/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Survey: security products send average large organizations 17K malware alerts per week, only 19% of which are reliable

Survey says security products waste our time  —  For anyone who has freaked out when an antivirus alert popped up on their screen and spent time researching it only to find …

Ars Technica Robert Lemos

Context & Ripple Effects

This 2015 survey put a number on what security teams had long complained about: security tools generating far more signal than anyone can verify, with only about one in five alerts worth acting on. The coverage that followed kept validating the premise — a test of 250 Android antivirus apps found most could not reliably detect malware, and Google's own Play Protect ranked last among 15 scanners in a 2021 detection study.

The survey also sits awkwardly against an industry whose own testing practices were murky: allegations that Cylance used bogus malware to close deals exposed how little independent verification stood behind vendors' detection claims.

First-order effects

  • Large organizations' security teams spend their week triaging 17,000 alerts of which 81% are noise — analyst hours, not attacker activity, become the binding constraint on response speed.

Second-order effects

  • Buyers push vendors on verified detection rates rather than raw alert volume, forcing antivirus makers to submit to independent efficacy testing or lose deals to products that do.

Third-order effects

  • If reliability stays this low, enterprise security consolidates around fewer high-fidelity platforms and built-in OS-level defenses get scrutinized as hard as third-party tools — Play Protect's last-place ranking shows defaults are no safe harbor either.

The trend: Security tooling is being re-judged on verified detection accuracy as alert fatigue erodes trust in volume-first antivirus products.