Securitylab•September 14, 2026•🇷🇺Translated from Russian

Context is Everything: How to Avoid Drowning in Security Incidents and Distinguish Employees from Attackers

The original headline reads: Context decides everything: how not to drown in incidents and distinguish an employee from an attacker.

Developer commits code at three in the morning — is this an anomaly or not? The answer lies not in technical signatures but in context, which determines whether a suspicious event counts as a critical incident requiring immediate response. The article examines how to configure filtering rules by embedding business-process context instead of simply tightening thresholds. It covers behavioral analysis setup, trust in neural networks, and, most importantly, how to avoid noise while still catching real attacks.

Why the system sees threats where none exist: the nature of false positives

False positives are not system errors or analyst mistakes. They signal either data overload, undocumented processes, or security specialists suffering from alert fatigue. For example, a gateway solution detects connections to non-standard addresses. Without an endpoint agent that sees exactly what the employee is doing, the system lacks data for proper evaluation and must flag even legitimate actions as suspicious. Analysts then receive thousands of alerts, each requiring manual review.

Another case involves an employee traveling from Novosibirsk to Moscow. The time zone shifts by four hours, yet the system does not know about the business trip. A policy flags the five a.m. login as a schedule deviation, triggering an unnecessary investigation. Adding context changes the picture: an employee requesting customer data may be routine until the system knows the same person is in the process of leaving the company, at which point the request becomes an incident.

Three levels of filtering: how not to confuse a regular employee with an insider or hacker

Context is built in three layers, each refining the previous one and eliminating legitimate events.

  • Level 1 — Process and regulation. Documented scenarios are encoded so the system ranks events by risk instead of discarding them. Legitimate actions receive low priority yet remain available as context for evaluating other activity.
  • Level 2 — Identification and access. Data from VPN logs, multi-factor authentication, gateways, and access journals are combined. When an employee reaches unusual resources, endpoint visibility from solutions such as Staffcop reveals exactly which files were opened, where data was sent, and with whom communication occurred.
  • Level 3 — Actions and job duties. A developer working with code is normal; the same developer exporting a customer database from a CRM system is a high-risk incident that should trigger immediate response and automatic access blocking.

The system must rank events by risk using employee profiles and typical behavior rather than treating every anomaly as an attack.

Behavioral analysis: help or new source of noise

UEBA attempts to detect anomalies without manually writing thousands of rules, yet classical statistical approaches compare everyone against a single norm and therefore generate many false positives. Modern systems can group employees by similar tasks, but configuration errors still cause alert floods. Machine-learning models require quality training data, continuous analyst feedback, and careful handling of sensitive information. External neural networks pose additional risks because logs, personal data, and infrastructure details leave the organization’s perimeter.

Correct operation occurs only after training. The system initially produces thousands of anomalies; analysts confirm most as false, and only after several feedback cycles does performance stabilize. Models should be trusted as a narrowing stream of alerts, never blindly. Any configuration must reflect actual company processes.

Metrics: how to evaluate system performance without self-deception

Chasing the number of registered incidents is counterproductive. Effectiveness is measured by quality and the cost of handling alerts:

  • Overall reduction in false positives — the primary KPI. Dropping from 10,000 daily events with 9,900 false to 100 events with only 30 false shows the system now accounts for real business processes.
  • Speed of detection and remediation (MTTD/MTTR) reflects both system performance and process maturity, including backups and regulator interaction procedures.
  • Time and frequency of administration — hours spent daily verifying system health. Excessive maintenance creates blind spots during which incidents can occur undetected.

Small business: building protection without a team of analysts

Large organizations have SOC teams and dedicated budgets. Smaller companies rely on one or two specialists covering monitoring, tuning, and response. The recommended approach starts from consequences:

  1. Begin collecting logs from all services without attempting immediate detection; the archive provides a foundation for later analysis. Tools such as Staffcop with ready-made policies allow quick deployment.
  2. Identify the highest risks by asking leadership which incident would end the company or lead to personal liability.
  3. Configure policies against those specific risks using the collected data, gradually closing the most dangerous scenarios.
  4. Communicate with business managers and HR, who understand undocumented processes and can help avoid breaking working workflows while covering critical gaps.

