Nobody reads your alerts, and it isn't their fault
Alert fatigue is usually blamed on analysts. It's almost always a design problem — and design problems can be fixed.
Cyber security practitioner
I'm Steve Harris, a UK-based cyber security practitioner. I write about threat detection, incident response, and the practical engineering that keeps organisations standing when something goes wrong.
Most security problems are not exotic. They are ordinary gaps — an unmonitored log source, an alert nobody owns, a runbook that was never tested — that only become obvious once an incident is already underway. My work is about closing those gaps before they matter.
Building alerts that fire on real attacker behaviour rather than noise, and tuning the ones that already exist until analysts trust them again.
Triage, containment and clear-headed write-ups — including the executive summary that explains what happened without hiding behind jargon.
Practical reviews of tooling, logging coverage and process, with recommendations ranked by what actually reduces risk first.
Replace this section with your own words — see content/pages/home.md.
Alert fatigue is usually blamed on analysts. It's almost always a design problem — and design problems can be fixed.
The technical timeline is the easy part. The hard part is the one page that decides whether anything changes afterwards.
A working example of the markdown this site supports — and the three-step routine for publishing something new.
Security reviews, detection engineering and incident response support for teams that need senior help without a full-time hire.
Get in touch