This is a question to Atlassian Beacon Product Manager:
We have a very large Data Center customer with about 25K users, that wants to go to the cloud but has very big concerns with it.
One of the ways to mitigate the infosec risks that this customer raises is to show him the capabilities of Atlassian Beacon.
The customer says that he cannot say that Beacon really reduces the infosec risks, because it is not clear what is "Abnormal activity". There are no documented parameters/criteria/thresholds that can explain what Beacon considers as an Abnormal activity.
Can you explain what we can say to this customer? What are the criteria for considering an activity as Abnormal?