Guiding Perspectives: CEO Article Series
Thought leadership and commentary on workplace technology, employee internet policy, and data-driven management from the CEO of Wavecrest Computing.
Analytics Without Surveillance: What Three Decades of Employee Monitoring Taught Me
Thirty years ago, when the web arrived on every desk in the workplace, I watched organizations gain an extraordinary tool and, almost immediately, start looking for ways to see what people were doing with it. I have…
Thirty years ago, when the web arrived on every desk in the workplace, I watched organizations gain an extraordinary tool and, almost immediately, start looking for ways to see what people were doing with it. I have spent the time since then building software that answers that question, and I have watched the answer change shape more than once. Right now it is changing again, and I think it is changing for the better.
For most of those thirty years, the instinct ran in one direction: capture more.
When the web first reached every employee, the concerns were real and they were reasonable. Time disappeared into activity nobody could account for. Networks were exposed to threats that arrived through ordinary browsing. Legal and HR teams worried, rightly, about liability for what happened on company systems. Wanting visibility into all of it was not paranoia. It was responsible management of a powerful and unfamiliar tool.
So as monitoring tools grew more capable, many organizations reached for the most capable ones they could find. If a little visibility was good, total visibility seemed better. Screen recording, keystroke logging, and continuous activity capture promised to show everything, and for a while everything sounded like exactly what a careful employer should want.
What I have watched since is the slow arrival of the bill for that approach.
The more you capture, the more you have to carry. Screen and keystroke capture does not politely collect only the misconduct you were worried about. It sweeps up passwords, private messages, health information, and the personal lives of people who were doing nothing wrong. That is sensitive data you now own, have to secure, and may have to account for. In a growing number of states it comes with notification requirements. And it produces something no HR team I have ever met can actually use: hours of recordings per person per day that nobody has time to watch. A tool bought to create clarity ends up creating a liability to store and a haystack to search.
Meanwhile the thing organizations actually needed was sitting in plain view the whole time.
Every firewall, proxy, and secure web gateway already generates a record of the web traffic on the network. It is standard log data, the same kind of business record a company keeps as a matter of course. Read properly, it answers the question that started all of this, what are people doing on the web, without installing anything on anyone’s device and without recording a single screen or keystroke. I have come to describe this as analytics without surveillance, and I mean it precisely. You get the visibility, built on records you already keep, and you leave the surveillance behind.
That approach has three qualities the heavier model never had. It is agentless and less invasive by design, because it installs nothing on employee machines and captures no screens, no keystrokes, no audio, and no video, which means far less sensitive data collected and far fewer questions to answer about it. It produces defensible business records, consistent and repeatable, because it is built from the log data the organization already generates rather than from a recording someone has to vouch for. And it lets HR act on its own. When the records are already readable, an investigation does not have to wait in an IT queue, and the people responsible for policy can see what a person actually did without asking anyone to interpret raw logs for them.
That last point matters more than it sounds. For years the practical bottleneck was never capturing enough data. It was turning what had been captured into something a non-technical person could act on, cleanly and independently. Solve that, and you no longer need to watch people to understand what is happening. You only need to read, accurately, the record they already leave behind.
This is the work we have been doing at Wavecrest since 1996. Cyfin exists to take the web-use records your firewall already produces and turn them into clear, human-only web use reports that HR and management can read and act on themselves, with the automated background noise filtered out so what remains reflects what a person actually did. It was a somewhat contrarian idea for a long stretch of those thirty years. It looks less contrarian every month.
Here is where I think this goes. The next decade of employee monitoring will be less about watching people and more about reading the records you already keep. The organizations that get there first will carry less risk, review less noise, and make better decisions from cleaner information. After three decades of watching this field reach for more, I find it encouraging that the direction now is toward less. Less capture, less exposure, less intrusion, and, in the end, more of the clarity everyone was after in the first place.
Learn more about Cyfin web use reporting from Wavecrest Computing.
