A majority of IT professionals receive more than 500 public cloud security alerts per day, and they spend more than 20% of their time on prioritizing alerts, which results in missed critical issues and team burnout, a recent Orca Security report found.
The cloud security vendor surveyed more than 800 IT professionals across five countries and 10 industries for its 2022 Cloud Security Alert Fatigue Report. It found that 59% of respondents were pinged at least 500 times per day regarding potential security issues. And that 57% of respondents use five or more cloud service providers.
This multi-cloud model combined with disparate tooling is overwhelming security teams with alerts. The report showed those using 10 or more cloud security tools are 67% more likely to receive more than 1,000 alerts per day, and around 10% more of them suffered from alert fatigue than teams with five or fewer tools.
In the security space “there's a huge gap between the capabilities and the tools and the way that they are actually being utilized,” Orca Security CEO and co-founder Avi Shua told SDxCentral. “In this era of cloud security, tools … are sending many things that are technically correct, but simply not practical” to follow all of them.
He pointed out that in the report, 95% of the respondents said they are very confident of the accuracy of the security tools, but 43% of them reported that 40% of the alerts were false positives. “It might sound weird or contradictory,” Shua said.
The reason is the vast majority of the security tools make exactly the same mistake that only alerts “this is the most severe vulnerability … but they don't look who can access it and what's behind it,” Shua added. “There is the business impact versus a vulnerability that might be the most severe vulnerability in the world but it's blocked due to a configuration and there is nothing valuable.”
Alerts Fatigue Causes Missed Critical Issues, Burnout, Internal FrictionAs the amount of cloud security alerts increases, teams have to spend more time dealing with prioritization. A quarter of respondents spent more than 40% of their time deciding which alerts to handle first. Even spending so much time, 41% said critical alerts were being missed on a weekly basis. And more than 60% of respondents agreed alert fatigue has contributed to turnover or internal friction.
Non-contextualized vulnerability or misconfiguration alerts might lower security teams’ credibility in the organization, and then security practitioners would be less willing to ask other teams to fix those issues, Shua explained.
“I'm a big believer that secure tools should move from being right to being smart,” he said, adding tools need to be able to send alerts of vulnerability that can be exploited today or misconfigurations that require fixing in a timely manner.
Comments