Alert Fatigue in Security Operations Centres¶
Tariq, S., Baruwal Chhetri, M., Nepal, S., & Paris, C. (2025). Alert Fatigue in Security Operations Centres: Research Challenges and Opportunities. ACM Computing Surveys, 57(9).
Cited by¶
2 citations across 2 artifacts.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Habituation to Repeated Signal
- Cybersecurity SOCs ("alert fatigue"): SIEM and EDR alerts arrive in tens of thousands per analyst per shift, so the rational posture becomes triage by salience proxy, missing genuine attacks.
This sourcePeer-reviewed survey documenting SOC analysts overwhelmed by thousands of mostly-false-positive SIEM/EDR alerts per shift, causing desensitization and missed genuine threats.
- Cybersecurity SOCs ("alert fatigue"): SIEM and EDR alerts arrive in tens of thousands per analyst per shift, so the rational posture becomes triage by salience proxy, missing genuine attacks.
- Operational Overextension
- In cybersecurity, a defender extends monitoring across an expanding attack surface faster than analyst headcount and tooling can keep up, and a routine incident finds the perimeter under-monitored.
This sourceDocuments how SOC alert volume across an expanding attack surface outgrows analyst headcount, creating coverage gaps and missed genuine threats — the cybersecurity instance of frontier outrunning backbone.
- In cybersecurity, a defender extends monitoring across an expanding attack surface faster than analyst headcount and tooling can keep up, and a routine incident finds the perimeter under-monitored.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:c0e1056013a8 · see in the full table