else.
The people in the chair
Behind the percentages are people, and the human toll is where alert fatigue stops being an abstraction. When roughly half your working day is spent confirming that alarms mean nothing, the work becomes both exhausting and demoralizing.
Surveys consistently find burnout running above 70% among SOC analysts, with reporting compiled by Wiz citing figures around 71% who attribute it directly to alert fatigue, and the 2025 Pulse of the AI SOC report ranking alert fatigue (76%) and analyst burnout (73%) as the top two operational concerns. Tenure is short and shrinking; some SOCs cycle through analysts in under 18 months. Gartner has flagged cybersecurity burnout as an industry-level trend rather than an edge case. This creates a vicious loop. Fatigue drives turnover, turnover thins the team, a thinner team faces the same alert volume with fewer hands, and the backlog of uninvestigated alerts grows, which is precisely the condition under which a real one slips through. The 42% of alerts that go uninvestigated are not a statistic about laziness. They are what happens when finite human attention meets an effectively infinite queue. It is worth naming the incentive problem underneath. A false negative, a missed attack, can end a career and make headlines. A false positive costs only a few minutes. So detection vendors and rule authors are pushed, rationally, toward flagging more rather than less, because the cost of a missed threat is borne loudly and the cost of an extra alert is borne quietly by the analyst in the chair. Every conservative tuning decision, multiplied across thousands of rules, is what fills the queue.
Can machines clear the backlog?
The obvious response to a volume problem is automation, and the current wave of it is built on large language models. So-called AI SOC agents promise to do the triage that exhausts human analysts: read an alert, gather the surrounding context, decide whether it is a false positive, and either close it or escalate with a written explanation. The pitch is compelling because it targets exactly the right layer. If most of the work is confirming that noise is noise, and if that confirmation is mechanical, then a machine that does it tirelessly could hand analysts back their day. Vendors report dramatic reductions, with claims of cutting false positives by 70% to 90%, though these figures are self-reported and, as far as I can find, not independently audited. The independent read is more sober. Gartner placed AI SOC agents at the "Peak of Inflated Expectations" on its 2026 Hype Cycle, with actual market penetration between 1% and 5%, and warned repeatedly about "AI washing," the relabeling of ordinary automation as intelligence. Gartner's own projection, as reported by Help Net Security, is that around 70% of large SOCs will pilot these agents by 2028 but only about 15% will see measurable improvement without disciplined evaluation. There is a deeper reason for caution, and it is the base rate fallacy again, one level up. An AI triage agent is itself a classifier making a call under the same brutal arithmetic. If it is 99% accurate at dismissing false positives, then across thousands of alerts a day it will still confidently close some real attacks, and it will do so faster and at greater scale than any tired human. The automation does not repeal the math. It changes who is subject to it, and it raises the stakes on the errors, because a machine that auto-closes a genuine alert has recreated the Target failure without anyone in Bangalore even seeing the red light. This is why the more careful vendors and Gartner alike insist that agents handle enrichment and recommendation while humans keep containment authority and the final escalation call.
What to watch
The quiet truth of alert fatigue is that it is not primarily a technology failure or a discipline failure. It is a consequence of trying to find rare events in an ocean of ordinary ones, and no sensor, human or machine, escapes the probability that governs that search. The Target breach happened not because the alarm failed but because it succeeded, in an environment where success looked exactly like the thousands of daily false alarms around it. The interesting question for the next few years is whether automation changes the shape of the problem or just relocates it. If AI agents genuinely absorb tier-one triage, the measure of success will not be how many alerts they close but how many real attacks they close by mistake, a number vendors have every incentive not to publish. Watch for whether that figure ever becomes something buyers can independently verify. Watch, too, for a subtler shift: as machines take over the confirming-noise-is-noise work, the human analysts who remain will spend their days almost exclusively on ambiguous, escalated, genuinely hard cases, with none of the easy closures that once gave a shift its rhythm. That may be better work. It may also be a faster road to burnout. Either way, the alert that no one answers will not disappear. It will just be answered, or not, by something new.
Sources
- BankInfoSecurity, "Did Target Ignore Security Warning?", 2014
- U.S. Senate Committee on Commerce, Science, and Transportation, "A 'Kill Chain' Analysis of the 2013 Target Data Breach", 2014
- Microsoft Security Blog / Omdia, "Unify now or pay later: New research exposes the operational cost of a fragmented SOC" (State of the SOC 2026), 2026
- Prophet Security, "Alert Fatigue in Cybersecurity: Why Tuning Isn't Enough Anymore", 2025
- Stefan Axelsson, "The Base-Rate Fallacy and the Difficulty of Intrusion Detection", ACM Transactions on Information and System Security, 2000
- arXiv, "Base-Rate Fallacy Redux and a Deep Dive Review in Cybersecurity", 2022
- Secure.com, "What Percentage of SOC Alerts Are False Positives (And How Many Actually Need a Human)?" (citing Devo SOC Performance Report), 2025
- Verizon, "2025 Data Breach Investigations Report, Executive Summary", 2025
- Wiz, "SOC Analyst Burnout: Causes, Signs & Fixes", 2025
- Netenrich, "Is SOC Analyst Burnout Putting Your Org at Risk?" (citing Pulse of the AI SOC report), 2025
- Help Net Security, "Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results", 2026
- Cynet, "Gartner Hype Cycle 2025: Cybersecurity AI Assistants and AI SOC Agents", 2025