Key Takeaways
- A 2023 survey of 2,000 security operations analysts reported 4,484 alerts per day per SOC, with 67% left unaddressed.
- The same survey found that analysts spent an average of nearly three hours a day manually triaging alerts and regarded 83% of alerts as false positives.
- A four-year field dataset examined by IBM researchers contained 115 million network alerts, showing that alert labels and benign activity require more nuance than a single false-positive rate.
- Splunk's 2025 survey found that 59% of respondents had too many alerts and 55% dealt with too many false positives.
- Microsoft's controlled study found experienced security professionals using its assistant completed tested tasks 22% faster and with 7% higher accuracy.
Cybersecurity alert triage workload statistics: the short answer
No single alert-volume target fits every security operations center. A small team protecting one cloud application and a global SOC monitoring thousands of endpoints do not have comparable queues. Public studies also use different units: raw events, detections, alerts, cases, incidents, or analyst opinions. Those terms should not be combined as if they describe the same work.
The available evidence still gives security leaders useful bounds. A 2023 Vectra AI survey of 2,000 security operations analysts reported an average of 4,484 alerts per day per SOC. Respondents said their teams could not address 67% of them and spent nearly three hours a day on manual triage. Splunk's 2025 security survey found that 59% of respondents had too many alerts and 55% dealt with too many false positives.
These cybersecurity alert triage workload statistics are best used as comparison points, not staffing standards.
| Workload measure | Published finding | Study scope and caution |
|---|---|---|
| Daily alert volume | 4,484 alerts per SOC | 2023 Vectra AI survey of 2,000 SecOps analysts; self-reported average |
| Alerts not addressed | 67% of daily alerts | Same survey; "not addressed" is not the same as a missed confirmed attack |
| Manual triage time | Nearly 3 hours per analyst day | Same survey; reported time rather than observed time |
| Alerts considered false positives | 83% | Same survey; respondent judgment, not a universal measured rate |
| Respondents with too many alerts | 59% | Splunk State of Security 2025 |
| Respondents dealing with too many false positives | 55% | Splunk State of Security 2025 |
| Cloud alert resolution exceeding five days | 43% | Check Point 2024 Cloud Security Report survey |
| Experienced users completing tested security tasks faster with AI | 22% faster | Microsoft controlled study; vendor tool and bounded task set |
Alert volume and review coverage
The Vectra survey supplies a direct volume benchmark, but it also exposes a denominator problem. If a SOC receives 4,484 alerts a day and does not address 67%, then about 1,480 alerts are addressed and about 3,004 are not. Those figures are calculations from the published percentages, rounded to whole alerts. Vectra did not report them as queue counts.
That arithmetic does not prove the unaddressed group contained 3,004 genuine threats. Correlation, suppression, duplicate removal, severity thresholds, and automated closure can all keep an alert from reaching manual review. A useful workload report therefore needs at least three counts:
- Alerts created by detection tools.
- Alerts promoted to a human review queue.
- Cases or incidents created after correlation and triage.
An older Forrester Consulting study commissioned by Palo Alto Networks found that the average surveyed security operations team received more than 11,000 alerts per day. The study was published in 2020, so it is not a current market average. Its value is comparative: published alert-volume figures can differ by more than twofold because the surveyed populations and alert definitions differ.
IBM researchers provide a stronger view of what sits under those headline counts. Their peer-reviewed USENIX Security 2024 study analyzed 115 million network alerts collected from a real SOC over four years, from 2018 through 2022. The researchers distinguish true attacks, failed attack attempts, and benign triggers. That classification is more informative than treating every nonincident as a simple false positive.
False positives are not one clean category
The 83% figure in Vectra's report is often repeated as a measured false-positive rate. It came from a survey question about alerts that analysts considered false positives and not worth their time. It should not be applied to every SOC queue.
Splunk's 2025 finding is framed differently: 55% of respondents said they dealt with too many false positives. It measures the prevalence of a workload complaint, not the share of alerts that were incorrect. Both findings show operational strain, but they answer different questions.
The IBM field study makes the distinction practical. A benign trigger may be correct according to a detection rule while posing no threat in context. An attack attempt may also be real even when it fails. Closing either alert without opening an incident does not necessarily mean the detector was wrong.
Teams can report cleaner triage statistics by separating:
| Queue outcome | Definition | Why it matters |
|---|---|---|
| Detection error | The rule or model identified activity that did not meet its stated condition | Points to logic or model tuning |
| Benign true detection | The activity matched correctly but was authorized or harmless in context | Points to allowlists, context, or workflow design |
| Failed attack attempt | Malicious activity occurred but did not succeed | May still justify blocking, hunting, or control changes |
| Duplicate or correlated alert | Another alert or case already represents the same activity | Measures tool overlap and correlation quality |
| Confirmed incident | Investigation found an event that requires response | Feeds escalation and response staffing |
One blended false-positive percentage hides which repair will reduce work. Detection errors require different action from duplicate alerts or correctly detected administrator behavior.
How much analyst time goes to triage?
