Security Teams Ignore Nearly A Third Of Alerts, And Many Later Become Incidents

Prophet Security's survey of 250 security professionals finds SOC teams overwhelmed by alert volume, with 96% now using or evaluating AI.

Published on Aug 5, 2026
Security Teams Ignore Nearly A Third Of Alerts, And Many Later Become Incidents

Security teams are leaving an average of 28% of alerts uninvestigated, citing a lack of time or staff to work through them. Of those surveyed, 60% said an alert that was never investigated later became a material incident that exposed data, disrupted operations, or created business risk. That is the central finding of Prophet Security’s second annual State of AI in Security Operations report, released yesterday (Aug. 4) at Black Hat USA.

The volume behind that gap is concerning. Nearly three-quarters of organizations field more than 50 alerts a day, and over a quarter take in more than 500. The average investigation takes 75 minutes to complete. Two in five said they had disabled a detection rule, or considered it, because they could not keep up with the alerts it produced.

The findings come from a survey of 250 IT and security professionals conducted by ViB and commissioned by Prophet Security, which sells an AI platform for security operations. Figures are self-reported.

AI Adoption Is Now Near-Universal

“The organizations seeing the greatest success aren’t replacing analysts with AI,” said Kamal Shah, co-founder and CEO of Prophet Security.

“They’re using AI to investigate every alert, reduce response times, and free experienced defenders to focus on higher-value work like threat hunting, detection engineering, and incident response.”

The report puts AI use in the SOC at 96%, split between organizations already running it day to day and those piloting or evaluating it. Just 4% said they had no plans to adopt it.

Among teams already using AI, 72% said it cut investigation time by at least 25%, and 18% reported cutting it by more than half.

Respondents named faster response, better around-the-clock coverage and fewer false positives as the main measures of success.

Attackers Are Adopting AI Too

More than half of respondents (56%) said they had seen a rise in AI-driven attacks over the past year, climbing to 63% in financial services and 58% in healthcare.

The most commonly reported threat was phishing and social engineering carrying clear signs of language-model-generated text, followed by deepfake-enabled fraud and more sophisticated credential attacks.

Adoption is not frictionless. Data privacy and AI transparency ranked as the top two barriers, and nearly half of the organizations that tried to build their own AI-powered SOC tooling later abandoned the effort or moved to a commercial product.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.