Detection Engineering
Alert volume is not a security metric
Elena Marsh · 2 Jun 2026
Why the number of alerts a platform generates tells you almost nothing about whether your organisation is actually safer.
Ask most vendors what their platform does well and the answer, eventually, comes back to volume: more telemetry, more coverage, more alerts surfaced. It's an understandable pitch — volume is easy to demonstrate in a sales cycle. It's also close to irrelevant to the question a client actually needs answered, which is narrower and harder: of everything happening in this environment right now, what needs a human decision in the next hour?
We've sat with clients whose previous provider forwarded several thousand alerts a week. Almost none of them had been triaged beyond a severity tag assigned by a rule, not a person. The client's own team had, in effect, been handed the job the vendor was paid to do.
The fix isn't more tooling. It's treating interpretation as the actual deliverable, and measuring detection engineering against a much less flattering metric than alert count: how many of the alerts we generate change what a client does next. Anything that doesn't clear that bar is noise, however sophisticated the rule behind it.
Related reading
Compliance
DORA is a resilience test, not a compliance checkbox
What actually changes operationally for UK-serving financial firms under DORA, beyond the paperwork.
Merrow Research Team · 14 May 2026
Incident Response
The first 90 minutes of a ransomware event
A breakdown of the decisions that determine containment scope, drawn from anonymised patterns across Merrow's retainer caseload.
Tomás Reyes · 22 Apr 2026