Harnessing Revolutionary Tools: Lessons from the Internet and the Dawn of AI
Introduction Thirty years ago, as the CEO of Wavecrest Computing, I witnessed the internet’s emergence as a transformative force, reshaping business operations with a magnitude that arguably surpasses Henry…
Introduction
Thirty years ago, as the CEO of Wavecrest Computing, I witnessed the internet’s emergence as a transformative force, reshaping business operations with a magnitude that arguably surpasses Henry Ford’s assembly line. The introduction of early browsers like Mosaic and Netscape made the internet accessible to all, enabling instant communication, global collaboration, and unprecedented productivity. Today, we stand at the threshold of another revolution: the rise of artificial intelligence (AI) tools. Both the internet and AI are powerful instruments, but their potential is only realized through careful management. At Wavecrest, our products, Cyfin and CyBlock, have helped businesses navigate the internet’s challenges for decades. As AI reshapes the workplace, the lessons we’ve learned underscore the need for oversight, informed decision-making, and tailored strategies to maximize productivity, security, and compliance.
The Internet’s Transformative Impact
The internet’s arrival in the 1990s was a paradigm shift. Much like Ford’s assembly line standardized manufacturing, browsers democratized information, empowering businesses to operate globally and innovate rapidly. However, this power came with challenges. When internet access reached every employee’s desktop, businesses gained a revolutionary tool but often lacked the means to manage it effectively. Wavecrest was among the first to recognize this, developing Cyfin to provide actionable insights into employee web usage, addressing not just security but also productivity and legal concerns.
Ford’s assembly line succeeded because he trained workers, monitored performance, and iterated improvements. In contrast, many businesses deployed the internet without similar rigor. Acceptable use policies, often driven by legal departments, focused on liability but rarely harnessed the internet’s full potential. This gap—between the tool’s power and its management—persists, leaving companies vulnerable to risks and missed opportunities.
Challenges of Internet Access
The internet introduced three key challenges, each requiring careful oversight:
Security Risks: Research shows that 88% of data breaches stem from human error, such as clicking phishing links or mishandling data (Stanford Research: 88% Of Data Breaches Are Caused By Human Error). Employees, not external hackers, are often the weakest link, necessitating robust training and monitoring.
Legal Liabilities: Internet misuse can lead to lawsuits over harassment, copyright infringement, or data privacy violations. For example, inappropriate email use or unauthorized downloads expose companies to significant risks (Employment Liability Laws for Internet Usage). Legal-driven policies address these but often overlook productivity.
Productivity Losses: Studies estimate that 30-40% of workplace internet activity is non-work-related, costing U.S. businesses $63 billion annually (Employee Internet Management: Now an HR Issue). Social media, shopping, and entertainment distract employees, undermining efficiency.
These challenges highlight a critical truth: being informed is essential for effective decision-making. Without visibility into how employees use the internet, businesses cannot optimize its benefits or mitigate its risks.
The AI Revolution: A New Frontier
As we reflect on the internet’s impact, AI tools—large language models, automation platforms, and analytics engines—are ushering in a new era. Like the internet, AI promises to augment human capabilities, streamline tasks, and drive innovation. However, it also amplifies existing challenges and introduces new ones. Dropping AI onto employees’ desktops without oversight risks repeating the internet’s early mistakes, where enthusiasm outpaced management.
Security Risks: AI amplifies human error risks. A 2024 Gartner report notes that 40% of organizations faced AI-related security incidents due to employee misuse, such as inputting sensitive data into unsecured models (Gartner: AI Security Risks). Without monitoring, businesses cannot detect or prevent these vulnerabilities.
Legal Liabilities: AI raises complex legal issues, including data privacy violations and ethical concerns. Processing personal data with AI can violate regulations like GDPR, while AI-generated content may infringe copyrights or produce biased outputs (AI and Data Privacy Risks). Tailored policies are essential but must be grounded in real usage data.
Productivity Concerns: AI’s potential to boost efficiency is immense, but misuse can erode gains. A 2025 McKinsey study estimates that 20% of AI initiatives fail to deliver ROI due to poor integration (McKinsey: AI Productivity Challenges). Employees using AI for personal tasks or inefficient workflows—such as excessive prompt tweaking—can mirror the internet’s productivity losses.
Training Gaps: Effective AI use requires training, but generic programs miss the mark. Without data on how employees interact with AI (e.g., tools used, tasks performed), training cannot address specific needs, reducing its impact.
The Pitfalls of Generic Policies
Both the internet and AI suffer from a common issue: reliance on boilerplate policies. Internet acceptable use policies, often legal-driven, focused on liability but neglected productivity. Similarly, generic AI policies—such as blanket bans on public models or vague usage guidelines—fail to account for organizational nuances. A marketing team may need AI for creative content, while a finance team requires strict data controls. Without understanding actual usage, policies remain disconnected from reality, undermining productivity, security, and compliance.
