With a global talent gap of approximately 4.76 million professionals, and two-thirds of thousands of daily alerts left uninvestigated, burnouts and high turnover are inevitable. This public survey analysis dissects the root causes of SOC analyst shortages and alert fatigue, offering three actionable strategies to move beyond manual labor and explaining how to present these solutions to the C-suite.

"We get thousands of alerts daily, but we can only investigate a fraction of them." "We batch and check overnight alerts the next morning." "Just when we think a junior analyst has matured, they change jobs." Hearing these comments from security operations teams is all too common. Whether a company has an in-house SOC (Security Operations Center) or outsources its monitoring, the dual problems of "talent shortage" and "alert fatigue" almost always appear as two sides of the same coin.
Based on published research data, this article outlines the structure of the security talent gap and "alert fatigue," explaining why brute-force manual operations are reaching their limits. We will then provide practical strategies across three main areas: (1) noise reduction by streamlining detection rules and logs, (2) automated triage and primary investigation using AI agents, and (3) redesigning human roles, followed by advice on how to explain these concepts to executive leadership.
The Security Talent Gap in Japan and Globally
First, let's look at the scale of the talent shortage. According to the 2024 study by ISC2, a global certification body, the global cybersecurity workforce stood at approximately 5.47 million in 2024—nearly flat (up 0.1%) from the previous year. However, the "workforce gap" (the shortfall between the number of professionals needed and those available) reached approximately 4.76 million, expanding by 19.1% year-over-year (ISC2 Cybersecurity Workforce Study, 2024). While the supply of talent has stalled, the attack surface and threats continue to grow.
In the same study, 90% of respondents reported at least one skills gap within their team, and 64% believe that "skills gaps cause more severe negative impacts than staff shortages." Budget constraints were cited as the primary cause of both staffing and skills gaps, with about 20% expecting further headcount reductions over the next 12 months. Furthermore, more than half noted they "do not have time to learn new skills" (ISC2, 2024). This highlights a vicious cycle: teams cannot learn due to staff shortages, and skills gaps persist because they cannot learn.
Regionally, the APAC workforce grew by 3.8% in the study, while North America saw a 2.7% decrease, showing that conditions vary by geography (ISC2, 2024). In Japan, securing and training talent remains a key policy priority, as evidenced by the IPA (Information-technology Promotion Agency) dedicating an independent section to "Current Status and Development of Cybersecurity Human Resources" in Chapter 3 of its "Information Security White Paper 2025" (IPA Information Security White Paper 2025, 2025). In reality, most domestic organizations operate with only a few dedicated security staff, or have IT departments handle security as a side role. Establishing a 24/7/365 monitoring structure solely with internal staff is generally extremely difficult. The basics and limitations of SOC structures are covered in "What is a SOC? Roles, Tier Structures, and the Basics/Limits of 24/7/365 Operations."
The Anatomy of "Alert Fatigue": Thousands of Daily Alerts, Two-Thirds Uninvestigated
Alongside the talent gap, "alert fatigue" is the other major challenge. Alert fatigue refers to a state where the continuous influx of alerts exceeding processing capacity degrades analysts' attention and judgment, leading to critical alerts being missed or ignored entirely. Originally a well-known concept regarding clinical monitor alarms in healthcare, it manifests in a far more severe form within security operations.
The underlying cause is the skyrocketing volume of signals. Microsoft processes 78 trillion security signals daily, up from 65 trillion the previous year. The company blocks approximately 7,000 password attacks per second, and encounters with human-operated ransomware increased 2.75x year-over-year (Microsoft Digital Defense Report, 2024). Additionally, research shows a 56% year-over-year increase in the proportion of malicious data breaches involving AI-powered attacks (IBM Cost of a Data Breach Report, 2026). As EDR (Endpoint Detection and Response) and SIEM (Security Information and Event Management) platforms get better at capturing these attack indicators, the volume of alerts reaching the SOC inevitably rises.
Studies quantify the impact on the ground. A survey by security vendor Vectra AI of 2,000 SOC analysts revealed that SOC teams receive an average of 4,484 alerts daily. Due to alert fatigue, 67% of these alerts are never processed, and analysts perceive 83% of all alerts as false positives (Vectra AI 2023 State of Threat Detection, 2023). It is physically impossible for a few analysts to manually investigate over 4,000 daily alerts, systematically creating this "unaddressed two-thirds."
