Tag Archives: cyfin

Why Your Firewall Logs Don’t Actually Show What Employees Are Doing

If your IT team is pulling reports directly from your firewall logs and sending them to HR, there is something important you need to understand: those reports are almost certainly not showing you what you think they are.

This is not a criticism of your IT team. It is a structural problem that goes all the way back to how the internet was built. Understanding it explains why investigating employee web activity is so much harder than it looks, and why the tools you choose to do it matter enormously.

A Quick History Lesson That Changes Everything

In the early days of the internet, before the web browser as we know it existed, every service on the internet had its own dedicated channel. Each was clearly separated and easy to identify:

  • Web browsing used one channel
  • Email used another
  • File transfers used another
  • Remote access used another

If you monitored network traffic in those days, you knew exactly what kind of activity generated it. The separation was clean.

Then the browser arrived and transformed everything. As internet use exploded, there was an urgent push to secure web communications. A single encrypted channel became the universal standard. Suddenly the vast majority of all internet communication was flowing through one pipe.

That shift created the foundation of the problem we are dealing with today.

When Everything Moved Into One Channel

As web-based applications took off, they naturally adopted the same communication structure built for websites. Online banking, cloud storage, collaboration tools, SaaS platforms all followed the same path. Why build something new when the existing infrastructure was already everywhere and already trusted?

The result is that today, a single channel carries an enormous mix of traffic: the websites your employees deliberately visit, the web applications your business relies on, and a long list of activity that has nothing to do with human behavior at all.

That last category is where the real problem lives.

The Traffic Nobody Talks About

Here is what is actually flowing through your network alongside your employees’ web activity, and what ends up recorded in your firewall logs:

  • Operating system and software updates. Microsoft checks for Windows updates. Adobe verifies software licenses. Your endpoint security platform downloads new threat definitions. Every one of those actions generates network connections that get logged alongside everything else.
  • Website trackers. Modern websites are embedded with dozens of third-party tracking scripts that continuously send usage data back to analytics platforms, advertising networks, and content delivery services. A single visit to a news website can silently generate hundreds of outbound connections in the background, none of which represent a deliberate action by your employee.
  • Application background activity. Cloud applications, collaboration platforms, and business software regularly check in with their servers for updates, license validation, and performance data. This happens automatically, continuously, and invisibly throughout the workday.

None of this traffic reflects what an employee chose to do. But it all shows up in the firewall log, recorded exactly the same way as an intentional website visit.

The core problem in plain terms:
Your firewall has no way to distinguish between a connection your employee deliberately made and a connection their computer made automatically in the background. It logs them all the same way. A raw firewall report treats them all the same way. And that means any analysis built on raw firewall data is working with fundamentally flawed information.

The Second Problem: How Firewalls Actually Log Web Activity

Even setting aside all of the background noise, there is a second fundamental issue with reading firewall logs directly.

Firewalls record network connections, not website visits. Those are not the same thing.

When one of your employees opens their browser and navigates to a single website, their computer may establish dozens or even hundreds of separate network connections to fully load that page. The text, images, stylesheets, fonts, and interactive elements of a modern website often come from multiple different servers and domain names. Each connection is logged individually.

So what HR sees when someone forwards them a raw firewall report is not a clean record showing that an employee visited ESPN. It is potentially 100 separate log entries with different domain names, different connection times, and different data volumes that together represent one single website visit. Without something to reconstruct those connections into a coherent browsing session, the data is essentially unreadable to anyone without deep technical expertise.

Asking a non-technical person in HR to draw conclusions from that is not just unhelpful. It creates a genuine liability risk. Disciplinary action taken on the basis of misread or misunderstood firewall data is exactly the kind of situation that leads to serious HR and legal complications.

Why Not Just Use a Screen Recording or Keystroke Tool?

It is a fair question. If the goal is to know what employees are doing online, why not use something that captures everything directly? Screen recordings and keystroke logging tools sound more thorough on the surface. And from a pure marketing standpoint, they often look impressive in a product demo.

The answer comes down to legal reality, and it is significant.

In U.S. case law, infrastructure logs including firewall logs are an accepted and well-established legal basis for businesses to monitor activity on company-owned networks and equipment. Employers have a recognized right to monitor how their infrastructure is being used, and properly generated firewall-based reports have consistently held up in workplace investigations, disciplinary proceedings, and litigation.