The Role of Oversight: Lessons from Cyfin
Wavecrest’s experience with the internet offers a blueprint for managing AI. Cyfin addresses the internet’s challenges by transforming complex firewall logs into clear, actionable reports, enabling management and HR to monitor usage, identify risks, and optimize productivity. Unlike built-in firewall tools, which focus on traffic and security, Cyfin excels at reconstructing user actions, providing insights competitors cannot match. This capability is critical, as raw logs are voluminous and difficult to interpret, often leading IT and management to chase inaccurate data (The Significance and Role of Firewall Logs | Exabeam).
Extending this to AI, businesses need tools to track interactions with AI platforms—e.g., which tools are used, how often, and for what purposes. Cyfin’s adaptability positions it to deliver similar visibility, reporting on AI usage to inform policies, training, and security measures. For example, Cyfin could identify employees sharing sensitive data with AI models, spending excessive time on non-work tasks, or struggling with specific tools, enabling targeted interventions.
Best Practices for Harnessing Revolutionary Tools
To maximize the internet and AI’s potential, businesses should adopt these strategies:
- Implement Comprehensive Monitoring: Use tools like Cyfin to gain visibility into internet and AI usage, providing management with data to make informed decisions.
- Develop Tailored Policies: Base policies on actual usage patterns, ensuring they address productivity, security, and legal needs specific to your organization.
- Prioritize Training: Tailor training to usage data, addressing gaps in skills or security awareness to enhance effectiveness.
- Foster a Culture of Responsibility: Encourage employees to use these tools productively and safely, supported by clear expectations and monitoring.
- Leverage Specialized Tools: Avoid relying on generic solutions like firewall logs, which lack the granularity needed for user-focused insights.
Conclusion: A Call to Action
The internet transformed business, and AI promises to take this further. However, their power is only realized through proactive management. Ford’s assembly line succeeded because he monitored and optimized it; businesses must do the same with the internet and AI. Security risks, legal liabilities, productivity losses, and training needs demand comprehensive oversight, tailored policies, and actionable data. At Wavecrest, we’ve spent 30 years helping businesses navigate these challenges with tools like Cyfin, which deliver the insights needed to harness revolutionary tools effectively.
As we embrace AI, let us learn from the internet’s history. Being informed is critical—only with the most facts can we make the best decisions. Businesses unaware of tools like Cyfin or struggling to implement oversight risk squandering AI’s potential, just as many did with the internet. By investing in visibility and management, organizations can shape a future where these tools drive productivity, security, and innovation. Join us in harnessing the next revolution.
Finally—Clarity from the Chaos of Firewall Logs
How Cyfin Delivers Actionable Employee Web Activity Reports from Complex, Noisy Firewall Data Executive Summary Organizations rely on firewalls to secure their networks, but these tools generate logs that are…
How Cyfin Delivers Actionable Employee Web Activity Reports from Complex, Noisy Firewall Data
Executive Summary
Organizations rely on firewalls to secure their networks, but these tools generate logs that are incredibly complex. Every device, system update, browser tab, and cloud sync creates a connection—and every connection gets logged. For IT, HR, and management teams trying to understand actual employee behavior online, these logs present a mess of indistinguishable data. Cyfin changes that.
Cyfin is a powerful log-parsing and reporting engine that reads raw, connection-based firewall logs and delivers clear, human-readable reports focused on employee-initiated web activity. It cuts through the noise—from Windows updates to endpoint security traffic—and delivers reports designed for both technical and non-technical audiences.
Why Cyfin is Different
Most tools tell you everything that happened on the network. Cyfin tells you what your employees did.
Firewall logs don’t distinguish between a user browsing a news site and their machine syncing with a cloud service. Cyfin’s core strength is its ability to recognize and separate human-initiated actions from the flood of background traffic that is increasingly using the same web protocols and ports.
This distinction is essential. Whether you’re conducting an internal investigation, responding to a compliance request, or simply monitoring productivity, Cyfin gives you the clarity you need to make decisions based on facts, not assumptions.
Key Benefits
- Accurate Employee Web Usage Monitoring
- What It Does: Filters out non-human activity to focus solely on employee-initiated web actions.
- Why It’s a Game-Changer: Standard firewall reports lump everything together, distorting the picture of employee behavior. Cyfin ensures accuracy by isolating what matters.
- For IT: Automates log analysis, reducing your workload and delivering precise data.
- For HR & Management: Delivers a true view of employee web use—perfect for enforcing policies or boosting productivity.