Why False Positives Persist
The reasons for persistently high false-positive rates are common across most organizations. First, detection rules are constantly "added" but rarely "removed or consolidated." Default product rules, rules hastily added after past incidents, and threat intelligence-based rules remain active and overlap, triggering multiple alerts for a single event. Second, context such as asset and user information is often missing. An alert for an "after-hours login with admin privileges" is normal for a batch processing server, but highly suspicious for an accountant's endpoint. If this contextual information is not tied to the alert, analysts must manually research it every time. Third, alerts from EDR, SIEM, cloud, and email products arrive in silos without correlation. Consequently, analysts are left with a binary choice of either checking everything "just in case" or ignoring them in bulk.
"Uninvestigated Alerts" Equal Immediate Risk
Analysts know the danger of missed alerts all too well. In the Vectra AI survey, 71% of analysts admitted that "their organization has likely already been compromised" (Vectra AI, 2023). Additionally, a Tines survey of 900 security professionals cited "too much data, not enough context" (37%) as one of the top workplace frustrations (Tines Voice of the SOC, 2023). The core of analyst burnout lies in this mismatch between alert volume and the quality of actionable data.
For executives, the key takeaway is that the scenario of "a real threat hiding among uninvestigated alerts" is common. In the IPA's "10 Major Information Security Threats 2026," "damage from ransomware attacks" ranked first for organizations, followed by "attacks targeting supply chains and contractors" in second place, with "cyber risks surrounding AI utilization" debuting in third (IPA 10 Major Information Security Threats 2026, 2026). Ransomware attacks typically leave multiple footprints across endpoints and identity controls between initial entry and encryption. A classic pattern of severe damage occurs when these mid-stage alerts get buried as "just 1 of 4,000 daily alerts."
The Cost of Burnout and Attrition: Why Brute-Force Manual Operations Fail
Alert fatigue does not just lead to missed threats; it also drives talent out of the organization. In the Tines study, 63% of respondents experienced some level of burnout, and 55% stated they are likely to change jobs within the next year. Half pointed to understaffed SOCs, and 81% reported that "this past year's workload was the heaviest yet" (Tines Voice of the SOC, 2023). Similarly, the Vectra AI study found that 67% of analysts are actively looking for or considering a new job (Vectra AI, 2023).
This trend extends beyond analysts. Gartner predicted in 2023 that nearly half of cybersecurity leaders will change jobs by 2025, with 25% transitioning to entirely different roles due to work-related stress. At the same time, Gartner predicted that by 2025, lack of talent or human error will be responsible for over half of all significant cyber incidents (Gartner Press Release, 2023). The ISC2 study also noted that 26% of respondents struggle with "retaining talent with high-demand skills" (ISC2, 2024).
The cost of attrition goes beyond recruitment ads and hiring processes. A SOC analyst only becomes fully effective after accumulating months or years of implicit knowledge regarding network architecture, business system quirks, and what constitutes "normal" behavior for specific departments. When an analyst leaves, this knowledge is lost, increasing the load on remaining members and often triggering a chain reaction of further departures. Moreover, alert investigation quality drops during handovers and training periods. Talent loss must be viewed as a direct cost that widens security gaps.
Ultimately, these costs materialize as breach damages. IBM reports that the global average cost of a data breach reached $4.99 million—a record high up 12% year-over-year. Conversely, organizations that extensively utilize AI and automation in security reduced breach costs by $1.93 million compared to those that do not (IBM Cost of a Data Breach Report, 2026). Relying solely on manual operations is financially disadvantageous both in routine labor costs and post-incident damages.
Three Reasons Why Hiring More Staff Won't Solve It
While "hiring more people" seems like an obvious solution, it is unrealistic for most organizations. First, alert growth outpaces hiring speeds. With cloud expansion, remote work, SaaS adoption, and broader EDR deployments, the scope of monitoring and alert volumes have grown exponentially. In a market where the talent gap widened by 19.1% in a single year (ISC2, 2024), few companies can consistently hire experienced analysts. Second is the cost of 24/7/365 coverage. To keep a single monitoring seat continuously staffed while factoring in shift patterns, leave, and training, multiple headcount are required per seat, making night and weekend staffing exceptionally difficult. This is detailed in "Why Night and Weekend Security Operations Fail to Run Smoothly." Third, increasing headcount does not change the nature of the work. If you add people to an environment where over 80% of alerts are perceived as false positives (Vectra AI, 2023), new hires will spend their time verifying false positives, reproducing the cycle of burnout and attrition.
In short, manual scaling cannot achieve complete alert coverage. Organizations must redesign their operating models to reduce alert volumes, offload primary investigations to automated systems, and free up human time for high-value decision-making and continuous improvement.
