Security Monitoring Gaps
Alert Fatigue
Alert volume so high that analysts stop triaging — real threats pass unreviewed.
What it is
Default SIEM rule packs generate high false positive rates when applied to environments they were not tuned for. Analysts under volume pressure triage for speed, not accuracy. Rules that fire hundreds of times daily with 0% true positive rate are eventually muted or ignored entirely. Alert fatigue is the primary operational reason why organisations with monitoring tools still miss attacks in progress.
Attack techniques
- Uncalibrated detection rules
- Excessive low-fidelity alerts from default rulesets
- No alert quality metrics (TP/FP ratio)
- Missing analyst runbooks causing slow triage
Business impact
An organisation can be fully breached while producing thousands of alerts per day — none of which were the relevant ones. Alert fatigue converts monitoring investment into noise with no security value.