Skip to content
Merrow

Detection Engineering

Alert volume is not a security metric

Elena Marsh · 2 Jun 2026

Why the number of alerts a platform generates tells you almost nothing about whether your organisation is actually safer.

Ask most vendors what their platform does well and the answer, eventually, comes back to volume: more telemetry, more coverage, more alerts surfaced. It's an understandable pitch — volume is easy to demonstrate in a sales cycle. It's also close to irrelevant to the question a client actually needs answered, which is narrower and harder: of everything happening in this environment right now, what needs a human decision in the next hour?

We've sat with clients whose previous provider forwarded several thousand alerts a week. Almost none of them had been triaged beyond a severity tag assigned by a rule, not a person. The client's own team had, in effect, been handed the job the vendor was paid to do.

The fix isn't more tooling. It's treating interpretation as the actual deliverable, and measuring detection engineering against a much less flattering metric than alert count: how many of the alerts we generate change what a client does next. Anything that doesn't clear that bar is noise, however sophisticated the rule behind it.