Screen capture and keystroke logging tools occupy very different legal territory. Depending on your state, your industry, and how those tools are deployed, using them can expose your organization to meaningful legal liability including privacy violation claims from employees. The requirements around disclosure and consent are considerably more complex, and any disciplinary action based on that type of monitoring is far more vulnerable to a legal challenge.

There is also a practical reality that rarely gets discussed openly: who is actually going to review the output? Consider what it means to capture screen recordings for an entire workforce. An hour of video per employee per day. Thousands of keystrokes to read through per person. The volume of data these tools produce is completely unmanageable at any realistic scale. They make for compelling product demonstrations. They do not make for workable investigation workflows.

The bottom line on alternative tools:
Firewall-based reporting done correctly gives HR exactly what they need: a clear, accurate, legally defensible record of what an employee did online, in a format anyone can read, generated in minutes rather than hours. The alternatives that appear to offer more actually deliver less, and at a substantially higher legal and operational cost.

Why This Takes More Than a Report Template

Solving the firewall noise problem is not a matter of formatting the log data differently or applying a filter. It requires sophisticated software that can do several things simultaneously:

  • Strip out all non-human background traffic before any analysis begins
  • Reconstruct individual user browsing sessions from potentially hundreds of separate connection records
  • Translate ambiguous technical domain names into recognizable website names that anyone can understand
  • Present the results in a format that a non-technical person in HR or management can read, interpret, and act on

This is precisely what Cyfin was built to do, and why it required a dedicated team of developers to build it. The problem it solves is genuinely complex, even if the output looks simple. That simplicity is the entire point.

What This Means for HR and Management

If your organization is trying to investigate employee web activity using raw firewall reports, or any tool that has not specifically solved the noise and session reconstruction problem, you are working with data you cannot trust.

Reports that mix human activity with background noise will overstate what employees are actually doing online. Sessions that span dozens of log entries will be impossible to interpret without proper reconstruction. Any investigation built on that foundation, however well-intentioned, is built on information that will not hold up to scrutiny.

Accurate employee web investigations start with accurate data. Accurate data starts with understanding what firewall logs actually contain. And making that data usable for HR starts with a tool that was specifically designed for that purpose.


About Cyfin

Cyfin by Wavecrest Computing has been purpose-built for employee web use reporting and investigations since 1996. Our noise-filtering engine and session reconstruction technology transform raw firewall log data into clear, human-only reports that HR and management can read, understand, and act on independently, without needing IT to interpret the results.
https://www.wavecrest.net • 321-953-5351

Monitoring Employee AI Usage: Reporting for AI Policy Compliance

Generative AI tools like ChatGPT, Copilot, Gemini, and Grok are now part of daily work. That creates a governance gap. HR and management set the AI policy, but without a clear view of how AI tools are actually being used, there is no reliable way to know whether that policy is being followed. Cyfin by Wavecrest Computing gives HR and management that visibility from your existing firewall logs, with no software installed on employee devices.

Why employee AI usage needs oversight

Most organizations have written an AI acceptable use policy, or are about to. The harder part is enforcement. A policy you cannot measure is just a document. Common questions HR and management want answered include:

  • Which AI tools are employees actually using, and are any of them outside policy?
  • Is AI being used for personal tasks during work hours?
  • Which departments rely on AI most, and where might training help?
  • Are usage patterns creating risk that should be reviewed?

Without visibility into real usage, these stay guesses. Cyfin turns them into reportable facts.

What Cyfin shows you about employee AI use

Cyfin reads your existing firewall logs and produces noise-free, human-only reports focused on employee-initiated activity. For AI specifically, every Cyfin customer can see:

  • Which AI tools are being used, identified by name through Cyfin’s Artificial Intelligence category
  • Who is using them, across the organization by user and department
  • How often each tool is used and how long sessions last
  • Historical trends, so you can see whether usage is rising and where

This is usage reporting that HR and management can read and act on independently, without asking IT to interpret raw log data.

Can Cyfin see what employees type into AI tools?