Every security system embodies a trade-off: wider capture produces more noise; narrower focus raises the chance of missing an attack. Balance is achieved through context, not through the number of agents or licenses purchased. Technology evolves, yet the core problem remains: systems cannot differentiate a deadline from data theft or a business trip from an anomaly. Only humans who understand real company processes can make that distinction accurately.

Related articles

Habr•Other

Why Defending a Company Costs Millions While Attacks Can Succeed for Just Hundreds of Dollars

In the latest episode of Belyaev Podcast, CISO Vyacheslav Kasimov of Tochka Bank and Boris Evdokimov of ASNA pharmacy chain discussed the persistent asymmetry in cybersecurity spending. Attackers increasingly rely on affordable cloud services, automation, and rented infrastructure, while defenders must invest heavily in monitoring, access controls, backups, and skilled teams. The experts stressed that the absence of known breaches does not equal security, as undetected incidents or delayed discovery remain common risks. They advocated shifting from a "no" culture to risk-based decision making that helps business leaders understand potential losses, mitigation costs, and residual risk. The conversation also covered responsible use of AI in SOC operations and the long-term damage caused by loss of customer trust after incidents.

AntiMalware•Other

Beeline Offers One Month Free Access to Six Services for Prepaid Customers

Beeline has launched a promotional campaign allowing home users on prepaid plans to try up to six digital services for free over 30 days. The offer, tied to the operator's second annual Cellular Independence Day, runs from October 2 to October 9 and includes services such as Virtual Assistant PRO, unlimited mobile data, internet sharing without speed reduction, custom network name display, 250 GB of cloud storage, and access to over 650,000 e-books and audiobooks. Each selected service activates its own free period starting from the moment of connection and deactivates automatically afterward. Customers already paying for four or more of the listed services will receive 300 bonus rubles for communication instead. The unlimited data option is unavailable in the Chukotka Autonomous Okrug and Norilsk. Activation is handled exclusively through the Beeline mobile app, and users with existing paid subscriptions to any service cannot activate the free trial version of the same service.

Habr•Other

Enterprise-Grade Web Protection on a Budget: How Cloud WAF Lowers Barriers for SMBs

A new overview from Reg.cloud explains how cloud-based Web Application Firewalls reduce the cost and complexity of protecting websites, APIs, and web applications for small and medium-sized Russian businesses. According to Positive Technologies data cited in the article, 75% of successful web application attacks in 2025 disrupted organizational operations, while 82% of SMBs faced cyber incidents in the past year. The piece details the differences between traditional on-premises WAF deployments and cloud offerings, emphasizing ready-made protection profiles for CMS platforms, SaaS services, and digital agencies. It outlines a three-stage operational model covering preparation, DNS-based traffic redirection, and ongoing policy tuning that can be handled by existing DevOps or development teams without dedicated security staff. The service currently offers a free tier supporting up to three applications at 50 requests per second, along with seven preconfigured security profiles and dual audit/blocking modes. The article concludes by stressing that WAF remains only one layer and must be combined with patching, access controls, and separate DDoS or anti-bot solutions.

AntiMalware•Other

Yandex B2B Tech Integrates Hybrid Full-Text and Vector Search in Single YDB Query

Yandex B2B Tech has added hybrid search to its YDB database, allowing full-text and vector approaches to run together inside one SQL query. The update helps small and medium businesses as well as large corporations locate exact document identifiers while also matching semantic meaning in descriptions, even when wording differs. Full-text search handles precise elements such as policy numbers, codes, and names, whereas vector search identifies conceptual similarity. Results from both methods are merged and ranked within the same transaction, keeping all data inside a single database instance. This removes the need to maintain a separate search engine and vector store or to reconcile information between them. The technology is aimed at chatbots, recommendation systems, and AI assistants that process technical content where both exact codes and human-readable problem descriptions matter equally. Hybrid search is now available in the on-premises YDB 26.3 release and in the cloud-based Managed Service for YDB.