My Friday SIEM post is here. On today's plate I wanted to discuss the Fear of Not Doing Enough problem in security.
New attack drops. We throw a generic detection at it fast so we have "something." It generates noise. We don't tune it. The false sense of coverage becomes more important than actual coverage.
And nobody connects the detection to what happens after it fires.
You write a detection rule. Do you have the SOP for it? Do you know the analysis path? Can you estimate how that alert impacts your team's workload downstream?
Dylan Williams probably has some really strong opinions on this one ๐
If you can't answer those, you deployed a work generator with no operating manual.
But even if you fix all of that, you're still only looking at one input stream.
A was reading 38-page ACM research paper reviewed 30+ solutions to alert fatigue in SOCs. Every single one assumes the work starts with a SIEM alert.
SIEM alerts are probably more than half the work for most teams. But the work that doesn't come from the SIEM is often the most manual, least structured, and hardest to track.
IT escalations.Access reviews. Audit findings. Pen test remediation. Compliance asks.
In most cases you will have some or probably no automation for these .
Most of it lives in Slack threads, email chains, and spreadsheets. It runs on copy-paste, tribal knowledge, and good intentions.
As Erik Bloch has pointed out many times, most of the SOC work ' day-to-day has nothing to do with chasing advanced adversaries. And outside of very large enterprises with 10 security sub-departments, the same 3-5 people triaging SIEM alerts are also pulling audit evidence and handling IT escalations. The non-SIEM stuff eats time disproportionately because it's all manual.
Ross Haleliuk recently wrote about ServiceNow betting on "workflow gravity" to win in security. Whoever owns where work happens owns the decisions. Right now security work has no gravity. It's scattered across Slack, Jira, email, SIEM consoles, and spreadsheets.
Process mining exists for finance and operations. In security? Still very early days. Some vendors are starting to tackle it. But we still have zero data on how security work actually flows end to end.
We've been fixing the middle. Investigation is faster. AI triage is real. Now I think it's time to zoom out to where we were supposed to start. The hardest part. That's exactly why not many are doing it yet.
Fix the input. Model the cost. Understand the workflow.
If you thought this post is long , well I thought this deserved a full blog:
https://lnkd.in/dSjUYvyr
Originally posted on LinkedIn on 13 February 2026.
Read the original post and the comments.


