Security teams are drowning in alerts, and AI might not be the answer everyone thinks it is.
In this episode, Erik Bloch, VP of Security at Illumio, breaks down the math on why AI-powered alert triage may be financially unfeasible for most organizations. With 85 to 90 percent of alerts being non-malicious, security teams are still sorting through massive volumes of noise to find the real threats.
Many vendors are betting that AI will solve this problem by triaging alerts at scale. But the reality?
Processing a thousand alerts per day over the course of a year can cost millions of dollars in compute time for LLMs. For most companies outside of Google or major financial institutions, that budget simply doesn't exist.
Erik's take is different: push the problem back to the vendors.
The tools generating 80 to 90 percent garbage alerts are the ones organizations pay millions of dollars per year for. Rather than adding another expensive layer on top to filter the noise, vendors should be delivering higher fidelity alerts from the start.
As a defender, the goal is finding high fidelity alerts that can be actioned. If vendors filtered better on their end, security teams could focus on catching bad guys instead of triaging false positives.
Full episode: https://www.youtube.com/watch?v=BTzrk8h52xk
#cybersecurity #AI #SOC #alertfatigue #infosec #securityoperations #podcast