D3 Security · Security Operations Glossary
What Is Cost Per Alert?
A standalone glossary definition, part of the D3 Security Operations Glossary.
Definition
Cost per alert is the unit economics of triage: what it costs to bring one alert to a defensible disposition. The figure is only meaningful when read as a multiple of the analyst labor it displaces, and when priced at production volume, not pilot volume.
Triage labor is the largest cost in most security operations. Proper investigation of a single alert takes twenty to forty minutes of analyst time, worth roughly $20 to $45 at fully loaded rates. A SOC handling even a thousand alerts a day is therefore spending millions a year on work that an agentic system performs for a fraction of the cost.
That comparison is what makes cost per alert a useful number. On its own a per-alert price says nothing. Set against the labor it displaces, it becomes the clearest way to test whether an agentic SOC deployment pays for itself.
One caution about the inputs. The twenty-to-forty-minute window is an operating assumption, not a published benchmark. No government agency or peer-reviewed study publishes a minutes-per-alert figure, so anyone using one should say whose assumption it is. The loaded hourly rate is public, and it can be built from two federal datasets.
The labor baseline, from federal data
| Input | Figure | Source |
|---|---|---|
| Median wage, information security analysts | $124,910 per year, $60.05 per hour (May 2024) | BLS Occupational Outlook Handbook |
| Wages as a share of total employer cost | 70.1% for private industry workers (December 2025) | BLS Employer Costs for Employee Compensation |
| Fully loaded analyst rate | $85.66 per hour, $1.43 per minute | Derived from the two rows above |
| Fully loaded cost per analyst-year | About $178,000 at the federal 2,080-hour convention | Derived from the two rows above |
Run the assumption through that rate and twenty to forty minutes of triage costs $29 to $57. The $20 to $45 range above is the conservative reading of the same work. The arithmetic that follows holds either way, and it holds harder at the federal rate.
Reading the number as a multiple
The arithmetic gives usable thresholds. Against triage labor worth roughly $20 to $45 per alert:
- Below about $4.50 per alert: the business case starts working, on a tenfold return against displaced labor.
- At $2 or less: the case survives a skeptical finance review.
- At about $1: the case stops being a debate. For a SOC handling 1,000 alerts a day, a bill at that level stays inside the cost of the two to three analysts it frees.
That last threshold is worth checking with real numbers. A dollar an alert at a thousand alerts a day is $365,000 a year. Two analysts at the federal loaded rate cost $356,000. The comparison is that tight, and it is a comparison a CFO can rebuild without your spreadsheet.
These thresholds move with your inputs, and the method does not. Substitute your own loaded rate and your own alert volume, and the shape of the answer holds.
Also see:
Capacity Reallocation
Agentic SOC
The cost base most evaluations leave out
Detection is priced on ingested volume. Security operations is priced on people. Alerts price nothing on their own, which is why cost per alert has to be constructed before it can be compared.
The volume side is documented in places most buyers never look. Internet2, the higher-education and research networking consortium, states in its member SIEM program FAQ that licenses are “based on total daily volume of data indexed,” with tiers at 50GB, 100GB, 200GB, 500GB and 1000GB per day, and that the price per GB falls sharply as volume rises. Small SOCs pay the worst unit rate. Stanford University publishes an internal chargeback of $64 per GB of logs ingested per day, billed monthly, which is one of the few institutional ingest rates disclosed openly anywhere.
That cost base is compounding. The SANS SOC Survey has asked the same question three years running, and the share of SOCs that dump all incoming data into a SIEM without a retrieval or management plan has risen from 29% in 2023 to 38% in 2024 to 42% in the 2025 edition. SANS calls it “a trend that’s easy to justify today and hard to pay for tomorrow.”
The same 2025 survey reports the finding that explains why this term needs a definition at all: 42% of SOC staff do not know their SOC’s budget. A unit cost that nobody inside the function can state is a unit cost nobody is managing.
Why pilot pricing misleads
Two facts about this category’s cost base are underpriced in most evaluations. First, the rate buyers see today belongs to a market competing hard for share. Epoch AI, which maintains the most rigorous public tracker of inference prices, finds prices for a fixed performance level falling between 9x and 900x per year with a median of 50x, and states plainly that reduced profit margins “may explain some of the drops in price, but we didn’t find clear evidence for this.” That uncertainty is the exposure. A multi-year deployment is being costed against a rate that nobody can tie to a cost base.
Second, frontier models are generalists. They are remarkable at ingesting and extrapolating data, and they are not security operations experts. Handed a raw alarm, a generalist model does not know your environment, your log shapes, or your query languages, and it underperforms exactly where triage gets hard. Vendors that resell frontier tokens inherit both problems and pass them to the buyer, and the buyers who signed at pilot pricing discover this at renewal.
Four measured effects sit underneath that, and each one breaks the link between a headline token price and your actual bill.
- An agentic loop is not one prompt. A 2026 study of 500 tasks across eight frontier models, co-authored by Erik Brynjolfsson and Alex Pentland, found that agentic tasks consume 3,500 times the tokens of a single-round reasoning task and 1,200 times a multi-round chat. Input volume drives the cost, and prompt caching does not fix it, because the same accumulated context gets re-fed on every step.
