SecuritylabSeptember 14, 2026🇷🇺Translated from Russian

Context is Everything: How to Avoid Drowning in Security Incidents and Distinguish Employees from Attackers

The original headline reads: Context decides everything: how not to drown in incidents and distinguish an employee from an attacker.

Developer commits code at three in the morning — is this an anomaly or not? The answer lies not in technical signatures but in context, which determines whether a suspicious event counts as a critical incident requiring immediate response. The article examines how to configure filtering rules by embedding business-process context instead of simply tightening thresholds. It covers behavioral analysis setup, trust in neural networks, and, most importantly, how to avoid noise while still catching real attacks.

Why the system sees threats where none exist: the nature of false positives

False positives are not system errors or analyst mistakes. They signal either data overload, undocumented processes, or security specialists suffering from alert fatigue. For example, a gateway solution detects connections to non-standard addresses. Without an endpoint agent that sees exactly what the employee is doing, the system lacks data for proper evaluation and must flag even legitimate actions as suspicious. Analysts then receive thousands of alerts, each requiring manual review.

Another case involves an employee traveling from Novosibirsk to Moscow. The time zone shifts by four hours, yet the system does not know about the business trip. A policy flags the five a.m. login as a schedule deviation, triggering an unnecessary investigation. Adding context changes the picture: an employee requesting customer data may be routine until the system knows the same person is in the process of leaving the company, at which point the request becomes an incident.

Three levels of filtering: how not to confuse a regular employee with an insider or hacker

Context is built in three layers, each refining the previous one and eliminating legitimate events.

  • Level 1 — Process and regulation. Documented scenarios are encoded so the system ranks events by risk instead of discarding them. Legitimate actions receive low priority yet remain available as context for evaluating other activity.
  • Level 2 — Identification and access. Data from VPN logs, multi-factor authentication, gateways, and access journals are combined. When an employee reaches unusual resources, endpoint visibility from solutions such as Staffcop reveals exactly which files were opened, where data was sent, and with whom communication occurred.
  • Level 3 — Actions and job duties. A developer working with code is normal; the same developer exporting a customer database from a CRM system is a high-risk incident that should trigger immediate response and automatic access blocking.

The system must rank events by risk using employee profiles and typical behavior rather than treating every anomaly as an attack.

Behavioral analysis: help or new source of noise

UEBA attempts to detect anomalies without manually writing thousands of rules, yet classical statistical approaches compare everyone against a single norm and therefore generate many false positives. Modern systems can group employees by similar tasks, but configuration errors still cause alert floods. Machine-learning models require quality training data, continuous analyst feedback, and careful handling of sensitive information. External neural networks pose additional risks because logs, personal data, and infrastructure details leave the organization’s perimeter.

Correct operation occurs only after training. The system initially produces thousands of anomalies; analysts confirm most as false, and only after several feedback cycles does performance stabilize. Models should be trusted as a narrowing stream of alerts, never blindly. Any configuration must reflect actual company processes.

Metrics: how to evaluate system performance without self-deception

Chasing the number of registered incidents is counterproductive. Effectiveness is measured by quality and the cost of handling alerts:

  • Overall reduction in false positives — the primary KPI. Dropping from 10,000 daily events with 9,900 false to 100 events with only 30 false shows the system now accounts for real business processes.
  • Speed of detection and remediation (MTTD/MTTR) reflects both system performance and process maturity, including backups and regulator interaction procedures.
  • Time and frequency of administration — hours spent daily verifying system health. Excessive maintenance creates blind spots during which incidents can occur undetected.

Small business: building protection without a team of analysts

Large organizations have SOC teams and dedicated budgets. Smaller companies rely on one or two specialists covering monitoring, tuning, and response. The recommended approach starts from consequences:

  1. Begin collecting logs from all services without attempting immediate detection; the archive provides a foundation for later analysis. Tools such as Staffcop with ready-made policies allow quick deployment.
  2. Identify the highest risks by asking leadership which incident would end the company or lead to personal liability.
  3. Configure policies against those specific risks using the collected data, gradually closing the most dangerous scenarios.
  4. Communicate with business managers and HR, who understand undocumented processes and can help avoid breaking working workflows while covering critical gaps.

Every security system embodies a trade-off: wider capture produces more noise; narrower focus raises the chance of missing an attack. Balance is achieved through context, not through the number of agents or licenses purchased. Technology evolves, yet the core problem remains: systems cannot differentiate a deadline from data theft or a business trip from an anomaly. Only humans who understand real company processes can make that distinction accurately.

Related articles

SecuritylabOther

Teenage Smartphone Addiction: Causes, Consequences, and Treatment Approaches

Smartphone use has become an integral part of adolescent life, but problematic usage patterns rather than device ownership itself are the focus of concern. Medical experts avoid the term smartphone addiction and instead address issues like disrupted self-control, social media overuse, and gaming disorder that interfere with sleep, studies, relationships, and mental health. Data from Pew Research indicates nearly 50% of U.S. teens aged 13-17 are online almost constantly, while CDC findings link four or more hours of daily screen time to elevated anxiety and depression symptoms. Family digital habits strongly influence teen behavior, and rigid bans often fail without addressing underlying issues such as boredom, anxiety, or social isolation. Parents are advised to track specific disruptions over a week and consider professional help when signs of depression, bullying, or self-harm appear alongside device overuse.

HabrOther

VK WorkSpace Federation Enables Secure Multi-Organization On-Premise Messaging Without Infrastructure Merge

VK Tech has released federation capabilities for its VK WorkSpace corporate messenger that connect independent On-Premise installations while preserving each organization's full control over data, administration, and security policies. The feature, first piloted in November 2025 and expanded in the July 2026 26.2 release, supports multi-party chats across more than two separate environments. Federation relies on mutual trust establishment and per-user access grants rather than full directory replication or proxy access to a single host instance. Each participating organization maintains local copies of messages, files, and chat metadata, allowing continued access even if a partner installation becomes unavailable. The architecture deliberately avoids both centralized hosting and open protocols such as Matrix to keep changes to the existing messenger core minimal. Administrators retain independent levers to create or revoke trusts and to limit which employees may communicate externally.

AntiMalwareOther

Sergey Volkov of Cloud.ru Named Top CISO in Russian IT Sector Ranking

Sergey Volkov, Director of the Cyber Protection Center at Cloud.ru, has secured first place in the information security category of the annual Top-1000 Russian Managers ranking. The ranking, published by the Association of Managers in the Kommersant newspaper since 2001, is compiled through peer evaluations by top executives followed by review from expert commissions. Volkov oversees information security strategy and operations for Cloud.ru, and his top position reflects professional recognition of his leadership results. The Association also analyzed broader achievements among laureates and identified key trends in Russian management. Artificial intelligence adoption for business process optimization appeared in 80 percent of reviewed accomplishments. Client orientation through user experience analysis and personalized solutions ranked second, while operational efficiency via cost reduction, automation, and digitalization took third place.

AntiMalwareOther

Russia Hands Down First Conviction Under New Criminal Article for Online Drug Propaganda

A resident of Orenburg became the first person in Russia to receive a criminal sentence under Article 230.3 of the Criminal Code, which criminalizes online drug propaganda following repeated administrative violations. The man was fined 100,000 rubles and had his mobile phone confiscated after he printed and posted leaflets containing a QR code that directed users to job advertisements linked to drug distribution. The scheme began when he was recruited via messenger to place the leaflets for 10 rubles each, without realizing the content involved narcotics-related vacancies. Prior to this case, the individual had already been sanctioned twice within the same year for illegal drug advertising, allowing prosecutors to escalate the matter to the new criminal provision that took effect on 1 March. The court considered his prior record as a recidivism aggravating factor yet imposed the minimum fine after he admitted guilt, expressed remorse, and cooperated with investigators. The ruling has already entered into force, marking the initial application of the statute that permits penalties up to two years of imprisonment or fines between 100,000 and 300,000 rubles.