Incident Response

Alert Fatigue Statistics: What the Numbers Mean

Use alert fatigue statistics with a visible source, sample, date, and denominator, then convert them into local capacity, yield, queue, and coverage decisions.

Alex Gibson, Co-Founder and Principal at Artemes AI
Alex Gibson
Co-Founder, Principal
Aug 4, 2026 10 min read
Alert fatigue statistics source ledger comparing survey responses, field observations, research benchmarks, and local queue capacity math

Alert fatigue statistics do not prove that every SOC is drowning. They prove that many teams measure alert pressure with incompatible definitions, then borrow an industry percentage instead of calculating their own work.

The problem is not a shortage of alarming numbers. It is a shortage of denominators. “Too many alerts,” “false positive rate,” “unreviewed,” and “burned out” describe different conditions. Put them in one slide and the result looks precise while hiding the operating decision.

Use external research to challenge assumptions and win attention. Use local queue data to set staffing, tuning, routing, and coverage decisions. A benchmark cannot tell you which rule consumed Tuesday afternoon.

Infographic

Read the denominator before the headline

Survey responses, field observations, and lab benchmarks answer different questions about alert fatigue.

Source ledger for interpreting alert fatigue statisticsFour source cards show a Splunk respondent survey, a SANS leader and practitioner survey, an NCSC field observation, and a 2026 research benchmark. Each card names what the number supports and what it cannot prove. A bottom panel converts local alert count and review time into weekly capacity demand.ONE PERCENTAGE CAN HIDE FOUR DIFFERENT DENOMINATORSSPLUNK 202559% report too many alertsself reported operating pressurerecord date, sample, label, and scopeSANS 2026444 practitioners, 69 leaderstwo views of the same SOCrecord date, sample, label, and scopeNCSC 2026up to 99% in observed SOCsfield example, not an averagerecord date, sample, label, and scopePACT 202643% and 21% burden cutstwo benchmark data setsrecord date, sample, label, and scopeLOCAL CAPACITY TESTalerts × active review minutes = weekly demandCompare demand with staffed minutes, useful actions, unresolved work, and attack replay.

What do alert fatigue statistics actually prove?

A credible statistic proves only what its source, sample, question, labels, and date allow. A respondent survey describes perception. A field observation shows what happened in specific environments. A lab benchmark compares methods under defined data and thresholds. Ticket data describes your workflow, assuming the labels are sound.

Treat each number as an instrument. Before citing it, record who produced it, when data was gathered, how many people or events were included, which population they represent, and the exact denominator. If the source does not disclose one of those fields, say so.

This is the gap in many ranking pages for alert fatigue statistics. They collect large percentages from unrelated surveys but do not reconcile definitions or convert the figures into a capacity decision. A useful article needs a source ledger and a local worksheet, not a longer wall of fear.

Which alert fatigue numbers should never be combined?

Do not average a respondent share with an alert share. “Fifty percent of practitioners report too many alerts” cannot be blended with “fifty percent of alerts were closed as false.” One describes people who selected a survey answer. The other describes ticket labels. They have different units and different ways to be wrong.

Keep raw events separate from alerts, and alerts separate from cases. One attack can produce 40 events, eight alerts, and one correlated case. A product that groups the eight alerts may report an 87.5 percent reduction even though the analyst still makes one decision. That may be useful, but it is correlation performance, not proof that the underlying detections became more accurate.

Do not compare a laboratory false positive rate with a production closure rate unless the labels, thresholds, and benign population match. Lab data is usually cleaner. Production has service accounts, deployment tools, broken parsers, temporary exceptions, and incomplete investigations. A rate can rise because reality became messier or because the team finally stopped calling unresolved work false.

Burnout percentages belong in their own lane as well. They describe people, not detector accuracy. Connect them through local workload data, schedule stability, after shift demand, and repeated work. Correlation may support an operating hypothesis. It does not prove that one noisy rule caused a health outcome.

What did the 2025 Splunk security study find?

Splunk's State of Security research released May 20, 2025 surveyed 2,058 security leaders from October through December 2024. It says 59 percent of respondents had too many alerts and 55 percent dealt with too many false positives. Forty six percent said they spent more time maintaining tools than defending the organization. Fifty seven percent reported losing investigation time because of gaps in their data management strategy.

Read those as respondent shares, not alert shares. The study does not say that 55 percent of all alerts were false. It says 55 percent of respondents reported dealing with too many false positives. That distinction matters when a board asks whether half of the queue is wrong.

The combination is more useful than any single value. Alert count, false alerts, tool maintenance, and data gaps all consume the same limited operator time. A purchase that cuts one queue but adds heavy integration work can move the burden rather than remove it.

What does the 2026 SANS SOC Survey add?

SANS published its 2026 SOC Survey release on June 11, 2026. It reports 444 responses from security operations practitioners and a parallel survey of 69 CISOs and senior executives. Among the leaders, 24 percent chose lack of visibility across the enterprise as the largest barrier to effective security operations.

That split sample exposes a management problem too. Fifty nine percent of leaders said management paid close attention to SOC hiring and retention needs, while 32 percent of practitioners agreed. That 27 percentage point gap had persisted each year the question was asked.

Alert fatigue is not only a rule quality problem. It can be a visibility, ownership, and funding problem viewed through the queue. Leaders who believe staffing receives enough attention may read a growing backlog as analyst performance. Practitioners may see the same backlog as evidence that admitted work exceeds capacity.

Why is the 99 percent false positive figure easy to misuse?

In guidance published April 27, 2026, the UK National Cyber Security Centre described how poor metrics can harm a SOC. The author reported observing ticket focused SOCs where as many as 99 percent of tickets were triaged as false positives.