- Thinking tokens bill at the output rate. Output is the most expensive line on any price sheet. Google’s own Gemini pricing page labels the column “Output price (including thinking tokens).” Epoch AI measures reasoning-model output lengths growing about 5x per year against 2.2x for non-reasoning models.
- Per-token price and per-task cost are different variables. Anthropic’s pricing documentation states that its newer tokenizer “produces approximately 30% more tokens for the same text.” A headline rate can hold flat while the bill climbs.
- Security-tuned inference carries a premium. OpenAI’s published price list puts a cyber-specialized model at $12.50 per million input tokens and $75.00 per million output tokens, roughly 2.5 times its general flagship on both sides. Purpose-built security inference costs more to run, whoever runs it.
Why per-token billing moves risk onto the buyer
Per-token pricing looks transparent. In an agentic workload it transfers three kinds of variance to the party least able to model them.
- The same task does not cost the same twice. In the 500-task study above, the most expensive run of a given task cost about twice the cheapest, with tail cases reaching 30 times. The models predicted their own token use with a correlation no higher than 0.39, and systematically underestimated it.
- Failure costs more than success. On the tasks that every model failed, models burned more tokens than on the tasks every model solved, because they have no reliable rule for stopping. The authors put it directly: users “still need to pay for the token costs even if the task fails.”
- Hidden reasoning is unauditable in principle. A May 2026 University of Tennessee paper in the cs.CR security literature shows that published schemes for auditing reasoning-token billing can be defeated, and summarises the structural problem in one line: “The opacity that creates the need for auditing is the same opacity that blocks it.” The authors tested academic auditing frameworks on public datasets and make no allegation against any provider. The point stands on its own. A buyer cannot verify tokens they never see.
Flat-rate pricing per alert moves that variance back to the party that can model it. That is the whole argument for the unit.
What uninvestigated alerts cost
An alert queue nobody works is usually discussed as a staffing complaint. The IBM Cost of a Data Breach Report 2025, based on Ponemon Institute fieldwork across 600 breached organizations, prices it instead.
- Detection failure carries a $900,000 premium. Breaches that an organization’s own teams and tools identified averaged $4.18 million. Breaches the attacker disclosed averaged $5.08 million.
- Speed is worth $1.14 million. Breaches identified and contained inside 200 days averaged $3.87 million. Past 200 days, $5.01 million.
- The clock is still measured in months. Mean time to identify and contain fell to 241 days, a nine-year low from a 287-day peak in 2021. Mean time to identify alone is 181 days.
- Detection and escalation is its own line item. It averaged $1.47 million per breach, the largest decline among the four cost categories tracked.
- Self-detection is improving. Internal teams and tools caught 50% of breaches in 2025, up from 42% in 2024 and 33% in 2023.
Those figures convert an unworked queue into a balance-sheet item, which is the form a budget conversation can actually use.
What to require from a vendor
Price every agentic SOC at the SOC you are becoming, not the one running the pilot:
- Your volume and your mix: the cost per alert at your actual alert profile.
- Ten times your volume: the same figure modeled at scale.
- Unsubsidized model rates: the bill when token pricing hardens.
- Retries and failed loops: who pays when an investigation loop fails and runs again.
- The ingest bill: the per-GB SIEM cost that your triage depth and retention window drive.
- The unit on every number: a cost figure with no stated currency and no stated denominator is not a price.
What independent benchmarks report
Accuracy claims in this category are cheap to make and rarely priced. Four recent evaluations are worth knowing before you read anyone’s marketing, including ours.
- Real SIEM data is harder than it looks. ExCyTIn-Bench, from Microsoft Security AI Research and Penn State and published at ICML 2026, runs agents against eight real attack chains across 57 Microsoft Sentinel log tables. The strongest frontier model reached 0.606 on a partial-credit reward. Query success correlated with reward at 0.86, so performance was gated by the ability to interrogate the data correctly.
- There is now a published human baseline. SIR-Bench, from Amazon Web Services, states that Tier-2 analysts typically achieve 85% to 90% true positive detection and 70% to 80% false positive rejection under time pressure. It also names the failure mode worth naming: “alert parroting,” where an agent restates the alert without discovering new evidence.
- Acting is not the same as judging. OpenSec found frontier incident-response agents containing threats in 62.5% to 100% of episodes while carrying false positive rates of 45% to 82.5%. The authors’ conclusion: “the calibration gap is not in detection but in restraint.”
- Published accuracy is unpriced. An audit of twelve agent benchmark papers found that none of the eight agent benchmarks disclosed inference cost in any form. The cost-disclosure mean was exactly zero. As the auditors put it, “the same accuracy at hundredfold cost is a different operating point.”
The independent number that does not exist
Worth saying plainly: there is no non-vendor benchmark for cost per alert. Government statistics publish analyst wages. Academic literature publishes alert volumes and agent accuracy. Institutional surveys publish SOC staffing and tooling. The IBM and Ponemon work prices breaches. None of them publishes a dollar cost to bring one alert to disposition. Every per-alert figure in circulation, including the one below, originates with a vendor. That is a reason to audit the method behind any per-alert figure, including ours.
