← Cybersecurity & OT Security Studio
Concept Explainer · Cybersecurity

False Positive vs. False Negative

One wastes an analyst's time on an alert that fired for nothing. The other lets a real attacker walk past a control that never made a sound — and the two are connected in a way most people miss.

Every detection control — a SIEM correlation rule, an EDR agent, an IDS signature, a SOC analyst reading a queue — makes a binary call on every event: alert, or don't. There are exactly four possible outcomes once you cross that call against what actually happened, and security teams live or die by which two of the four they're accumulating. Get the "harmless" one wrong at scale, and it quietly produces more of the dangerous one.