Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

MDR alert triage gaps: what security teams are not seeing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Roughly 40% of alerts are never investigated, while about 57% of organisations suppress or tune detections to cut noise, creating a gap between dashboard coverage and alert-level reality, according to Prophet Security. The real governance issue is not visibility alone, but whether investigation, timing, and evidence remain auditable under managed-service triage.

NHIMG editorial — based on content published by Prophet: What Your MDR Isn't Telling You

By the numbers:

  • 57% in recent surveys, ations, around 57% in recent surveys, suppress or tune out detection rules specifically to cut noise.

Questions worth separating out

Q: What breaks when MDR services never fully investigate alerts?

A: When alerts are filtered, auto-closed, or only partially reviewed, the organisation loses timely visibility into real identity and access risks.

Q: Why do identity alerts need stronger handling than other detections?

A: Identity alerts often represent the earliest sign that an attacker has reached a usable account, token, or privileged session.

Q: What should organisations measure to know whether MDR is working?

A: Track validated incident rate, time to containment, false positive reduction, and whether the service is acting on the right identity and endpoint signals.

Practitioner guidance

  • Instrument investigation-completion metrics Track percentage of alerts fully investigated, partially handled, auto-closed, or handed back, and review those metrics by alert class, not just by monthly total.
  • Demand the full evidence chain Require closed-case artefacts that include the queries run, enrichment steps, analyst reasoning, and the decision path for any identity-related alert.
  • Separate identity alerts from generic noise Create distinct escalation rules for identity, privileged access, and OAuth-related detections so they cannot be buried under broad severity tuning.

What's in the full article

Prophet's full article covers the operational detail this post intentionally leaves for the source:

  • The specific alert-level questions the vendor says teams should ask at renewal, including suppression, investigation completion, and per-alert cost.
  • The operational comparison between queue-based MDR handling and AI-driven investigation timing, including the cited latency gap.
  • The discussion of black-box investigation output, including what evidence is typically missing from closed tickets.
  • The source article's explanation of how provider staffing economics shape what gets investigated and what gets deprioritised.

👉 Read Prophet's analysis of what MDR dashboards leave out at the alert level →

MDR alert triage gaps: what security teams are not seeing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Alert-level opacity is now a governance problem, not just an operational inconvenience. Dashboard metrics can show coverage while still concealing which alerts were never fully investigated, downgraded, or handed back without a durable record. That matters because governance depends on decision traceability, especially when identity and access signals are the first signs of compromise. Practitioners should treat investigation completeness as a control outcome, not a reporting artefact.

A question worth separating out:

Q: Who is accountable when outsourced detection decisions miss a real incident?

A: The provider may perform the service, but accountability for risk still sits with the organisation that owns the assets, identities, and compliance obligations. That means teams must define what counts as full investigation, require artefact retention, and ensure the contract supports audit and incident reconstruction.

👉 Read our full editorial: What your MDR dashboard hides about alert-level investigation gaps



   
ReplyQuote
Share: