Alert Fatigue Calculator
Quantify analyst alert fatigue from queue depth, false-positive rate and shift utilisation, and estimate alerts left untouched.
Inputs
Handovers, meetings, documentation and breaks consume 25–35% of any shift.
Alert Fatigue Index
59.5/ 100
Fatigue Risk Level
High — triage quality is already degrading
Queue Load vs Capacity
116.7%
Alerts per Analyst per Hour
7.00alerts/h
Alerts Left Unworked per Shift
24alerts
Hours per Shift Spent on False Positives
4.90hours
Highest-Value Intervention
Queue exceeds capacity — automate triage or add a seat before tuning anything else
Step by step
Values used
Alerts arriving per shift = 240 alerts; Analysts on the shift = 3 analysts; Shift length = 8 hours; Average minutes to triage an alert = 7 minutes; False-positive rate of the alert stream = 75 %; Alerts closed automatically by SOAR = 30 %; Realistic triage utilisation of the shift = 70 %
Alert Fatigue
Queue load = alerts per analyst × minutes per alert ÷ (shift hours × 60 × utilisation). Fatigue index = 0.45 × (load ÷ 2) + 0.35 × false-positive rate + 0.2 × scaled hourly arrival rate.
Unworked backlog
Unworked alerts = (required minutes − available minutes) ÷ minutes per alert, floored at zero.
Alert Fatigue Index
= 59.5 / 100
Fatigue Risk Level
= High — triage quality is already degrading
Queue Load vs Capacity
= 116.7
Alerts per Analyst per Hour
= 7.00 alerts/h
Alerts Left Unworked per Shift
= 24 alerts
Hours per Shift Spent on False Positives
= 4.90 hours
How it works
The index blends three independent drivers of fatigue: whether the queue physically fits in the shift, how much of the work turns out to be pointless, and how frequently interruptions arrive. Load is halved before weighting so that 200% of capacity, not 100%, maxes out that component. Fatigue is measurable and it predicts missed intrusions: when the queue exceeds capacity, analysts triage by closing the cheapest alerts first, which is exactly the behaviour a low-and-slow attacker relies on.
Formulas
Alert Fatigue
Queue load = alerts per analyst × minutes per alert ÷ (shift hours × 60 × utilisation). Fatigue index = 0.45 × (load ÷ 2) + 0.35 × false-positive rate + 0.2 × scaled hourly arrival rate.
- load
- Required triage minutes as a percentage of usable shift minutes
- utilisation
- Fraction of the shift genuinely available for triage, typically 65–75%
- false-positive rate
- Share of alerts that close as benign
Unworked backlog
Unworked alerts = (required minutes − available minutes) ÷ minutes per alert, floored at zero.
- required minutes
- Triage minutes the incoming queue demands
- available minutes
- Usable triage minutes on the shift
Frequently Asked Questions
How is Alert Fatigue calculated?
Queue load = alerts per analyst × minutes per alert ÷ (shift hours × 60 × utilisation). Fatigue index = 0.45 × (load ÷ 2) + 0.35 × false-positive rate + 0.2 × scaled hourly arrival rate. The index blends three independent drivers of fatigue: whether the queue physically fits in the shift, how much of the work turns out to be pointless, and how frequently interruptions arrive. Load is halved before weighting so that 200% of capacity, not 100%, maxes out that component.
Why does Alert Fatigue matter?
Fatigue is measurable and it predicts missed intrusions: when the queue exceeds capacity, analysts triage by closing the cheapest alerts first, which is exactly the behaviour a low-and-slow attacker relies on.
What values do I need to enter?
This calculator takes 7 inputs: Alerts arriving per shift, Analysts on the shift, Shift length, Average minutes to triage an alert, False-positive rate of the alert stream, Alerts closed automatically by SOAR, Realistic triage utilisation of the shift. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why cap utilisation below 100%?
No analyst triages for eight uninterrupted hours. Shift handover, case documentation, escalation calls, training and breaks reliably consume 25–35%, so a plan built on 100% utilisation is short-staffed by a third on day one.
Is a high false-positive rate always the problem?
Not always, but it is usually the cheapest thing to fix. If load is already above capacity, tuning alone will not save you — the arithmetic says you need automation or another seat as well.