- Simplified Compliance and Security
- What It Does: Produces detailed, auditable reports to meet regulations (e.g., GDPR, HIPAA) and spot security risks.
- Why It’s a Game-Changer: With remote work and data privacy laws on the rise, Cyfin’s reports provide compliance-ready evidence and threat detection.
- For IT: Seamlessly integrates with your firewall setup for efficient monitoring.
- For HR & Legal: Offers easy-to-use reports tailored to your compliance needs, simplifying audits.
- No Software on Employee Devices
- What It Does: Monitors activity directly from firewall logs—no agents needed on individual devices.
- Why It’s a Game-Changer: Cuts deployment hassle, reduces privacy concerns, and works across all devices.
- For IT: Eliminates the need to manage software on endpoints, saving time.
- For HR & Management: Provides monitoring without invasive tools, maintaining employee trust.
- Multi-Vendor Firewall Compatibility
- What It Does: Supports top firewall brands like Palo Alto, Cisco, Fortigate, and SonicWall.
- Why It’s a Game-Changer: Unifies reporting in mixed IT environments, streamlining management.
- For IT: Standardizes reporting across vendors, simplifying your workflow.
- For Management: Ensures consistent, clear reports regardless of firewall setup.
- Scalable for Any Organization
- What It Does: Handles large data volumes effortlessly, growing with your needs.
- Why It’s a Game-Changer: Keeps performance strong as your workforce expands.
- For IT: Manages high-throughput environments without slowdowns.
- For Management: Delivers reliable insights at every stage of growth.
Cyfin in Action
Consider this scenario: A department manager suspects excessive personal web use during work hours. The IT team pulls logs from their firewall, but what they get is a flood of technical entries—tens of thousands of lines including Windows telemetry, antivirus updates, background ad tracking, and cloud syncs.
With Cyfin, that same data is distilled into a clear, chronological report showing actual employee-initiated browsing—highlighting visits to shopping sites, video streaming platforms, and news articles. HR receives a clean PDF report that supports a productive and well-informed conversation with the employee in question.
Conclusion
Cyfin solves a problem that even seasoned IT professionals struggle with: how to turn raw firewall data into meaningful insights about employee web behavior. Its ability to separate human action from machine noise makes it an invaluable tool not just for IT, but for HR, Legal, and Management teams as well.
When accurate visibility into employee online activity matters, Cyfin is the solution that delivers clarity from chaos.
- Accurate Employee Web Usage Monitoring
Understanding Employee Internet Monitoring: What Cyfin Reports Show You
IEmployee internet monitoring works best when it answers real questions for the people who need answers. Cyfin by Wavecrest Computing reports on how employees use the web, using your existing firewall logs, so HR and…

IEmployee internet monitoring works best when it answers real questions for the people who need answers. Cyfin by Wavecrest Computing reports on how employees use the web, using your existing firewall logs, so HR and management can see what is happening and act on it independently.
An important distinction up front: Cyfin is a reporting product. It does not block or filter websites. It tells you what happened. If you also need to control access and enforce filtering policy, that is CyBlock, our companion product. This post is about what Cyfin’s reporting gives you.
Why accurate reporting matters
Raw firewall logs mix human activity with machine noise. Software updates, background app check-ins, and embedded trackers all get logged the same way as a deliberate visit. Reports built on that data overstate activity and obscure what an employee actually did.
Cyfin filters out non-human traffic and reconstructs browsing sessions before producing a report. What you read reflects employee-initiated activity, in a format a non-technical person can interpret.
What you can see and do
Policy compliance. A written acceptable use policy only works if you can verify it is being followed. Cyfin shows actual web use against your policy, so you can see where behavior falls outside your guidelines and follow up.
Workplace investigations. When a concern comes up about a specific employee, HR can run a clear, dated report and drill down to the detail, without asking IT to interpret log data.
Productivity insight. Managers can see how time is spent across categories such as social media, streaming, shopping, news, and AI tools, and how patterns shift over time.
Web application use. See which web applications and services employees are using, including generative AI tools identified by name. That visibility is what tells you whether the tools in use align with what your organization has approved.
Training and policy refinement. Real usage data shows where guidance would help, so training addresses what people are actually doing rather than what you assume they are doing.
How it fits your environment
Cyfin is agentless. There is nothing to install on employee devices, because it reads the log data your firewall already produces. It supports the major firewalls in use today, including Palo Alto Networks, Cisco, Fortinet, Check Point, and SonicWall.