Three Strategic Moves to Outgrow Manual Limits
Move 1: Reduce Noise by Streamlining Detection Rules and Logs
The first step is auditing the detection rules and logs that generate alerts. Streamlining this data before introducing automation or AI dramatically improves downstream efficiency.
Practically, start by aggregating the past 1 to 3 months of alerts by detection rule to analyze "volume," "investigation rate," and "true-positive rate." In most organizations, a handful of rules account for the vast majority of alerts, with almost none resulting in actual incidents. For these rules, apply thresholds, exclude known normal business patterns, consolidate duplicate rules, or change their action to "log for correlation only, do not alert." Additionally, integrating asset registries and identity data to automatically append server severity and user roles to alerts will eliminate repetitive manual lookups during triage.
Logs also require auditing. Ensure that key logs needed to reconstruct attack chains (from EDR, identity providers, email, proxies, and cloud consoles) are centralized in the SIEM, and remove logs that trigger alerts but are never used in investigations. Cross-source log correlation analysis is a prerequisite for seeing the complete attack picture that isolated alerts miss.
Track noise-reduction progress with metrics rather than intuition. Monitoring "false-positive rates," "the percentage of total alerts investigated," and "incidents detected per rule" on a monthly basis embeds rule maintenance into a continuous lifecycle. For KPI design, see "What are MTTR and MTTD? SOC KPI Design and Practical Improvement."
Move 2: Automate Triage and Conduct Primary Investigations with AI Agents
Even with reduced noise, manually investigating all remaining alerts is difficult. The second strategic move is automating triage (alert prioritization and initial assessment).
Organizations have traditionally used SOAR (Security Orchestration, Automation, and Response) platforms to automate routine tasks—such as querying IP reputation, retrieving endpoint details, and notifying analysts—via playbooks. While useful, playbooks only handle pre-defined logic. When unexpected scenarios arise, humans must step in. Building and maintaining playbooks also requires significant engineering effort.
To overcome these limitations, organizations are turning to AI agents for primary investigations. Upon receiving an alert, an AI agent mimics an expert analyst: it asks questions like "What is the parent of this process?" "What did this user do on other devices right before this?" and "Has this destination been observed before?" It queries EDR and SIEM platforms for evidence, determines the likelihood of an attack, and generates an investigation report. Unlike playbook-based automation, AI agents do not require every logic branch to be hardcoded; they learn the context of each environment to improve accuracy over time.
Ensuring accuracy is critical here. When adopting AI-driven investigations, design operations to run AI alongside human judgment for a set period to measure alignment, feed false positives/negatives back into the model for learning, and verify that the reasoning behind decisions is recorded in a human-readable format. For detailed steps, see "Automating Alert Triage: Primary Investigation Steps with AI Agents and Ensuring Accuracy."
Note that security teams view automation with mixed feelings. In the Tines study, 93% believe "workplace automation will improve work-life balance," yet 56% worry that "automation will eliminate their jobs" (Tines Voice of the SOC, 2023). Positioning automation not as a tool for headcount reduction, but as a way to free people for high-value tasks, is key to successful adoption. This leads to the third move.
Move 3: Redesign Human Roles Around Decision-Making, Threat Hunting, and Improvement
Traditional SOCs rely on a tiered structure where junior Tier 1 analysts filter high-volume alerts and escalate suspicious findings to Tier 2 and Tier 3 analysts. However, since Tier 1 work consists mostly of verifying false positives, this structure concentrates the most repetitive tasks on the least experienced staff, driving high attrition.
By offloading primary investigations to AI agents and automation, human roles shift to three core areas. The first is "Decision-Making." When AI identifies a high-probability attack and compiles the evidence, humans must decide whether and when to isolate assets based on business impact, and communicate with stakeholders and leadership. The second is "Threat Hunting." Rather than waiting for alerts, analysts proactively query logs based on hypotheses (e.g., "If this technique were used here, what traces would it leave?") to find hidden threats that bypassed detection rules. The third is "Continuous Improvement." This involves analyzing false-positive trends, tuning detection rules, providing feedback to AI models, and running incident response drills to elevate overall operations.
This redesign also aids talent retention. As noted in the ISC2 study, where over half of respondents lacked time to learn (ISC2, 2024), learning and growth stop when analysts are overwhelmed by alert verification. Redirecting time from alert sorting to specialized tasks like threat hunting and detection engineering transforms the career path for analysts. For smaller teams, simplifying to a two-layer structure—"AI for primary investigation, humans for decision-making and improvement"—is a highly practical model.
