By Simon Phillips, CTO, CybaVerse
Alert fatigue is an issue that has plagued Security Operations Centres for years.
As organisations’ digital estates grow, there is more architecture to secure and more architecture for threat actors to attack, which has ultimately led to more alerts.
Today, on average a SOC will face thousands of alerts every day, each of which could indicate a potential threat. Each alert must therefore be analysed and investigated before appropriate action can be taken.
However, ask any SOC analyst and they will tell you the majority of these alerts are benign or false positives.
Yet, analysts will still spend hours investigating activity that ultimately poses little or no risk, hoping to identify the small number of genuine threats hidden amongst the noise.
Given the volume they face, and the possibility of missing something before it’s too late, it’s a noisy, high-stress environment that often leads to burnout and fatigue.
To tackle these issues, many SOCs today are turning to Artificial Intelligence (AI) to support the management of alerts.
In this scenario, the first-line analyst is replaced by an agent that reviews the incident to determine whether it’s malicious and if further action is required. The analyst must then review the conclusion reached by the agent to ensure it is accurate, but they don’t conduct the initial investigations themselves, which reduces the volume of alerts they have to investigate every day.
However, even despite these improvements, is there another way that could reduce the noise even further?
If organisations are still generating huge numbers of unnecessary alerts, have they actually solved the underlying problem, or simply moved it further downstream?
Moving AI upstream
Instead of asking AI to investigate incidents after they have been created, some organisations are using the technology much earlier in the detection process.
Rather than having AI decide whether an alert is malicious, in this scenario it’s used to help build better detection logic and more effective workflows before alerts ever reach an analyst.
For instance, in a phishing attack when an employee reports an email as suspicious, many security platforms immediately generate an incident that someone must investigate.
Traditionally, either a human analyst or an AI assistant would then collect additional context, checking whether links have been clicked, whether anyone else received the email, or whether similar activity appeared elsewhere in the environment.
If these types of checks are incorporated into the detection process, and the answers to the questions are no, then an incident would never need to be created in the first place.
The AI would determine that there was no wider threat, meaning the alert could be filtered out before it ended up in the SOC ticket queue.
The result is a faster, more efficient SOC, with far fewer unnecessary alerts reaching analysts.
From a customer perspective, this can also reduce the costs of working with an outsourced SOC partner.
Many AI-powered investigation platforms price their services according to the number of alerts they process, so reducing unnecessary alerts before they reach the investigation stage can improve efficiency while also helping organisations control operational costs.
Improving security through engineering
Another benefit of moving AI further upstream is that it limits access to sensitive customer data.
Many AI-driven investigation platforms analyse real customer logs and incident data to determine whether activity is malicious. While providers implement safeguards, some organisations are uncomfortable with sensitive operational data being processed by external AI systems, particularly where regulatory or contractual obligations apply.
Using AI during detection engineering changes this process. The AI is used to create the logic that identifies threats, not to inspect live customer data.
Once the detection rules have been verified, they can be applied consistently across customer environments without repeatedly sending operational data through AI models.
Solving the cause, not the symptom
The cyber security industry has become very good at handling alert fatigue, but not so good at preventing it. Is it time a different approach was adopted?
If security teams continue generating thousands of low-value alerts every day, replacing analysts with AI may improve efficiency, but it won’t address why the alerts exist in the first place.
As AI becomes more deeply embedded within security operations, organisations should consider where it delivers the greatest value. In many cases, the answer may not be at the point where analysts investigate incidents, but much earlier, where better detection engineering prevents unnecessary incidents from being created at all.
By reducing false positives at the source, this allows analysts to spend more time on genuine threats, while improving consistency, cutting costs and helping organisations make better use of both their technology and their people.

