Black Hat USA 2026Startup City, Booth 5815 · Aug 4–6 · Mandalay Bay, Las VegasBook a booth demo

What does your triage queue cost?

Two numbers about your SOC — modelled against AIDR’s published, independently measured benchmarks.

Model it on your numbers.

Slide to match your SOC. Everything downstream uses AIDR’s published benchmarks — nothing hypothetical.

30,000
6

Model assumptions

200:1 noise reduction (LockNLock production) · 23× MTTR (K-Testbed) · 15 min manual triage per alert (industry assumption) · 160 analyst-hours per month · savings capped at 90% (published cost-efficiency benchmark) · $120,000 average analyst salary (ISC2 2024 survey).

Projected annual savings$648,000at least — capped at the published 90% cost-efficiency benchmark

Incidents your team actually touches

150/mo

down from 30,000 alerts — every one investigated first

Analyst capacity recaptured

5.4 FTE

7,463 analyst-hours/month freed from triage

Response speed

23× faster

MTTR vs. manual response — measured on K-Testbed

Fair questions.

Where do these benchmarks come from?

The 200:1 noise reduction was measured in a customer's production environment. The 23× response-time gain was independently benchmarked in a public-sector evaluation. The 15-minute manual-triage figure is an industry planning assumption — bring your own number to a demo and we'll rerun the model.

Does “capacity recaptured” mean fewer analysts?

No — it means triage stops consuming them. Teams redirect the recovered hours to threat hunting, hardening, and the investigations that genuinely need human judgment.

My alert volume spikes. Does the model still hold?

Yes — AIDR investigates every alert at any volume, nothing is sampled out. A spike raises the AI’s workload, not your team’s.

Is the 200:1 number guaranteed?

It’s a measured production figure, not a guarantee — your ratio depends on your alert mix. That’s exactly what a demo models on your own stack.