That is not a measured industry average. It is a field observation about some SOCs and the incentive created by ticket metrics. The same guidance explains that analysts measured on closure count or speed have a reason to find a quick false positive verdict rather than investigate.

The number is still valuable. It shows the outer edge of a broken queue and warns against treating closure labels as objective truth. If “false positive” includes duplicates, approved activity, low value events, and unresolved work, the rate measures taxonomy failure as much as detection failure.

Define false positives and false negatives before building a trend. If the label does not point to a distinct fix, it should not be the headline metric.

What recent alert fatigue research changes the discussion?

A May 21, 2026 preprint introduced PACT, a method for reducing alert burden in streams where malicious events are rare. In tests on two public benchmark data sets, the PACT alert fatigue study reduced benign normalized false positive burden by 43 percent and 21 percent compared with a frozen baseline. It also used 3.8 times and 5.2 times fewer analyst queries than periodic random updating.

The tradeoff is the important development. Under its free running triggers, the method lost about ten percentage points of recall for positive windows. A threshold only baseline pushed false positives lower but cut recall on one data set by 55 percentage points. Lower burden was possible. Lower burden with preserved coverage was harder.

This is benchmark research, not a production SOC outcome, and the paper is a preprint. Still, it shows why aggregate accuracy is a weak operating measure. Teams need false alert burden, analyst query demand, and recall on rare attacks beside one another.

How do you convert alert statistics into capacity math?

Start with admitted alerts, not raw events. Suppose the queue receives 3,000 alerts a week and each requires seven active minutes. That is 21,000 minutes, or 350 hours. Eight analysts at 40 hours provide 320 gross hours before meetings, training, leave, incident response, and detection work. The queue is overloaded before the week starts.

A claim that automation removes 40 percent of alerts would cut this example to 210 review hours if review time is evenly distributed. It rarely is. The removed alerts may be cheap duplicates while the remaining cases take longer. Measure minutes by rule and verdict. Then calculate useful action yield and unresolved work.

Five analysts times six hours a week of repeated triage is 30 hours. At an illustrative loaded labor cost of $90 an hour, that is $2,700 a week and $140,400 across 52 weeks. Replace the rate with your finance number. Keep the hours even if finance will not supply one. Time is the first budget the queue consumes.

Our false positive cost model covers the broader labor and delay calculation. The key here is to separate sourced industry data from local assumptions so nobody mistakes an example for a customer result.

Which local metrics reveal alert fatigue?

Build a weekly scorecard by rule, data source, and queue lane. One blended SOC average can hide the detector that consumes half the week. Track a small set of measures that lead to a decision.

  • Admitted work: alerts and cases that entered a human queue, including unresolved items.
  • Active review minutes: hands on investigation time, separate from calendar age.
  • Useful action yield: reviews that changed containment, scope, a control, a rule, or a risk decision.
  • Verdict mix: false alert, benign true, duplicate, low value, useful, and unresolved shares.
  • Queue age: median and oldest age by urgency, not one average across all work.
  • Coverage evidence: attack replay pass rate, data source health, and sampled suppression results.
  • Ownership: the costly rules with named owners, next changes, and review dates.

Pair this scorecard with security signal to noise measurement. Alert fatigue is the operating condition. Yield, cost, queue age, and coverage are the instruments that show where to intervene.

How should you survey analysts without creating another weak statistic?

Ask about observable work. How many times did you recheck the same behavior? Which evidence was missing at first touch? How often did the queue interrupt deeper work? How many cases did you leave unresolved at shift end? Which rule would you stop or reroute tomorrow, and what attack coverage must remain?

Run the survey beside ticket and schedule data. An analyst may report manageable volume while after shift work rises. Another may report overload because five difficult identity cases consumed a day even though count fell. Neither response is wrong. The local record explains the mechanism.

Artemes AI uses deep endpoint context with AI driven analysis to help reviewers assemble evidence around a finding. That may reduce repeated lookup work. The metric should still count human review time, unresolved evidence, corrections, and coverage. A faster draft is useful only if the final decision improves.

Frequently asked questions

What percentage of security alerts are false positives?

There is no defensible universal percentage. Published figures use different tools, populations, labels, and denominators. Calculate the rate locally by rule and keep benign true, duplicate, low value, and unresolved cases separate.

How many alerts can one SOC analyst handle?

Count active minutes, not tickets. A grouped case may take five minutes while an identity investigation takes two hours. Available capacity also needs deductions for incidents, meetings, training, tuning, and recovery.

Are self reported alert fatigue surveys useful?

Yes, for understanding perceived pressure and gaps across a sample. They do not measure your alert mix or prove a causal link. Use them to frame questions, then test those questions against local work data.

Which alert fatigue statistic should a CISO report?

Report local admitted work, useful action yield, active review minutes, unresolved age, and tested coverage together. Add an external benchmark only with its source date, sample, and definition visible.

Executive takeaway

Stop shopping for the biggest alert fatigue percentage. Build a source ledger for every external claim, then calculate local demand as alerts times active review minutes. Break the result down by rule and verdict. Put useful action, unresolved work, queue age, and attack replay beside it. The statistic worth managing is the one that names an owner and changes next week's work.

Artemes AI

Put more evidence behind vulnerability decisions

Artemes AI combines endpoint telemetry, sourced vulnerability intelligence, and review-gated analysis so teams can examine the evidence, missing context, and recommended next step together. We are accepting early-access requests now.

Alex Gibson, Co-Founder and Principal at Artemes AI

Alex Gibson

Co-Founder, Principal

Alex writes about configuration drift, operational security evidence, endpoint telemetry, AI-assisted triage, and the practical work of turning signals into better remediation decisions.

Signal vs. Noise
Incident Response
Blue Team
Found this useful? Share it.

Get articles like this in your inbox.

Security research and occasional Artemes AI product updates.