In Vectra's 2023 survey of 2,000 security analysts, analysts estimated that 83% of the alerts they get are false positives.
That's the real cost of bad tuning. Not wasted time. Lost trust. Once people stop believing the alert, the real one walks right past them.
I ran into this with a recurring DLP false positive. Same pattern, over and over, legitimate work getting flagged as sensitive data exposure.
The cause: a redundant custom data type overlapping a pre-built category that already covered the same content.
Isolated the overlap, fixed it, and the false positive pattern stopped.
I build HIPAA-compliant DLP policies the same way: every rule has to earn its place. More rules isn't more protection. Past a point, it's just more ways to train people to ignore you.
False positives are a security problem. Investigate them like one.