Analysts leave when they cannot do meaningful work efficiently. Constant false positives, weak tooling, and no way to fix bad inputs create friction that erodes motivation. Security work is inherently demanding, so retention depends on reducing unnecessary red tape and giving analysts a path to improve detection quality instead of repeatedly fighting the same problems.
Why frustration makes analysts want out
Analysts usually do not leave because the work is hard in the abstract. They leave when the job stops letting them solve problems effectively. If every shift is consumed by noisy alerts, incomplete context, and manual triage, the role turns into repetitive interruption rather than investigation. That creates the sense that effort is being wasted instead of converted into better detection.
The practical issue is control. When analysts cannot tune bad detections, remove low-value alerts, or influence upstream telemetry quality, they are forced into a reactive loop. That is exhausting because the team sees the same defects every day but lacks authority to improve the system that produces them.
A related frustration is that investigation work depends on fast, trustworthy evidence. If tools are slow, data is fragmented, or enrichment is unreliable, even a competent analyst spends more time assembling basic facts than reasoning about an event. The result is cognitive drag: the analyst is doing process repair, not security analysis.
What actually drives attrition in detection and investigation teams
Retention problems often start with a mismatch between effort and impact. Analysts want to close incidents, reduce ambiguity, and improve signal quality; instead, they are often measured on volume, queue clearance, or response speed alone. When success is defined by throughput but the environment keeps generating poor inputs, the work feels endless and unrewarding.
Frustration also grows when investigation findings do not change anything. If analysts repeatedly identify the same root causes, but engineering, platform, or tuning changes never follow, they learn that careful work has no downstream effect. Over time, that destroys ownership and makes the role feel disposable.
Tooling matters here, but not as a cosmetic issue. Good detection engineering supports the analyst by preserving context, reducing false positives, and making alert quality improvable over time. SANS Security Resources is useful here because it reflects the practical reality that detection and incident work depends on operational craft, not just policy.
Why fixing the workflow matters more than asking people to “tolerate” it
Analyst frustration is usually a systems problem, not a resilience problem in the personality sense. Teams can normalize friction for a while, but chronic friction lowers concentration, slows learning, and makes good people avoid deep investigation work. That is especially true when every improvement request is delayed by process or ownership ambiguity.
Security leaders should also recognize that inefficient detection work degrades the quality of the program itself. Analysts who spend most of their time on low-value alerts have less time for hypothesis testing, threat hunting, tuning, and feedback to control owners. In practice, the organisation loses both retention and detection quality at the same time.
That is why mature defensive programs focus on reducing noise, shortening investigation paths, and creating a real feedback loop from analyst findings back into detections, logging, and prevention. MITRE D3FEND is relevant because it helps connect defensive actions to specific adversary behaviors, which is exactly the kind of structure that improves investigation efficiency and makes tuning more meaningful. MITRE ATT&CK Enterprise Matrix also helps teams anchor detections to realistic adversary techniques instead of maintaining noisy rules that nobody trusts.
Risk and Threat Considerations
Frustration in detection work is not just a morale issue. It can create real security exposure because analysts who are overloaded, under-supported, or burned out are less likely to notice weak signals, investigate carefully, or keep pace with alert tuning. Over time, the organisation can become slower at spotting genuine compromise and more dependent on heroics.
Failure mechanism: Excessive false positives, poor tooling, and no mechanism for fixing upstream causes create a high-friction operating loop. Analysts spend their time clearing noise instead of improving detections, which leads to disengagement, errors, and eventual turnover.
Impact: The team loses experienced investigators, detection quality stagnates, and attackers gain a better chance of hiding in the noise. The same conditions that drive attrition also weaken the organisation’s ability to learn from incidents and improve defensibility.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | Enterprise Matrix | Explains adversary techniques behind detections and investigations. |
| Recommendation — Map detections to ATT&CK techniques and remove noisy coverage gaps. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Better logging and review reduce noisy, hard-to-investigate alerts. |
| Recommendation — Improve log quality and review workflows to cut investigation friction. | ||
| NIST CSF 2.0 | DE.CM-01 — Assets are monitored to find anomalies and events | Analyst frustration often stems from ineffective continuous monitoring. |
| DE.AE-02 — Detected events are analyzed to understand attack targets and methods | Investigation quality depends on usable analysis, context, and triage. | |
| Recommendation — Tune monitoring so alerts are actionable and operationally sustainable. Strengthen event analysis workflows so analysts can investigate efficiently. | ||
Practitioner Guidance
What to prioritise: Fix the highest-friction alert classes first, especially the ones that create repeated manual work without improving risk coverage. If an alert cannot be tuned, enriched, or retired, it will eventually become a retention problem as well as an operational one.
What to verify: Analysts need a visible path from finding a problem to changing the detection, logging, or enrichment behind it. If they can only close cases but cannot influence quality, the organisation is training them to accept noise rather than reduce it.
What good looks like: Good teams do not eliminate all alerts. They keep the queue small enough that analysts can think, confirm that the most important detections are explainable, and make recurring investigation pain a signal for engineering change rather than a permanent condition.
Practitioner takeaway: Retention improves when analysts can do meaningful security work end to end, not when they are simply asked to absorb more frustration.
Related resources from NHI Mgmt Group
- How should security teams operationalise detection engineering when analysts are already buried in triage work?
- Why do Microsoft security stacks still leave analysts overloaded even when detection coverage is strong?
- What are the signs that a security search language is becoming too complex for day-to-day investigation work?
- What happens when analysts are expected to do too much manual work in security operations?