The Reality of AI SOC: Empowering Teams and Eliminating Operational Overhead
An operating model integrating these three moves around an AI-agent core is known as an "AI SOC." While the definition of an AI SOC and how it differs from traditional SOCs are outlined in "What is an AI SOC? Mechanism, Differences from Traditional SOCs, and Key Benefits Explained Simply," its main value in this context is how it breaks the cycle of alert fatigue.
Yagura AI SOC is a service featuring AI agents that replicate the workflows of tier-one analysts, autonomously investigating and addressing EDR and SIEM alerts 24/7/365. By automating repetitive primary investigations, it extends coverage to alerts that would otherwise go unchecked, reducing operational overhead. Organizations should validate the impact in their own environments, looking not just at eliminated manual tasks but also at time saved on human verification and follow-up investigations.
Additionally, Yagura AI SOC utilizes contextual memory to learn local environments, continuously improving investigation accuracy. The implicit knowledge of "what is normal for this department" is retained within the system rather than inside an analyst's head, mitigating the risk of quality drops when staff leave. It integrates with over 100 security products (including EDR, SIEM, and identity providers) and can analyze alerts from existing tools like Microsoft Sentinel. This makes it easy to deploy without replacing current infrastructure, avoiding extra operational burdens. To learn more about how AI agents augment rather than replace analysts, see "The Era of the AI Agent SOC: Augmenting, Not Replacing, Analysts."
Securing Executive Buy-In
When presenting these strategies to leadership, security investments are often framed as a choice: "hire more staff, outsource, or automate." Grouping the discussion around Risk, Cost, and Human metrics helps align security initiatives with business priorities:
The Risk Dimension: Present your current alert investigation rate to show that leaving alerts unaddressed creates a systemic risk. Point to industry data showing that 67% of alerts go uninvestigated (Vectra AI, 2023) as a benchmark to compare against your internal performance.
The Cost Dimension: Highlight that the global average cost of a data breach is $4.99 million, and that organizations leveraging AI and automation save an average of $1.93 million (IBM Cost of a Data Breach Report, 2026). Compare ongoing staffing costs against potential incident damages.
The Human Dimension: Share metrics on team overtime, after-hours escalations, and recent turnover to show how burnout impacts monitoring quality. Emphasize that in an industry where 63% experience burnout and 55% plan to change jobs (Tines, 2023), assuming you can easily hire your way out of the problem is unrealistic.
Conclude by presenting a phased plan: "First, clean up rules to reduce noise; second, automate primary investigations; third, focus human analysts on decision-making and improvement." Tying each phase to clear KPIs (investigation rate, false-positive rate, MTTD/MTTR) enables leadership to track the return on investment. The key is positioning this initiative not as a cost center, but as a strategic step to eliminate missed threats and ensure business continuity with existing resources.
Summary
With the global security workforce gap reaching 4.76 million (ISC2, 2024), two-thirds of daily alerts left unexamined (Vectra AI, 2023), and over 60% of analysts experiencing burnout (Tines, 2023), talent shortages and alert fatigue are deeply linked. For most organizations, hiring more headcount alone cannot break this cycle.
Addressing this requires three steps: first, clean up rules and logs to improve alert quality; second, offload triage and primary investigations to AI agents and automation to achieve full coverage; third, redesign human roles around decision-making, threat hunting, and improvement to foster professional growth. The integration of these strategies is the AI SOC, an operating model that fundamentally shifts the economics of threat monitoring. The first step is simple: gain visibility into your team's alert coverage and daily workload.
Related Service: Learn more about Yagura AI SOC, which uses AI agents to autonomously investigate and address EDR/SIEM alerts 24/7/365, helping teams eliminate operational overhead.
References & Sources
ISC2 Cybersecurity Workforce Study (2024): https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study
Tines Voice of the SOC (2023): https://www.tines.com/reports/voice-of-the-soc-2023/
Vectra AI 2023 State of Threat Detection (2023): https://www.vectra.ai/resources/2023-state-of-threat-detection
IBM Cost of a Data Breach Report (2026): https://www.ibm.com/reports/data-breach
Gartner Press Release "Gartner Predicts Nearly Half of Cybersecurity Leaders Will Change Jobs by 2025" (2023): https://www.gartner.com/en/newsroom/press-releases/2023-02-22-gartner-predicts-nearly-half-of-cybersecurity-leaders-will-change-jobs-by-2025
Microsoft Digital Defense Report (2024): https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/microsoft-digital-defense-report-2024
IPA 10 Major Information Security Threats 2026 (2026): https://www.ipa.go.jp/security/10threats/10threats2026.html
IPA Information Security White Paper 2025 (2025): https://www.ipa.go.jp/publish/wp-security/2025.html



