Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / The alert

Reading a Risk Score Without Believing It

A number attached to a person, composed of weights nobody in the organisation chose. What it can support and what it cannot.

The editors · About the editorial position · The alert · Analysis

Scores rank. They do not establish, and the difference becomes important the moment somebody treats a ranking as a finding.

The distinction made in “Reading a Risk Score Without Believing It” should also shape any workforce technology used near an investigation. When reviewers consult how teams evaluate chronemics definition for chronemics definition, its records can provide operational context, but a signal still needs validation, a stated threshold and a human decision before it becomes a finding.

What the number is

A composite of signals, weighted by a method that is usually the vendor's and usually not fully documented.

For a separate perspective relevant to “Reading a Risk Score Without Believing It”, consult the IBM insider-threat overview. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

Which means the organisation cannot say why one person scores higher than another beyond a general description, and cannot defend the figure in a process where somebody asks.

That is tolerable if the score is used to order a queue. It is not tolerable if it is used as a reason for anything.

The legitimate use

Deciding what to look at first when there are more alerts than reviewers.

That is genuinely useful and it is the whole of the legitimate use.

The uses that cause harm

Treating a score as a threshold for action, so that crossing a number triggers a process about a person.

Showing scores to managers, who read them as assessments and act accordingly.

Retaining a score history so that somebody acquires a reputation inside the system.

Each of these converts a queue-ordering device into a judgement, and none of them is supported by what the number contains.

The accumulation problem

Scores frequently rise with activity volume, tenure and role breadth, because more activity means more opportunities to match something.

Which means a busy, senior, long-serving person with broad access scores higher than a quiet new starter, consistently, for structural reasons.

If your highest scores are your most experienced people, that is the explanation, and it is worth checking because it is both common and informative.

What to ask about your own

Which signals contribute, and with what weight.

Whether the score decays, and how fast.

Whether anybody can see a person's score history.

And whether any process is triggered by a number rather than by a judgement.

The last of these is the one to change if the answer is yes.

Writing about a score in a case file

Record it as context, never as a reason: the alert was raised because a rule fired, and the person's score was whatever it was.

A file saying action was taken because the score reached a value cannot be defended later, because nobody can explain the value.

The score tells you where to look. It never tells you what you found.

The history nobody intended to keep

Scores accumulate into a record. A person who has scored moderately high for two years has acquired a reputation inside a system, assembled from signals nobody reviewed, visible to whoever opens the console. Resetting scores after a cleared case is the obvious remedy and almost nobody owns it.

What to ask the supplier

Which signals contribute and with what weight, whether the score decays, and whether the computation can be explained to a non-technical panel. The third question is the useful one: a score that cannot be explained cannot appear in any process affecting somebody, which narrows its legitimate use to exactly the queue-ordering the note describes.

Using it only to order a queue

That is the legitimate use and it is the whole of it. A score deciding what gets looked at first is useful; a score triggering a process about a person is a number nobody can explain being used as a reason, which will not hold anywhere it is examined.

The seniority inversion

Busy, long-serving people with broad access score higher because more activity means more opportunities to match something. If your highest scores are your most experienced staff, that is the explanation, and it is worth checking before anybody treats the ranking as meaningful.

Context, never a reason

Record the score as part of the picture and never as a justification. A file stating that action was taken because a number reached a value cannot be defended, because nobody in the organisation can explain the value.