D3 Security · Security Operations Glossary
What Is Effective Alert Risk?
A standalone glossary definition, part of the D3 Security Operations Glossary.
Definition
Effective Alert Risk (EAR) is the score a governed agentic SOC assigns at stage 2 of the alert lifecycle: the risk this alert poses to your environment specifically, computed from factors like exposure, identity blast radius, data proximity, and threat-intel match.
The score is real and it earns its place: it ranks the queue so humans see what matters first. The governance question is what sits behind it. In a governed agentic SOC, any analyst can open a disposition and see the breakdown: the factors, the weight each one carried, and the evidence behind each factor, including evidence that cut against the verdict. The reasoning is the interface, and it is also the audit trail.
Why the breakdown matters
That is the difference between auditable reasoning and a black-box score. A score you can’t open is a verdict you can’t defend, to your own analysts at handoff, to a client asking why their host was isolated, or to a regulator asking why an alert was closed. When you evaluate any platform in this category, ask to open the disposition. Then ask to see the contradicting evidence. Where it’s buried, so is your answer at audit time.
Also see:
Governed Agentic SOC
AI Alert Triage
Where EAR sits in the alert lifecycle
EAR is computed at stage 2 of the eight-stage alert lifecycle, Score and Dispose. It follows the read-only investigation that Attack Path Discovery runs at stage 1, and it precedes the narrative, recommendation, and response stages. Stage 2 is a recoverable validity gate: weak evidence never closes an alert, and dispositions can be reopened. The score ranks; it does not silently close.
How is EAR built in Morpheus?
In Morpheus, EAR ships with the breakdown open: factors, weights, evidence, and counter-evidence, one click from every disposition. The Cybersecurity Triage Reasoning Graph carries the investigative judgment behind the score at L2 depth on up to 95% of alerts in under two minutes. Because the breakdown is one click away, the same score that ranks the queue also produces the record you defend at audit time.
Frequently asked questions
What is Effective Alert Risk (EAR)?
The risk score a governed agentic SOC computes for each alert against your environment, from factors like exposure, identity blast radius, data proximity, and threat-intel match. It is assigned at stage 2 of the eight-stage alert lifecycle, and in a governed platform it opens to its full breakdown.
What factors go into EAR?
Factors like exposure, identity blast radius, data proximity, and threat-intel match. Each factor carries a weight, and each weight is backed by the evidence behind it, including evidence that cut against the verdict.
Why does the EAR breakdown matter?
Because a score you can’t open is a verdict you can’t defend, to your own analysts at handoff, to a client asking why their host was isolated, or to a regulator asking why an alert was closed. The breakdown makes the reasoning the interface, and the audit trail.
What is the difference between EAR and a black-box risk score?
EAR opens to the factors, the weight each one carried, and the evidence behind each factor, including contradicting evidence. A black-box score gives you a number with no way to inspect or defend it. When you evaluate any platform, ask to open a real disposition, then ask to see the contradicting evidence.
Where does EAR fit in the alert lifecycle?
EAR is computed at stage 2, Score and Dispose, after read-only Attack Path Discovery investigation at stage 1 and before the narrative and response stages. It ranks the queue so humans see what matters first.
Can an EAR disposition be reopened?
Yes. Stage 2 is a recoverable validity gate: weak evidence never closes an alert, and dispositions can be reopened. The score never converts uncertainty into a closed case.
Does EAR close alerts automatically?
No. Weak evidence never closes an alert, at any stage, in any autonomy mode. EAR ranks and dispositions the queue; it does not silently close cases on thin evidence.
Related terms
Governed Agentic SOC — The operating model that computes EAR and opens its breakdown.
AI Alert Triage — Automated investigation and disposition of alerts at machine speed.
Cybersecurity Triage Reasoning Graph — The reasoning engine that carries the judgment behind the score.
Triage Slop — Low-quality automated triage output that a black-box score can hide.
Further reading
Why fail-open matters
Attack Path Discovery
Book a demo
Last updated: July 2026