Threat Detection vs False Positives
Tune OT-specific behavioral baselines and apply ML-driven analytics to reduce false positives while maintaining NIS2-required detection capability.
CyberTRIZ analysis · Seveso contradiction CY015 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Business Context
Cybersecurity monitoring systems continuously analyze industrial
networks to detect malicious activity. Highly sensitive detection rules
improve security but may generate excessive false alarms that distract
operators and security personnel.
The Contradiction
Greater detection sensitivity improves cyber protection.
Fewer false alarms improve operational effectiveness.
Why It Exists
OT environments generate large volumes of legitimate operational
activity that can resemble suspicious behavior if detection rules are
not properly tuned.
Direction
Use behavior-based analytics, machine learning, and continuous rule
optimization to improve detection accuracy while minimizing unnecessary
alerts.