SHARE
Facebook X Pinterest WhatsApp

Survey Highlights the Need for Automation to Manage Security Alerts

thumbnail
Survey Highlights the Need for Automation to Manage Security Alerts

System Security Specialist Working at System Control Center. Room is Full of Screens Displaying Various Information.

Twice as many security teams with high levels of automation resolve most or all alerts the same day compared to those with lower levels of automation .

Jul 22, 2020

Continuous intelligence (CI) is essential in situations where actionable insights must be derived from real-time data in milliseconds to seconds. A prime use case for CI is decision support and analysis automation of security alerts. That’s been the case for a while. But the need for automated help is now ever-more critical with cyberattacks on the rise and corporate boundaries being pushed into every employee’s home due to the pandemic.

See also: Using Continuous Intelligence for Decision Support and Automation

A recent Dimensional Research survey, sponsored by Sumo Logic, put the issues into perspective. The survey included 427 IT security stakeholders in organizations with at least 1,000 employees. It found that IT security staff simply cannot keep up with the volume of security alerts organizations receive every day.

Specifically, 56% of companies with more than 10,000 employees must deal with more than 1,000 security alerts per day. Most companies have seen increases in security alerts. Seventy percent of the companies surveyed have seen the volume of security alerts more than double in the past five years.

The challenges are likely to get exacerbated by current work conditions. “You increase the attach surface due to COVID,” said Greg Martin, General Manager of the Security Business Unit at Sumo Logic. 

He noted that you have workers and executives using their computers on the same networks as their families. This potentially exposes secure systems to vulnerabilities. “You’re pouring a clean glass of water into a dirty glass of water,” he said.

Overwhelmed with Alerts

Most respondents, 93% of the companies, said they could not address all the security alerts they receive on the same day. And 83% said their security staff experiences alert fatigue.

Such a situation is doubly bad. Lacking the bandwidth, security staff can only do their best in the time available. Certainly, they would focus most of their energy on the highest-level alerts. But therein lies a problem.

Ignoring attacks classified as low-level because there is not enough time or staffing power to get to them opens companies to problems. The reason: Many hackers use compounded and advanced persistent threat (APT) attacks. Essentially, compounded attacks use multiple, small, and less detectable attacks over time. Such an attack might start with a phishing attempt. The result might be the installation of malware or the stealing of credentials. Similarly, an APT attack would have the hacker gains access to a system and remain there for an extended period of time without being detected.

Advertisement

How Automation and CI can Help

Simply put, organizations are being overwhelmed with security alerts. What’s the best way to deal with the situation?

One way would be to add more staff. The survey found that 75% of the companies said they would need three or more additional security analysts to address all alerts the same day. Many companies are not likely to boost their staff, given the current economic conditions.

Instead, most (92%) believe automation is the best solution for dealing with the large volume of alerts. The idea here is to use real-time analysis of the alert data. One use of CI would be to classify and examine every alert. A more advanced use would be to spot patterns and make predictions. For example, these three low-level alerts, encountered in this order, are precursors to this type of attack.

How effective is automation? Twice as many security teams with high levels of automation (65%) resolve most or all alerts the same day compared to those with lower levels of automation (only 34%), according to the survey’s findings.

thumbnail
Salvatore Salamone

Salvatore Salamone is a physicist by training who writes about science and information technology. During his career, he has been a senior or executive editor at many industry-leading publications including High Technology, Network World, Byte Magazine, Data Communications, LAN Times, InternetWeek, Bio-IT World, and Lightwave, The Journal of Fiber Optics. He also is the author of three business technology books.

Recommended for you...

The Rise of Autonomous BI: How AI Agents Are Transforming Data Discovery and Analysis
Beyond Procurement: Optimizing Productivity, Consumer Experience with a Holistic Tech Management Strategy
Rishi Kohli
Jan 3, 2026
Smart Governance in the Age of Self-Service BI: Striking the Right Balance
Why the Next Evolution in the C-Suite Is a Chief Data, Analytics, and AI Officer

Featured Resources from Cloud Data Insights

The Difficult Reality of Implementing Zero Trust Networking
Misbah Rehman
Jan 6, 2026
Cloud Evolution 2026: Strategic Imperatives for Chief Data Officers
Why Network Services Need Automation
The Shared Responsibility Model and Its Impact on Your Security Posture
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.