TL;DR: A four-analyst SOC can face 300 to 400 high-fidelity alerts a week, with 90% resolving benign and about 40% of alerts in a 300-practitioner survey never investigated, showing that tuning cannot close the investigation gap, according to Prophet. The structural issue is investigation capacity, not alert volume, so SOCs need queue-design, enrichment, and decisioning changes rather than more rule trimming.
NHIMG editorial — based on content published by Prophet: Alert Fatigue in Cybersecurity: Why Tuning Isn’t Enough Anymore
By the numbers:
- The State of AI in Security Operations survey of nearly 300 CISOs, SOC leaders, and practitioners put the median team at about 960 alerts per day.
Questions worth separating out
Q: What breaks when a SOC relies on tuning instead of investigation capacity?
A: The SOC starts closing alerts on pattern recognition instead of evidence, which increases the chance of missed lateral movement, identity abuse, and delayed containment.
Q: Why do identity signals matter so much in alert triage?
A: Identity signals often determine whether an alert is ordinary or dangerous.
Q: How do security teams know if alert fatigue is improving?
A: They should look for shorter queues only if investigation quality stays high.
Practitioner guidance
- Baseline investigation capacity and queue quality Capture one week of alert dwell time, reopen rate, suppression ratio, context-gap rate, and time-to-decision before changing tooling or tuning rules.
- Correlate identity context before triage Feed alerting with IAM, PAM, and NHI signals so analysts see privilege scope, recent access change, and account history alongside the alert.
- Define a visible investigation-debt metric Track alerts that were closed without full evidence review and review that metric in operational meetings alongside backlog and escalation rate.
What's in the full article
Prophet's full analysis covers the operational detail this post intentionally leaves for the source:
- Baseline alert triage metrics and queue-design examples for measuring investigation debt
- Practical guidance on prioritising alerts by evidence quality, identity risk, and asset criticality
- Examples of evidence packaging and correlation workflows that reduce analyst context switching
- Discussion of AI SOC analyst behaviour against live alert volume rather than theoretical throughput
👉 Read Prophet's analysis of why alert fatigue is a capacity problem →
Alert fatigue in the SOC: why tuning alone is falling short?
Explore further
Investigation capacity is the real control plane of the SOC. Alert fatigue is not a morale issue first and not a tuning issue first. It is a governance problem in which the organisation has more alerts than it can properly investigate. That changes the meaning of detection quality, because a detection that cannot be fully reviewed is only partially operationalised. Practitioners should treat throughput as a control objective, not a staffing side effect.
A question worth separating out:
Q: Who is accountable when alerts are closed without full review?
A: Accountability sits with the security operating model, not just individual analysts. If the organisation accepts closure without investigation quality controls, then leadership owns the risk of missed incidents. SOC managers, detection engineering, and governance teams should define the standard for what counts as a complete review.
👉 Read our full editorial: Alert fatigue is a capacity problem, not a tuning problem