Analysts at managed security service providers say 53% of the alerts they get are false positives, and 44% say they ignore alerts when the queue gets too full. (IDC/FireEye analyst survey)
I handle escalations for managed service providers. That doesn't surprise me at all.
Here's the problem: business email compromise drove just over $3 billion in losses reported to the FBI in 2025, across 24,768 complaints. Second costliest crime type the FBI tracks. And BEC almost never trips an alarm that screams "THREAT." It looks like a vendor changing bank details. A forwarding rule nobody remembers creating. A login that's probably just someone traveling.
The scariest attacks are boring. That's the whole trick.
After 5,970 cases, 1,040 of them High or Highest priority, here's what I actually believe:
- The question is never "is this alert bad?" It's "can I prove what happened?"
- Headers are witness statements. Message trace is the crime scene. Auth results tell you which defenses held.
- Sometimes the threat is the tool. I've documented 498 product defects with logs and repro steps, and 315 reached DONE. Your detection stack can be wrong, and you won't know unless someone investigates it like a suspect.
Verizon's 2026 DBIR found a human element in 62% of breaches. Attackers don't need you to be careless. They need one person to act normal at the wrong moment.
Separating that from noise is the job. It's the job I want to keep doing, deeper.