Company At A Glance
Business Type
IT Security Software Company
SR&ED Category
Experimental Development
Team Size
14
Scope
Threat Detection, Access Monitoring, False Positive Reduction
Province
Ontario
The Challenge
The company was developing an internal security monitoring tool designed to identify unusual login patterns, permission changes, and suspicious access activity across multiple client environments. Existing security tools produced too many false alerts, while basic rule-based checks missed activity that looked normal in isolation but was unusual when viewed across a user’s behaviour over time.
The team needed to determine whether they could build a more reliable detection workflow that could flag meaningful risks without overwhelming users with low-value alerts.
What We Documented
01
Uncertainty
Uncertainty
The uncertainty was whether the system could distinguish between normal user behaviour and genuinely suspicious activity across different client environments. Standard rules were not reliable because each client had different access patterns, user roles, login locations, and permission structures.
02
Iterations
Iterations
The team tested different detection rules, scoring models, alert thresholds, data groupings, and user behaviour comparisons. Some versions caught more suspicious activity but generated too many false positives. Other versions reduced alerts but missed activity that should have been flagged.
03
Knowledge Gained
Knowledge Gained
The company gained knowledge about how to structure user activity data, compare behaviour over time, and balance detection sensitivity against false positive rates across different environments.
Results
Why This Qualified
- Required experimentation beyond standard security rules and alert settings
- Existing tools produced too many false positives for the intended workflow
- User behaviour varied significantly across client environments
- Multiple detection models and thresholds were tested before a workable approach was found
- New knowledge was gained about balancing detection accuracy with alert reliability
