---
title: "What the 2025 SANS Detection & Response Survey Reveals: False Positives & Alert Fatigue Are Worsening"
description: What the SANS data tell us and why false positives are now the biggest hidden risk facing defenders.
image: https://www.stamus-networks.com/hubfs/SN-SANS25-FalsePos.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# What the 2025 SANS Detection & Response Survey Reveals: False Positives & Alert Fatigue Are Worsening

 by [D. Mark Durrett](https://www.stamus-networks.com/blog/author/d-mark-durrett) | Dec 16, 2025 | [Network Detection and Response](https://www.stamus-networks.com/blog/tag/network-detection-and-response), [Declarations of Compromise](https://www.stamus-networks.com/blog/tag/declarations-of-compromise), [Cloud Security](https://www.stamus-networks.com/blog/tag/cloud-security), [Industry Perspective](https://www.stamus-networks.com/blog/tag/industry-perspective), [Artificial Intelligence](https://www.stamus-networks.com/blog/tag/artificial-intelligence), [Transparency](https://www.stamus-networks.com/blog/tag/transparency), [Clear NDR Enterprise](https://www.stamus-networks.com/blog/tag/clear-ndr-enterprise), [uncovered with Clear NDR](https://www.stamus-networks.com/blog/tag/uncovered-with-clear-ndr), [SANS](https://www.stamus-networks.com/blog/tag/sans)

![](https://www.stamus-networks.com/hubfs/SN-SANS25-FalsePos.jpg)

Alert fatigue - the condition that arises from being overwhelmed by millions of vague alerts and false positives that require lengthy research - is an everyday occurrence for SOC teams, and results in missed threat signals along with delayed incident detection and response. According to the newly released [2025 SANS Detection & Response Survey](https://www.stamus-networks.com/hubfs/SANS%202024%20Documents/2025_Survey_Detection-Response_Stamus.pdf?hsLang=en) (sponsored by Stamus Networks), the problem has escalated to crisis levels. False positives aren’t just slowing analysts down, they’re becoming one of the biggest obstacles to modern detection and response.

Here’s what the SANS data tells us and why false positives are now the biggest hidden risk facing defenders.

### **1. False positives are the top detection challenge in 2025**

According to the survey, 73% of organizations list false positives as their number one challenge in threat detection, which is a dramatic rise from last year.

This means that even as detection tools become more sophisticated, they’re still producing too much noise for analysts to manage effectively, resulting in SOC teams spending more time dismissing noise than analyzing true threats.

### **2. Frequency and severity are increasing**

More than 60% of respondents encounter false positives frequently or very frequently. Even more alarming: “very frequent” false positives jumped from 13% to 20% year-over-year. Detection engineering can’t keep up, and more alerts does not mean better detection.

### **3. The hidden cost: real threats slip through the cracks**

Every false positive consumes analyst time, and attackers know it. More noise creates more cover for lateral movement, credential abuse, and data exfiltration. High noise environments become high-risk environments.

### **4. Alert fatigue worsens staffing and retention issues**

SOC burnout is real. The survey highlights persistent skill and resource gaps, and alert fatigue is a major contributor. Even well-staffed teams can’t operate effectively if their tooling overwhelms them.

### **5. A shift is happening: teams want precision, not volume**

Teams don’t need another tool generating alerts, they need technology that identifies true threats with confidence and minimizes noise without sacrificing visibility. This is where advanced NDR plays a critical role.

Solutions like [Clear NDR](https://www.stamus-networks.com/clear-ndr?hsLang=en) use a combination of enriched network visibility, behavioral analysis, and high-confidence threat declarations to surface what matters and suppress what doesn’t.

Instead of adding to alert fatigue, [Declarations of Compromise® (DoC)](https://www.stamus-networks.com/blog/tired-of-alert-fatigue-how-declarations-of-compromise-doc-cut-through-the-noise-1?hsLang=en) help analysts focus on the risks that require real action.

