Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Home / The alert

What an Alert Is and Is Not

A signal that a rule matched, produced by a system with no knowledge of context. Treating it as an accusation is the first and most consequential error.

The editors · About the editorial position · The alert · Explainer

An alert says that a pattern occurred which somebody once decided was worth looking at. That is the whole of its content, and everything beyond it is inference belonging to whoever does the inferring.

The distinction made in “What an Alert Is and Is Not” should also shape any workforce technology used near an investigation. When reviewers consult employee monitoring software for employee monitoring software, its records can provide operational context, but a signal still needs validation, a stated threshold and a human decision before it becomes a finding.

What it actually tells you

That a defined condition was met: a volume threshold crossed, a file type sent somewhere, an access outside a baseline, a sequence of actions matching a pattern.

For a separate perspective relevant to “What an Alert Is and Is Not”, consult the CISA insider-threat mitigation resources. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

That the system recorded it correctly, which is usually but not always true.

Nothing about intent, nothing about circumstances, and nothing about whether the person had a perfectly good reason that the system has no way to know.

The language problem

Products describe alerts as risks, and people as risky. A dashboard showing a named individual with a rising score communicates something the underlying data does not support: that this person is a threat, in some stable sense, rather than that an activity pattern matched a rule last Tuesday.

The vocabulary matters because it shapes what happens next. A reviewer who opens an item labelled high-risk user has already been told the conclusion. One who opens an item labelled activity requiring context has been told what the item is.

Several organisations rename these deliberately and report that it changes how reviewers write their notes. That is a small intervention with a disproportionate effect, and it costs nothing.

Where the inference actually happens

Not in the system. In the person reading it, within the first minute, usually before they have looked at anything.

That first impression then shapes what evidence gets sought: somebody who has decided this looks suspicious will look for confirmation, and will find some, because almost any week of anybody's activity contains things that look odd in isolation.

This is ordinary and it is why the process matters more than the analyst's judgement. The later notes on decision thresholds and evidence standards exist to constrain that first minute.

What the alert is for

Prompting a question, not answering one.

The right disposition toward a new alert is that something happened which may have an entirely ordinary explanation, and the fastest route to finding out is usually to establish the context rather than to gather more evidence.

In most organisations the fastest route is to ask somebody who knows what the team was doing that week, which the preliminary review note covers and which resolves a substantial share before anybody is named.

The word that sets the tone

Products and dashboards label people rather than events, and a reviewer who opens an item headed high-risk user has been handed a conclusion before seeing anything. Several organisations rename these fields to describe the activity instead, and report that it changes how reviewers write. It is a free intervention and it operates on the only part of the system that actually forms judgements.

What a reviewer should write first

Before any assessment: what the rule was, what it observed, and what would need to be true for this to be entirely ordinary. The third item is the one that keeps the enquiry honest, because it forces the innocent explanation to be articulated while it is still easy to check rather than after a view has formed.

Reading one as a subject would

Open the alert record and ask what it says about a person as against what it says about an event. If the first is longer than the second, the record is doing something it was not built for, and that drift usually begins in the product's own vocabulary rather than in anybody's intention.

Where the inference actually forms

In the reviewer, in the first minute, before anything has been examined. Everything procedural in this collection exists to constrain that minute, because the system itself forms no view at all and the person reading it forms one immediately.

For the file: An alert records that a rule matched. It does not record a concern, and the distinction should survive into every note written about it.