Key takeaways
- Monitoring is not about mistrust. It is about having accurate information before making decisions that affect people.
- Reports are only as good as the data underneath them. Filtering out non-human traffic is what makes web use reports usable.
- HR and management can run their own reports, which keeps investigations moving and reduces the burden on IT.
- Reporting and filtering are different jobs. Cyfin reports. CyBlock filters.
Learn more about Cyfin.
Cyfin by Wavecrest Computing has been purpose-built for employee web use reporting and investigations since 1996. Its noise-filtering engine turns raw firewall log data into clear, human-only reports that HR and management can read, understand, and act on independently. https://www.wavecrest.net • 321-953-5351ternetMonitoring #CyberSecurityEducation #WorkplaceProductivity #DigitalWorkplace #Cyfin
Determining employee Web-use behavior with Smart Engine analytics
I previously discussed that employee Web use has much to do with human behavior in the workplace, and the management of it is not just an IT issue. All stakeholders and areas of the company can help manage employee…
I previously discussed that employee Web use has much to do with human behavior in the workplace, and the management of it is not just an IT issue. All stakeholders and areas of the company can help manage employee Web use effectively. With IT investing time in researching and implementing the most suitable Web filtering and monitoring solution for the organization, collaborators in the company, such as senior managers, HR, and department managers, can get the right information in the right format. Ideally the solution would include a reporting engine or Smart Engine making it possible for collaborators to get a true picture of employee behavior. Here I’ll discuss the features of a Smart Engine and its importance in deriving human behavior from Web-use data.
First of all, what is a Smart Engine? A Smart Engine is a powerful reporting engine that helps companies make informed, data-driven decisions and take action on issues concerning the proper use of their network resources. It provides direct, easy, and fast access to data, and low-latency, real-time analytics. With its elaborate, distributed system, it is highly scalable and able to handle petabytes of data. A Smart Engine is built for speed and provides a scalable solution that is optimized for analytics retrieval.
Smart Engine analytics provide the information for reporting–charts and reports–to present accurate and up-to-date Web activity. The Smart Engine utilizes algorithms that perform functions such as determining real Web browsing activity, user names, and time online from Web traffic, and categorizing URLs into logical groups based on content. Without the Smart Engine and its analytics, the reporting components could not provide the adequate information that a company needs to manage employee Web use. The Smart Engine makes technical data usable and manager-ready. Examples of its algorithms are discussed below.
The most important algorithm is one that distinguishes between real Web browsing activity from user clicks (or visits) and background Web activity (unsolicited traffic or hits) by identifying the content of each URL. True visits are actual user clicks that do not include multimedia URLs, such as images, audio Web pages, advertisements, or Web pages that were requested as part of a visit, that is, unsolicited. The differentiation between Web traffic visits and hits is of high importance for companies that want to manage the human factor. Companies can get a true, meaningful picture of the level and type of Web activity occurring in their network.
When Web filtering and reporting products do not include user names in Web traffic records, user Web activity is lost and unaccounted for. The company may not even know that this is occurring. Another algorithm performed by the Smart Engine is a user name caching algorithm that uses the cache user name if available, versus the IP address, allowing you to capture all activity of the user and get more detailed data in reporting.
When users are online, they could be reading a Web page, performing another task in a different application with the browser open, or possibly away from the computer entirely with the browser open. A time online algorithm uses a highly accurate priority method for calculating users’ time online. Managers and IT administrators can quickly see which users, categories, sites, and so on had the most volume of activity and address any potential issues, such as productivity loss, bandwidth slowdowns, and policy noncompliance.
Another algorithm that produces Smart Engine analytics is a categorization algorithm. This algorithm is designed to report on all Web activity. With the extensive content categories available in the Web filtering and monitoring tool, this algorithm categorizes the organization’s Web activity so that managers can analyze their employees’ Web usage. Proper URL categorization detects and identifies a broad range and a high percentage of total Web activity.
The Smart Engine feeds data to the reporting components of a Web monitoring and filtering tool and provides analytics for determining human behavior. You will not get this type of data directly from any firewall on the market today. The raw data itself is only information about machine/network requests. It is not about human activity, but about the machine’s response to a human request to get or push information. The Smart Engine enables companies to quickly create simple Web browsing reports and analyze current or historical Web-use data from human behavior. This human behavior data is what is truly needed to effectively manage employee Web use to keep your employees and network safe.
