Alert fatigue
Alert fatigue describes the state in which a team receives so many security alerts that it stops examining them seriously. The alerts keep arriving, they simply stop being read.
This is more dangerous than a detection gap, because it is invisible from the outside: the system reports, the documentation holds up, and nobody is looking.
Someone receiving a hundred alerts a day, ninety-eight of which turn out to be routine, adapts. After a few weeks the list gets skimmed rather than reviewed. That is not carelessness, it is a documented property of human perception under sustained load. It is also the point at which the one alert that mattered gets missed.
Alert fatigue rarely comes from a single poor tool. The usual sequence: a system is connected, rules are enabled generously so that nothing is missed, and because nobody has time for tuning, sensitivity stays high. Alert volume climbs while the number of people handling it stays the same. Related events arrive separately rather than as one incident, multiplying the count further.
The effective countermeasure is not detecting less. It is treating related events as a single case and ordering them by actual significance. Behaviour-based detection helps here, because it works from deviation against a learned baseline rather than fixed thresholds. The limit: no system removes a team's judgement about whether an anomaly has an ordinary explanation in this particular environment. Prioritisation reduces volume, it does not replace judgement.
On why attention, not data volume, is the constraint when reviewing network data:
Why attention is the constraint