Subscribe to the Non-Human & AI Identity Journal

Cost per true positive

Cost per true positive measures how much it costs to produce one real, actionable finding. It is a better operational metric than scan price because it combines economic efficiency with detection quality, which is what matters when a security team has to decide whether a workflow is worth running at scale.

Expanded Definition

Cost per true positive is an operational efficiency metric that ties spending to confirmed, actionable outcomes. It goes beyond a raw tool or scan price by asking how much budget is required to generate one finding that security staff can actually investigate, validate, and use. That distinction matters because a low-cost workflow can still be expensive if it produces noise, duplicates, or findings with no remediation path.

For security teams, the metric is useful wherever detection, triage, or validation workflows compete for limited analyst time. It can apply to vulnerability scanning, cloud posture reviews, identity investigations, phishing detection, or agent-assisted review pipelines, as long as the result can be judged as a true positive. The term is not a formal control objective in NIST SP 800-53 Rev 5 Security and Privacy Controls, but it maps naturally to control effectiveness and operational assurance discussions.

Definitions vary across vendors because “true positive” can mean confirmed malicious activity, policy violation, exploitable exposure, or another validated condition depending on the workflow. The most common misapplication is treating total scan cost as the metric, which occurs when teams ignore false positive, analyst review time, and downstream remediation effort.

Examples and Use Cases

Implementing cost per true positive rigorously often introduces measurement overhead, requiring organisations to weigh cleaner operational decisions against the work of classifying outcomes consistently.

  • A phishing detection team calculates the full cost of mail filtering, analyst review, and case handling, then divides by the number of emails confirmed as malicious after investigation.
  • A vulnerability management group measures the cost of scanning, deduplication, and validation against only those issues that prove exploitable and relevant to the asset owner.
  • An identity security team uses the metric to compare privileged access anomaly detection rules, counting only alerts that lead to confirmed misuse or risky access paths.
  • A cloud security team evaluates posture checks against findings that are real and actionable, rather than alerts that reflect accepted exceptions or inherited configurations.
  • An agentic AI review workflow measures the cost of human oversight, queue management, and evidence collection against only those outputs that are verified as unsafe or policy-breaking.

This is especially relevant when teams use structured controls and governance baselines from sources such as NIST, because the question is not whether a workflow produces activity, but whether it produces defensible security value.

Why It Matters for Security Teams

Cost per true positive helps security leaders decide whether a detection or review process is sustainable at scale. If the metric is poor, teams often respond by suppressing alerts, reducing coverage, or accepting delay in investigation, which can create blind spots and weaken governance. If the metric is healthy, it supports better prioritisation, more defensible resourcing, and clearer discussion between security, risk, and operations.

The metric is also important when automation is involved. In AI-assisted security workflows, a low apparent processing cost can hide expensive human verification, while a high-volume model may still be operationally attractive if its true positives are consistently useful. That is why frameworks such as NIST SP 800-53 Rev 5 Security and Privacy Controls remain relevant: they encourage thinking in terms of control outcomes, not just tool output.

Organisations typically encounter the real burden only after alert queues, false positives, or repetitive validation work overwhelm analysts, at which point cost per true positive becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 RS.AN-1 NIST CSF emphasises effective analysis of detected events, which this metric helps quantify.
NIST SP 800-53 Rev 5 SI-4 System monitoring and alerting quality are central to measuring useful findings versus noise.
ISO/IEC 27001:2022 A.8.16 Monitoring activities in ISMS programs depend on efficient, outcome-based security observations.
NIST AI RMF GOV-2 AI governance requires accountability for whether model-driven outputs create real value.
OWASP Agentic AI Top 10 Agentic AI security depends on controlling tool-using workflows that can generate noisy or unsafe outputs.

Track true-positive yield from monitoring controls and reduce noisy detections that waste analyst effort.