The nearest public anchors are procurement records, and they are instructive. The City of London Corporation awarded a managed detection and response contract covering 3,150 endpoints for £64,800 over six months, which works out to £3.43 per endpoint per month. A UK government framework price list for a managed XDR service starts at £4.00 per host per month, with onboarding from £25,000. Those are transacted prices, not list prices, and they buy monitoring. Neither one tells you what a single alert costs to investigate. That gap is the reason the unit matters.
What Morpheus AI costs per alert
Morpheus AI delivers full-depth triage at $0.97 per alert, achieved through architecture and design. Customers rely on Morpheus AI triage in production every day at 98% triage accuracy. When Morpheus is uncertain, it defers to a human.
The figure sits below the threshold where the business case stops being a debate, and it is quotable because it comes from architecture, not from reselling somebody else’s tokens. Investigation runs through Attack Path Discovery against your own telemetry, so the work that drives the bill is deterministic where it can be. Morpheus is sold on cost per alert, time returned, and coverage gained, never on a promise to remove people.
Frequently asked questions
What is cost per alert?
The unit economics of triage: what it costs to bring one alert to a defensible disposition. It is meaningful when read against the analyst labor it displaces.
What is an alert worth in analyst time?
Proper investigation of a single alert takes twenty to forty minutes, worth roughly $20 to $45 at fully loaded rates. Treat the minutes as your own assumption, because no government or peer-reviewed source publishes a minutes-per-alert benchmark.
What does a fully loaded analyst hour cost?
About $85.66. The US Bureau of Labor Statistics puts the May 2024 median wage for information security analysts at $124,910 a year, or $60.05 an hour, and its Employer Costs for Employee Compensation release puts wages at 70.1% of total employer cost for private industry workers as of December 2025. Dividing one by the other gives $85.66 an hour, $1.43 a minute, and about $178,000 per analyst-year at the federal 2,080-hour convention.
What price makes the business case work?
Below about $4.50 per alert the case starts working on a tenfold return against displaced labor. At $2 or less it survives a skeptical finance review. At about $1 it stops being a debate.
Is there an independent benchmark for cost per alert?
No. Government, academic, and institutional sources publish analyst wages, alert volumes, ingest rates, and breach costs, and none of them publishes a dollar cost to triage one alert. Every per-alert figure in circulation originates with a vendor, so audit the method and the inputs.
Why price at ten times current volume?
Because subsidized model pricing and pilot volumes both flatter the figure. A deployment planned over several years should be costed at the volume and the rates you expect to face, not the ones on offer today.
Why does an agentic investigation cost so much more than a single prompt?
Because the loop re-reads its own context on every step. A 2026 study of 500 tasks across eight frontier models found agentic tasks consuming 3,500 times the tokens of a single-round reasoning task, with input volume driving the cost and prompt caching failing to remove it.
Do falling token prices solve this?
Not on their own. Epoch AI measures inference prices for a fixed performance level falling between 9x and 900x a year, median 50x, and excludes reasoning models from that analysis because they generate far more tokens. Reasoning output lengths are growing about 5x a year and thinking tokens bill at the output rate.
Who pays for retries and failed investigation loops?
That is a question to put to the vendor directly, because it is a common gap in per-alert pricing and it scales with volume. Published research finds that failed agent runs consume more tokens than successful ones, since the agent has no reliable rule for stopping.
What does failing to detect a breach cost?
The IBM Cost of a Data Breach Report 2025 puts breaches identified by an organization’s own teams and tools at $4.18 million on average, against $5.08 million when the attacker disclosed the breach. Containment inside 200 days averaged $3.87 million, against $5.01 million past 200 days.
What does Morpheus AI cost per alert?
Morpheus AI delivers full-depth triage at $0.97 per alert, achieved through architecture and design, at 98% triage accuracy in production. When Morpheus is uncertain, it defers to a human.
Why does reselling frontier tokens raise the price?
Because the vendor inherits both the subsidy risk and the generalist problem. A general-purpose model handed a raw alarm does not know your environment, your log shapes, or your query languages, so it costs more and performs worse where triage gets hard. OpenAI’s own price list puts its cyber-specialized model at 2.5 times the input and output price of its general flagship.
Is cost the only return worth counting?
No. The second return is capacity, meaning the hours recovered from manual triage that fund detection engineering, threat hunting, and projects that were never staffed. A deployment should be measured on both.
Related terms
Capacity Reallocation — The second return on agentic triage, in which recovered hours fund unstaffed security work.
Agentic SOC — A security operations model in which AI agents autonomously triage, investigate, and respond to alerts while human analysts supervise.
AI Alert Triage — Automated investigation and disposition of alerts at machine speed.
Triage Slop — Low-quality automated triage output that a black-box score can hide.
SOC Consolidation — Reducing the number of tools a security operations team has to operate and maintain.
Further reading
Morpheus AI Platform
Why fail-open matters
Cost per alert research
Book a demo
Last updated: July 2026