DiagramsSame Taxonomy, Same Meaning?
The same three labels for an alert. On the third, the two functions are doing different work.
22 SEPTEMBER 2026 | DIAGRAM
In security, words drive purpose, and purpose drives the outcome. I have argued that before at the level of the whole program, where the choice between insider threat and insider risk decides what the program is able to do. This is the same problem one level down: a single alert, on a single desk, and three labels that look shared.
Security operations and insider threat detection classify an alert with the same labels, and because the labels are the same we tend to assume the work behind them is the same too. For two of them it is. For the third it is not, and the difference says a lot about what each function does.

A false positive is the same in both worlds: a rule fired on an event that was never an incident, and the remedy is tuning. A true positive is the same too: the rule proved effective, and the alert is escalated.
Benign positive is where they part, and the interesting thing is that both enter it through the same door: expected activity.
In security operations, expected means authorized, explicitly or by design, and authorized means harmless. The analyst does not decide anything. They verify that no adversarial activity actually occurred, and close.
In insider threat detection, expected does not necessarily mean authorized. Human behavior is partly predictable, and predictable is not in and of itself approved. The activity happened, nobody explicitly said yes, or no, and on a strict reading of the security policy it would count as a violation. A SOC would probably escalate it. The insider threat function often closes it, because the activity turns out to be legitimate, or because the impact is tolerable. It investigates when there is harm, or when the picture is still incomplete.
So in one world benign is verified. In the other it is decided.
That decision is not simply a classification. It is an assessment against the organization’s risk appetite, often made one alert at a time. And this is the part security operations does not carry: there, the risk belongs to someone else, to whoever authorized the activity, or to whoever set the appetite and the controls that follow from it. In insider threat operations, the threat and the risk are tied together, and the function absorbs both every day.
Which leaves the question I find most interesting. Who decides that a violation is benign? Risk? Compliance? The business? The honest answer is that very often it is the insider threat function itself, and rarely with anything in writing that says it may.
Worth asking at the next program review: was that authority ever given, or only assumed?