Nearly three hours of manual triage in an eight-hour day equals 37.5% of scheduled time. This is our calculation from Vectra's reported average, not a finding stated by the report. For a five-person team working 250 days a year, the same assumption produces 3,750 annual analyst hours. That is workload math, not a recommendation to remove staff or automate every review.
Manual review includes more than reading an alert title. An analyst may gather endpoint, identity, network, and threat-intelligence context; check whether activity is expected; decide severity; document the decision; and route the case. Tool switching can extend this work. Splunk reported in 2025 that 46% of respondents spent more time maintaining tools than defending their organization, while 57% lost investigation time because of gaps in their data-management strategy.
KPMG's 2024 SOC survey gives another view of the queue problem. Security leaders named identifying genuine threats through better analysis of false positives and false negatives at 27%, limited time and personnel at 22%, and high alert volume at 21% among areas needing improvement. These are shares selecting challenges in KPMG's survey, not percentages of analyst time.
Resolution time also matters. Check Point's 2024 Cloud Security Report states that 43% of respondents reported cloud alert resolution taking more than five days. The survey does not show that analysts actively worked each alert for five days. Elapsed resolution time includes queue wait, handoffs, evidence gathering, approvals, and remediation.
Escalation rates need a stable denominator
Published cross-industry research does not establish a universal percentage of security alerts that should escalate. The word "escalation" can mean a transfer from Tier 1 to Tier 2, a case sent to incident response, a request for business-owner context, or an executive and legal notification. Combining those events produces a rate that cannot guide staffing.
A SOC can calculate four rates without pretending they are interchangeable:
review rate = alerts reviewed by a person / alerts generated
case creation rate = cases opened / alerts generated
specialist escalation rate = cases transferred to a higher tier / cases opened
confirmed incident rate = confirmed incidents / alerts generated
Publish the numerator and denominator with each rate. Also report whether correlated child alerts remain in the alert count. A falling escalation rate can indicate better automation, weaker detection, or a team that has stopped opening cases. Quality checks are needed to tell those explanations apart.
The KPMG survey's 21% result for high alert volume and the Vectra survey's 67% unaddressed figure are useful warning signs, but neither supplies a safe escalation target. Teams need their own observed rates by alert type, severity, asset importance, and shift.
Fatigue and staffing pressure
Alert fatigue is difficult to measure directly. Surveys typically measure workload, burnout, intention to leave, or perceived pressure instead.
Proofpoint's 2024 Voice of the CISO survey covered 1,600 CISOs at organizations with more than 1,000 employees across 16 countries. It found that 53% had experienced or witnessed burnout during the prior 12 months, and 66% said expectations on the CISO or CSO were excessive. These are leadership responses, not a burnout rate for frontline SOC analysts.
ISC2's 2024 workforce study found that 67% of respondents said their organization had a cybersecurity staffing shortage. It also reported cybersecurity layoffs at 25% of respondents' organizations and budget cuts at 37%. The study covers cybersecurity professionals broadly, so it cannot be used as a SOC-only staffing estimate.
The connection to alert triage is indirect but important. A queue that depends on overtime or leaves large volumes unreviewed has little resilience when a person leaves, takes training, or handles an incident. Workforce reports help explain the capacity constraint. They do not prove that alerts caused every reported case of burnout.
For broader workforce context, see our review of workplace stress statistics. Keep general stress data separate from security-specific alert metrics.
What AI assistance has measured so far
AI can summarize incidents, correlate evidence, suggest queries, and draft response steps. The strongest public productivity evidence is narrower than many product claims.
Microsoft's 2024 controlled study found that experienced security professionals using Copilot for Security completed the tested tasks 22% faster and with 7% higher accuracy. Incident summarization was 39% faster, script analysis was 14% faster, and incident-report analysis was 19% faster. Microsoft sponsored and evaluated its own product, and the experiment tested selected tasks rather than a live SOC's full queue.
A separate Microsoft study of 149 people with basic IT skills found that Copilot users were 26% faster and 44% more accurate across the tested tasks. Participants were security novices, so that result should not be blended with the experienced-user trial.
Neither study establishes that an organization can reduce staffing by 22% or 26%. Faster task completion may allow deeper investigations, more alert coverage, documentation, threat hunting, or shorter queue waits. Teams should measure the effect on reviewed alerts, confirmed incidents, reversals, and missed detections before converting task speed into a headcount assumption.
Technical teams evaluating where assistance fits can also review our guide to a virtual assistant for software development. Administrative support may handle documentation, scheduling, reporting, and approved workflow steps, but security judgment and privileged actions need explicit ownership and access controls. For a wider operating-model comparison, see the business process outsourcing guide.