### Why Precision NDR Is Essential for Cutting Through Alert Noise

The SANS 2025 Detection & Response Survey highlights a reality that SOC teams have felt for years: alert volume is no longer the metric that matters. In fact, more alerts often mean more noise, more investigation backlog, and more opportunities for real threats to slip by unnoticed. What defenders truly need is clarity, the ability to quickly distinguish meaningful activity from the constant hum of routine network behavior.

Traditional detection tools remain vital, but they were never designed to shoulder the full weight of today’s hybrid environments, encrypted traffic patterns, and attacker tactics that intentionally evade or overwhelm single-layer detection systems. When these tools operate alone, they often generate incomplete or ambiguous signals, forcing analysts to spend valuable time interpreting alerts rather than acting on them.

This is why Network Detection and Response (NDR) has become an essential counterpart in modern security operations. NDR provides a broader, cross-environment view of activity, helping teams validate or dismiss alerts more confidently by offering the context and behavioral insight other tools cannot. It adds a layer of independent visibility that transforms scattered signals into something understandable and actionable.

And while many NDR platforms help reduce noise, the most effective ones take it a step further by providing precise, transparent, and explainable detections that show analysts why something is considered suspicious or malicious. This kind of visibility isn’t just helpful, it’s foundational. Without transparency, even accurate alerts become another source of uncertainty. With it, security teams gain the confidence to respond faster, tune with precision, and trust the intelligence driving their decisions.

Ultimately, SANS’ findings point to a simple truth: SOC teams don’t need more alerts, they need precise ones, backed by deeper context and greater transparency. NDR delivers that missing layer, ensuring that defenders aren’t just notified, but truly informed. In environments where every second counts, clarity isn’t just a competitive advantage, it’s a critical requirement for modern cyber defense.

If you're interested in reading the full 2025 SANS Detection and Response Survey, you can [download it here](https://www.stamus-networks.com/hubfs/SANS%20Documents/2025_Survey_Detection-Response_Stamus.pdf). For more information on our Clear NDR solution, [visit our product page ](https://www.stamus-networks.com/clear-ndr?hsLang=en)or click the demo link, listed below the author bio.

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fwhat-the-2025-sans-detection-response-survey-reveals-false-positives-alert-fatigue-are-worsening%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fwhat-the-2025-sans-detection-response-survey-reveals-false-positives-alert-fatigue-are-worsening%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fwhat-the-2025-sans-detection-response-survey-reveals-false-positives-alert-fatigue-are-worsening%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fwhat-the-2025-sans-detection-response-survey-reveals-false-positives-alert-fatigue-are-worsening%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fwhat-the-2025-sans-detection-response-survey-reveals-false-positives-alert-fatigue-are-worsening%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Fwhat-the-2025-sans-detection-response-survey-reveals-false-positives-alert-fatigue-are-worsening%3Futm_medium%3Dsocial%26utm_source%3Demail)

![D. Mark Durrett](https://www.stamus-networks.com/hubfs/Stamus%202020/Images/Stamus_Mark.jpeg)

#### D. Mark Durrett

 Mark is the chief marketing officer (CMO) at Stamus Networks, where he has responsibility for go-to-market strategy and execution. Mark started his career as an electrical engineer and worked in digital circuit design of networking and telecom hardware for over a decade. He has over 25 years of experience leading marketing, product management and engineering for technology companies. Mark has served as the senior product and marketing executive at Netsertive, Emerging Threats, Overture Networks, Bell and Howell, Covelight Systems and Hatteras Networks. Mark resides in North Carolina, USA.

[**](https://www.linkedin.com/in/dmarkdurrett/) [** ](https://twitter.com/dmarkdurrett)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Stamus Networks: When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/hubfs/SN-Perimeter-Fails-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

### [When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

SentinelOne's "Edge Decay" research names the threat. Here's how network detection and response...

[![When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/hubfs/SN-EDR-Goes-Dark-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

### [When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

I've spent a significant part of my career participating in [NATO cyber defense exercises](https://www.stamus-networks.com/nato-ccdcoe-participation?hsLang=en) -...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.