← All terms

Alert Fatigue

Alert fatigue is the desensitization that sets in when people receive too many security alerts or prompts, causing real warnings to be ignored, dismissed, or approved on reflex.

Alert fatigue is what happens to human attention under a constant stream of warnings: the more alerts a person receives, the less each one means. Analysts tune out dashboards, employees dismiss pop-ups without reading them, and approval prompts get accepted on reflex because approving is the fastest way back to work. The term comes from medicine — monitor alarms that nurses learn to ignore — and transfers to security almost unchanged.

How it works

Fatigue builds wherever the ratio of noise to signal is high. In the security operations center, thousands of low-fidelity detections a day teach analysts that most alerts are false positives, so triage becomes skimming and real intrusions ride along with the noise. At the employee level, the same mechanism operates on MFA prompts, browser warnings, cookie banners, and training reminders: each unnecessary interruption trains people that interruptions are safe to dismiss. Attackers exploit the conditioned reflex directly — an MFA fatigue attack is nothing more than weaponized alert fatigue, bombarding a victim with push notifications until approving one feels like the only way to make them stop.

How to defend

  • Cut the noise before adding detections. Every alert that fires without requiring action erodes the credibility of the ones that matter. Tune, aggregate, and auto-close; measure false-positive rates per rule.
  • Make the remaining prompts meaningful. Number matching and context (location, app, device) turn an MFA approval from a reflex into a decision — the core of the defense in our MFA fatigue guide.
  • Ration employee-facing interruptions. Well-timed, specific security nudges outperform blanket warnings precisely because they are rare enough to still carry information.
  • Watch the human telemetry. Falling report rates or rising time-to-acknowledge are early indicators that fatigue is setting in — signals worth tracking alongside technical metrics in a human risk program.

Related terms

MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.Security Operations Center (SOC)A security operations center (SOC) is the team that monitors, detects and responds to security events — including the ones people report.Security NudgeA security nudge is a small, well-timed prompt — a banner, a warning, a reminder — that steers employees toward the safe choice without blocking them or requiring training.Human FirewallA human firewall is a workforce trained and measured to recognize, resist and report social engineering — the defensive layer technology cannot replace.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo