Skip to content

Ordfall · Newsroom

From Alert Volume to Decision Quality

More detection is not more security. A queue nobody can read produces the same blindness as no detection at all, with the difference that it consumes a budget and looks like prudence.

Published
Section
Security
Reading
5 min read
Signed
Ordfall

A detection programme is easy to justify and easier still to expand. Every new data source looks like added visibility; every new rule looks like one gap fewer. Taken alone, each addition is defensible, which is exactly why none of these decisions is argued rigorously: none of them, on its own, appears to deserve an argument.

The product of a detection programme, however, is not alerts. It is decisions: someone who looks, understands, and acts in time. An alert is an input, and inputs in excess become waste when the capacity to decide is fixed, human and organised in shifts. A queue nobody can read produces the same blindness as having no detection at all — with the difference that it consumes a budget, occupies people, and looks like prudence from the outside.

Coverage is a metric you can buy

Coverage is attractive because it is purchasable and presentable: more sources, more rules, one more line filled in on a matrix. Nothing in that metric measures whether anything was decided. And the incentive runs one way only: adding a rule is safe and looks like diligence, while removing one requires someone to state, with their name attached, that this class of event does not deserve attention. Nobody wants to be that person after an incident. So the queue only grows, and it grows through an accumulation of prudent decisions.

The result is that the real triage policy stops being written and becomes tacit. Analysts learn which alerts are skimmed and which are genuinely opened. That knowledge is real, it is usually correct, it is recorded nowhere, it has never been reviewed by anyone, and it leaves when they leave. It is a decision not to act on an entire class of events, taken by default rather than by design — precisely the decision the organisation believed it had avoided by buying more detection.

The product of the programme is the last line

Illustrative schematic

  1. 01 Observed volume

    Everything the sources emit, before any rule. It grows with each source added.

  2. 02 Alert

    What a rule decided deserves attention. Still an input, and inputs in excess are waste.

  3. 03 Case

    Events grouped by what happened rather than by what fired.

  4. 04 Decision

    Someone looked, understood and acted in time. It is the only product the programme has.

Coverage is measured at the first line; the programme is judged at the last. The bands are geometry, not proportion: there is no reduction rate, volume or triage metric here — none of those numbers exists to be published.

The case, not the event

The unit of work ought to be the case, not the event. An event says what happened at one point; a case says what is happening to one entity — an identity, a machine, a customer, a transaction path. Correlation is what turns a run of individually unremarkable events into a shape someone can recognise. Without it, every analyst rebuilds the context by hand, every time, and that reconstruction becomes the work: the most expensive part, the slowest part, and the part nobody records.

Ten unrelated events cost ten readings and produce no conclusion. The same ten, gathered around one identity, usually produce one.

Treating the case as the unit has concrete engineering consequences. Enrichment happens before the human rather than during: who is this identity, what does it normally do, what does it have access to, and where would that lead. Deduplication and grouping are code, not analyst discipline. And the case carries its own history, so recurrence becomes visible — because a queue with no memory charges the full price of investigation every time the same problem repeats, and nobody notices that it is the same.

Ordering by material consequence

Severity is normally assigned by whoever wrote the detection, at the moment they wrote it, in the abstract. The ordering the operation needs is a different one: what would have to be true for this to matter, and how much it would matter. Four questions give an alert its place in the queue, and the first removes more items than any tuning tool ever will:

  • What does this alert let someone decide? If the only available response is to record it, it does not belong in a human queue.
  • What does it reach, if it is true: which data, which system, which customer. Consequence belongs to the asset, not to the rule.
  • What is the action, and who has authority to take it without asking permission? Without that, the alert is a request for a meeting.
  • Have we seen this before, and what was done? Without that answer, every occurrence costs what the first one cost.

It follows that a good share of detection should exist without ever reaching a person: as a figure in a report, as a trend that is watched, as an automated response with a record. Deciding what does not reach a human is an engineering activity with an owner and a review date, exactly like calibrating a threshold — and it has to be recorded, because a detection that stopped waking anyone is a change to the control. Silencing without recording is removing a protection without telling anyone it was ever there.

The human cost is a design cost

Fatigue is not a topic for the engagement survey; it is an engineering constraint. Attention degrades with volume in predictable ways, and the queue is a system with fixed human capacity, a night shift, and days when people are missing. A design that requires sustained vigilance over a noisy stream is a design that assumed, without checking, a property people do not have. The bill arrives as attrition, and attrition takes with it the tacit triage knowledge described above. The loop closes badly: the noisier the queue, the faster you lose the people who knew how to ignore it correctly.

No detection programme is better than the worst hour of the shift that reads it.

The measure we would propose is uncomfortable because it cannot be bought: how many cases produced a decision, how long passed between the event and that decision, and what share of the queue no human ever read. Those figures are almost never collected, and the reason is understandable — they describe the programme as it is rather than as it was funded. They are also the only ones that answer the question that matters. Detection that does not end in a decision is not a defence: it is documentation of an event, produced at high cost, to be read on the worst possible day.

Ordfall

Ordfall