The Science Behind Alert Fatigue in Security Teams, and How to Beat It

webinar april 22 for LI Site The Science Behind Alert Fatigue in Security Teams & How to Beat It

In this OX Security webinar, Field CTO Boaz Barzel is joined by security researcher Matt Johansen (Vulnerable U) and cognitive neuroscientist Professor Moshe Bar (Bar-Ilan University) to examine alert fatigue from both sides: what it does to a security team, and what it does to the human brain. They define the problem (an average organization sees more than half a million alerts, the vast majority non-critical), explain the neuroscience of cognitive load and depletion, and lay out practical mitigations spanning sleep, task-switching, nutrition, and, above all, leadership practices like rotating work and forcing time off. The panel closes on where AI might genuinely help, from natural-language triage to detecting fatigue itself.

Key Takeaways

  • Most alerts aren’t real, so the problem is signal, not effort. Research cited puts an average organization at more than half a million alerts, with 95 to 98% non-critical and sometimes not real issues at all.
  • “Alert fatigue” is just cognitive and decision fatigue. The brain has no dedicated alert module; the same depletion shows up whenever you repeat one mental process for hours, and it’s well documented across domains.
  • Fatigue changes how you work, not only how much. Depleted people become less creative and exploratory and default to easier, more automatic decisions, effectively a different employee doing qualitatively different work.
  • Sleep, task-switching, and nutrition are real mitigations. Sleep clears the metabolic waste that builds up in overused neurons; alternating tasks lifts mood and reduces depletion; steady glucose, omega-3, hydration, and antioxidants help too.
  • The fix is a leadership responsibility, not the individual’s. Rotate work for diversity, cap how long anyone is on call, and force time off after firefighting, because top performers won’t stop on their own.
  • AI may help the front line, but it’s early. Natural-language querying, correlating sources before alerting, level-one triage, and even detecting fatigue itself are promising directions to watch.

Video Transcript

Speakers

boaz li image

Boaz Barzel

View on LinkedIn

Field CTO, OX Security (host/moderator)

Field CTO at OX Security and the session’s moderator.

Moshe Bar

Professor of Neuroscience, Bar-Ilan University

Professor of neuroscience at Bar-Ilan University, a former Harvard Medical School professor and author of a book on mind wandering.

Matt Johansen

Matt Johansen

View on LinkedIn

Security Researcher, Vulnerable U

Security researcher behind Vulnerable U, with nearly two decades across offensive security, AppSec, and incident response at firms including Bank of America and Reddit.

FAQ

By the research cited in the session, an average organization sees more than half a million alerts, and 95 to 98% of them are not critical, and sometimes not real issues. The core challenge is signal-to-noise, not simply working harder.

On the front line it’s clicking “no, this is okay” 99 times out of 100 while staying sharp for the one that isn’t, plus the real exhaustion of late-night incident response. Signs include missed or mis-triaged findings, visible tiredness, and general burnout and stress.

Repeating one mental process depletes brain resources and reward chemicals like dopamine and serotonin. Depleted people don’t just do less, they do it differently, becoming less creative and exploratory and falling back on easier, automatic decisions.

Prioritize real sleep (it clears metabolic waste from overused neurons), alternate tasks rather than grinding one domain for hours, and pay attention to nutrition: steady glucose, omega-3, hydration, and antioxidants. Diversity of action both reduces depletion and improves mood.

Own the problem. Rotate work for variety, cap on-call stretches, and force time off after heavy firefighting, ideally matching rest to the hours someone was activated. Avoid “superhero culture,” where one or two people become single points of failure and burn out even on a fully staffed team.

Possibly both, and it’s early. AI can raise the volume of code and alerts, but it’s also promising for natural-language querying, correlating multiple sources before alerting, handling level-one triage, and even flagging when an analyst is entering a fatigue zone.

Rely on defense in depth: missing one alert shouldn’t mean the organization fails, because attackers have to clear many layers and make noise along the way. Then plan and practice so decisions aren’t made while tired, and swap team members in and out to execute the plan.