Research · 2 min read
100 Security Alerts Come In. How Many Actually Need Action?
A useful monitoring scorecard distinguishes raw alerts, reviewed alerts, incident-linked alerts, and distinct incidents.
64,800 alerts in six months sounds like a flood of crime. It isn't — and any monitoring provider quoting raw alert volume is counting on you not asking what happened next. Follow 100 alerts through our pipeline: 78 never need a human, 20 get dismissed by one, and fewer than 3 become incidents.
Our analysis of 64,800 alerts, january 1 through june 30, 2026.
How much operational work sits between a raw alert and a distinct incident?
Across 64,800 alerts recorded from January through June 2026, every 100 alerts produced 77.75 automatic filters, 19.64 dismissals after human review, and 2.61 incident records. Raw alert volume is not the same as reviewer workload or distinct incident volume.
The numbers behind the answer
Selected measures only. Denominators and interpretation stay attached so the headline cannot stand alone.
77.75
Automatically filtered per 100 alerts
50,382 of 64,800 raw alerts ended at the automatic-filter stage.
11.72%
Reviewed alerts creating an incident
1,690 of 14,418 alerts in the human-review cohort created an incident record.
1.57
Incident-linked alerts per distinct incident
1,690 incident-linked alerts consolidated into 1,076 distinct incidents.
What happens to 100 raw security alerts
Take 100 raw alerts. 77.75 die at the automatic filter — duplicates, noise, obvious nothing. Of the 22.25 that reach human review, 19.64 get dismissed by a person. 2.61 create an incident record. Raw volume, it turns out, mostly measures how twitchy the sensors are.
The second denominator is where the workload lives. Among alerts that actually reach review, 11.72% create an incident — a very different picture from the 2.61% raw conversion. A dashboard quoting only the raw number is describing the sensors, not the review team.
Evidence visual
Disposition of every 100 raw alerts
The three stages are mutually exclusive final alert outcomes. ‘Human dismissed’ is not labeled a false alarm because the outcome alone does not establish ground truth.
1,690 incident-linked alerts became 1,076 distinct incidents
One more unit change before the counts mean anything. An alert is a sensor event; an incident is the operational record a reviewer creates. One unfolding situation — somebody working a gate for two minutes — can fire several alerts. In this cohort, 1,690 incident-linked alerts consolidated into 1,076 distinct incidents: 1.57 alerts per incident, and 60.22 raw alerts per distinct incident.
Count linked alerts as separate incidents and you'd overstate case volume by half. These ratios describe the pipeline's shape. They don't establish detection accuracy, and they don't say whether staffing is right.
Dashboard rule
Keep raw alerts, reviewed alerts, incident-linked alerts, and distinct incidents as separate units.
A useful monitoring scorecard reports the work between detection and action
Each stage answers a different question. Raw alerts: how noisy is the detection layer? Reviewed alerts: how much human work did it take? Review-to-incident yield: what survived scrutiny? Distinct incidents: how many actual cases were there? Alerts per incident: how well does consolidation work?
Two things this aggregate can't tell you: which sensor source converts best — that needs source-by-stage denominators, not raw source totals — and whether reviewer staffing is adequate, which needs review duration, arrival patterns, and concurrency. The checklist below is the buyer's version.
- How many raw alerts entered the system?
- How many required human review?
- How long did review take?
- How many alerts linked to distinct incidents?
- How do stage rates vary by source and month?
Questions property teams ask
Does human dismissed mean a false alarm?
No. It means review did not create an incident record; the stage alone does not establish ground truth.
Does 2.61 per 100 mean only 2.61% of alerts were real?
No. It is the share that created incident records. Reality, relevance, and the operational incident threshold are different concepts.
Can these totals determine reviewer staffing?
Not by themselves. Staffing requires arrival patterns, review duration, concurrency, service levels, and escalation workload.
Which alert source converts best?
The source-by-stage calculation is required for that comparison. Raw source totals alone are not conversion rates.
Our methods, limits, and sources
How we calculated this
This is original 911 Sentinel research — we gathered the records, ran every calculation below, and published the aggregate dataset.
We exported our own alert records, assigned each alert to one final stage, calculated a per-100-alert funnel, isolated the human-review cohort, and deduplicated linked incident IDs.
- We validated alert timestamps, source, stage, and any incident link.
- We counted automatic-filter, human-dismissed, and incident-created outcomes.
- We calculated raw-alert and reviewed-alert conversion rates with explicit denominators.
- We counted distinct linked incidents and summarized source-stage and monthly patterns.
What this analysis cannot establish
- Reached human review is inferred from final stage rather than a dedicated review-start event.
- The current contract lacks review-start and completion timestamps.
- A human-dismissed alert is not automatically a confirmed false alarm.
- Source volume alone cannot establish source-specific effectiveness.
- Several alerts can link to one incident.
Sources
This study is 911 Sentinel's own work, built from our operational records.
Related questions and practical guides
New coverage — intake open
Define the alert-to-action scorecard before comparing systems
The operating model should make filtering, verification, incident creation, response, and reporting separate and inspectable stages.