Survey: security products send average large organizations 17K malware alerts per week, only 19% of which are reliable
Survey says security products waste our time — For anyone who has freaked out when an antivirus alert popped up on their screen and spent time researching it only to find …
Context & Ripple Effects
This 2015 survey put a number on what security teams had long complained about: security tools generating far more signal than anyone can verify, with only about one in five alerts worth acting on. The coverage that followed kept validating the premise — a test of 250 Android antivirus apps found most could not reliably detect malware, and Google's own Play Protect ranked last among 15 scanners in a 2021 detection study.
The survey also sits awkwardly against an industry whose own testing practices were murky: allegations that Cylance used bogus malware to close deals exposed how little independent verification stood behind vendors' detection claims.
First-order effects
- Large organizations' security teams spend their week triaging 17,000 alerts of which 81% are noise — analyst hours, not attacker activity, become the binding constraint on response speed.
Second-order effects
- Buyers push vendors on verified detection rates rather than raw alert volume, forcing antivirus makers to submit to independent efficacy testing or lose deals to products that do.
Third-order effects
- If reliability stays this low, enterprise security consolidates around fewer high-fidelity platforms and built-in OS-level defenses get scrutinized as hard as third-party tools — Play Protect's last-place ranking shows defaults are no safe harbor either.
The trend: Security tooling is being re-judged on verified detection accuracy as alert fatigue erodes trust in volume-first antivirus products.