TL;DR: Analysis of more than 25 million security alerts found that nearly 1% of confirmed incidents started as low-severity or informational alerts, rising to nearly 2% on endpoints, which means a typical 450,000-alert environment could miss about 50 real threats a year, according to Intezer. The finding shows that severity-based triage is now a governance failure, not just an operational inconvenience.
NHIMG editorial — based on content published by Intezer: Alert fatigue is costing you: Why your SOC misses 1% of real threats
By the numbers:
- nearly 1% of confirmed incidents originated from alerts initially labeled as low-severity or informational
- On endpoints, that figure climbed to nearly 2%
Questions worth separating out
Q: What breaks when SOC teams ignore low-severity alerts by default?
A: Teams create a structural blind spot where real compromises can sit inside routine telemetry until attackers have already expanded access.
Q: Why do identity signals matter so much in alert triage?
A: Identity signals often determine whether an alert is ordinary or dangerous.
Q: How do security teams know whether contextual prioritisation is working?
A: Look for shorter remediation times on externally exposed and credential-bearing systems, fewer high-risk findings waiting across multiple cycles, and a clear drop in unowned critical items.
Practitioner guidance
- Reset low-severity handling rules Require manual or automated validation for a defined subset of low-severity and informational alerts, especially where identity, endpoint, or cloud activity intersects.
- Tie mitigation status to live-state checks Confirm that an alert marked mitigated has actually removed malicious code, active sessions, or abused credentials from the environment.
- Prioritise identity-led investigation paths Escalate alerts involving tokens, service accounts, OAuth connections, and suspicious logins even when their severity is low.
What's in the full report
Intezer's full report covers the operational detail this post intentionally leaves for the source:
- Forensic breakdowns of how low-severity and informational alerts mapped to confirmed incidents across endpoint, cloud, identity, and phishing telemetry
- Endpoint analysis showing where tools reported mitigation while live forensic scans still found active compromise
- Phishing and cloud posture examples that show how attackers blend into trusted services and legacy misconfigurations
- The report's summary data and webinar framing for CISOs and SOC leaders who need the underlying alert set and methodology
👉 Read Intezer's 2026 AI SOC report for CISOs on missed threats and alert fatigue →
Low-severity alerts are still hiding real threats. Are your controls keeping up?
Explore further
Severity triage is now a governance control, not just a SOC workflow choice. Once organisations decide that low-severity alerts can be dismissed by default, they are making a policy decision about acceptable compromise. The data in this article shows that decision has measurable loss. For identity programmes, that matters because compromised sessions, API keys, and service accounts often arrive as weak signals before they become incidents. Practitioners should treat severity handling as a control boundary, not a convenience layer.
A question worth separating out:
Q: Who is accountable when a SOC misses a real threat hidden in low-severity noise?
A: Accountability usually sits with the security leadership that defines triage policy, the SOC owners who implement it, and the control owners whose telemetry feeds it. In practice, the question is not whether a tool missed the alert, but whether the operating model allowed evidence to be discarded before investigation.
👉 Read our full editorial: Alert fatigue is letting real threats hide in low-severity noise