A workload model for SOC planning
Start with observed queue data rather than a vendor's average:
daily review hours = alerts routed to people × average active review minutes / 60
Add specialist work separately:
daily escalation hours = escalated cases × average active escalation minutes / 60
The table below is illustrative planning math. None of its values is a published market benchmark.
| Alerts routed to people per day | Average review time | Escalation rate among reviewed alerts | Average escalation time | Calculated daily work |
|---|---|---|---|---|
| 300 | 4 minutes | 5% | 30 minutes | 27.5 hours |
| 600 | 4 minutes | 5% | 30 minutes | 55 hours |
| 600 | 6 minutes | 10% | 45 minutes | 105 hours |
For the first row, basic review takes 20 hours and 15 escalations add 7.5 hours. The total is 27.5 active queue hours. Staffing must also cover shift overlap, breaks, meetings, training, detection tuning, threat hunting, leave, and incident surges. Dividing by an eight-hour shift would understate the people required because no analyst spends every scheduled minute on queue work.
Use median and 90th-percentile handling times. Averages can conceal a small group of difficult cases that consumes much of the day. Split the model by detection family and severity rather than assigning one duration to every alert.
Metrics that make alert workload auditable
| Metric | Definition | Management question |
|---|---|---|
| Alert arrival rate | New alerts per hour and per day | When does demand peak? |
| Human-routing rate | Alerts sent to people divided by alerts generated | How much work reaches the queue? |
| Time to first review | Alert creation to analyst acceptance | Is queue delay growing? |
| Active review time | Minutes of analyst work per alert | How much labor does triage consume? |
| Closure reason | Detection error, benign match, failed attempt, duplicate, incident, or other defined outcome | What creates avoidable work? |
| Specialist escalation rate | Higher-tier transfers divided by reviewed cases | Which alert types consume scarce expertise? |
| Reopen or reversal rate | Closed alerts later reopened or reclassified | Are fast closures holding up? |
| Coverage | Reviewed or validly automated alerts divided by in-scope alerts | What part of the queue receives a disposition? |
| Analyst load | Active queue hours and open cases per staffed hour | Is scheduled capacity sufficient? |
Record automation as a disposition, not as invisible deletion. Sample automated closures and report their reversal rate. A shorter queue is only an improvement if detection quality and incident outcomes remain acceptable.
Frequently asked questions
How many security alerts does a SOC receive each day?
One 2023 survey of 2,000 SecOps analysts reported 4,484 per day on average, while a 2020 commissioned study reported more than 11,000. The gap reflects different samples and definitions. A team should publish its own counts for raw detections, promoted alerts, cases, and incidents.
What percentage of security alerts are false positives?
There is no reliable universal percentage. Vectra's 2023 respondents regarded 83% of alerts as false positives and not worth their time, while Splunk reported in 2025 that 55% of respondents dealt with too many false positives. The first is a reported share of alerts in one survey. The second is a share of respondents describing a problem.
How long should alert triage take?
The reviewed sources do not support one target. Measure active handling time and queue wait separately by alert type and severity. Use both the median and a high percentile when staffing the queue.
What is a good escalation rate for a SOC?
No cross-industry target is supported by these sources. Define what counts as an escalation, state the denominator, and pair the rate with confirmed incidents, reversals, missed detections, and handling time.
Can AI reduce alert triage workload?
Microsoft's controlled studies found faster and more accurate completion on selected security tasks. Those results support testing AI assistance, but they do not prove a proportional staffing reduction in a live SOC. Validate automation against local alerts and keep sampled human review.
Related operational research
For staffing context, see small-business cybersecurity statistics and technical support outsourcing statistics.
Sources and limitations
- Vectra AI, 2023 State of Threat Detection. Survey of 2,000 SecOps analysts; self-reported alert volume, triage time, and false-positive perceptions.
- IBM Research and USENIX Security 2024, True Attacks, Attack Attempts, or Benign Triggers?. Empirical analysis of 115 million network alerts from one SOC over four years.
- Splunk, State of Security 2025. Industry survey reporting alert, false-positive, tool-maintenance, and data-management pressure.
- KPMG, Time to Transform Is Now, Security Operations Center Survey 2024. Survey of security leaders; challenge selections are not time-allocation measures.
- Check Point, 2024 Cloud Security Report. Cloud-security survey; resolution time is elapsed time rather than active analyst labor.
- Microsoft, Randomized Controlled Trial for Copilot for Security, 2024. Vendor-run controlled study of experienced security professionals on selected tasks.
- Microsoft Cyber Signals, issue 6. Separate randomized study of 149 security novices with basic IT skills.
- Proofpoint, Voice of the CISO 2024. Survey of 1,600 CISOs at large organizations in 16 countries; leadership burnout is not a frontline analyst rate.
- ISC2, 2024 Cybersecurity Workforce Study. Global cybersecurity workforce research; broader than SOC alert triage.
- Palo Alto Networks and Forrester Consulting, 2020 State of Security Operations. Older commissioned survey used only to show how reported alert-volume benchmarks vary.
Most sources are surveys or vendor-sponsored studies. They use different populations, questions, products, and definitions. The IBM study supplies field evidence but comes from one SOC. No cited source establishes a universal staffing ratio, false-positive target, escalation rate, or review-time standard.
Tags
Ready to put this into practice?
Book a free 15-min match call
Tell us what role you're filling. We'll match you with a pre-vetted virtual assistant - or tell you honestly if we're not the right fit.
Book a free call →