It depends on your firewall. Cyfin’s standard reporting shows which AI tools employees use, how often, and for how long, but not the text they enter. Seeing what an employee actually submitted to an AI tool requires two things: a firewall that exposes AI-specific log fields, such as Palo Alto Networks with its AI visibility add-on, and SSL inspection enabled on that traffic. Where your firewall supports it, Cyfin can surface that deeper detail. Where it does not, you still get complete usage visibility.

Being straight about this matters. Usage-level reporting is what every customer gets and is enough to enforce most AI policies. Content-level visibility is an advanced capability that depends on your infrastructure.

How this helps HR and management

Cyfin is built for HR and management to run their own reviews:

  • Enforce your AI policy. Compare actual usage against your acceptable use guidelines and follow up where needed.
  • Support workplace investigations. Produce clear, dated records of AI tool use for a specific user or department.
  • Target training. See which teams lean on AI and where guidance would help them use it well.
  • Keep audit-ready records. Independent, readable reports that support policy decisions and reviews.

Because the reports filter out non-human background traffic, what you see reflects employee-initiated activity, not automated noise.

Works with the firewall you already have

Cyfin is agentless. There is nothing to install on employee devices, because it works from the log data your firewall already produces. It supports the major firewalls in use today, including Palo Alto Networks, Cisco, Fortinet, Check Point, and SonicWall, so it extends the investment you have already made rather than adding another endpoint tool to manage.

Get a clear view of AI use in your organization

You cannot enforce an AI policy you cannot measure. Cyfin gives HR and management the usage visibility to do it, from your existing firewall, without agents.

Learn more on our employee AI usage page, or request a sample AI usage report to see the format before you commit.


Cyfin by Wavecrest Computing has been purpose-built for employee web use reporting and investigations since 1996. Its noise-filtering engine turns raw firewall log data into clear, human-only reports that HR and management can read, understand, and act on independently. https://www.wavecrest.net • 321-953-5351

Cyfin: Employee Web Use Reporting and Investigations from Your Firewall Logs

Cyfin by Wavecrest Computing turns raw firewall log data into clear, human-only reports on employee web activity. HR and management can read those reports and act on them independently, without asking IT to interpret the data. Cyfin is agentless, so it works from the log data your existing firewall already produces.

That is the whole product in three sentences. The rest of this post explains why it takes purpose-built software to do it, and what it means for the people who actually need the answers.

Why raw firewall reports do not answer HR’s questions

Every organization with a firewall already has web activity data. The problem is that the data was never built to answer the question HR is asking.

Firewalls log network connections. They do not log website visits, and the two are not the same thing. When an employee opens a single web page, their computer may make dozens or hundreds of separate connections to load it. Each one is recorded individually. On top of that, a large share of what a firewall logs was never a human decision at all. Software updates, license checks, security definition downloads, embedded trackers, and background application activity all flow through the same channel and get logged the same way as a deliberate visit.

So a raw firewall report handed to HR is not a record of what someone did. It is a mix of human activity and machine noise, spread across entries that require technical expertise to reassemble. Drawing conclusions from it is difficult at best. Taking disciplinary action based on it is a real liability risk.

What Cyfin does with that data

Cyfin was built specifically to solve that problem. It does several things before you ever see a report:

  • Filters out non-human traffic. Background connections are removed before analysis begins, so the report reflects employee-initiated activity.
  • Reconstructs browsing sessions. Individual connection records are assembled back into coherent sessions with real start times and durations.
  • Translates domains into recognizable names. Ambiguous technical domain names become site names anyone can read.
  • Categorizes activity. Web use is grouped into meaningful categories, including social media, streaming, shopping, news, and AI tools, so patterns are visible without reading individual URLs.

The output is a report a non-technical person can open, understand, and act on. That simplicity is the point, and it is what required a dedicated engineering effort to achieve.

Who this is for

HR. When a concern comes up about an employee’s web use, HR needs an accurate, readable, dated record. Cyfin produces reports HR can run and interpret without IT involvement, which keeps investigations moving and keeps them defensible.

Management. Managers need to know whether acceptable use policy is being followed and where patterns are shifting. Scheduled reports go directly to the managers responsible for those groups, restricted to the groups they are authorized to see.

IT. IT stops being the bottleneck. Instead of fielding ad-hoc report requests and explaining log data, IT configures Cyfin once against the existing firewall and grants managers reporting-only access. Cyfin supports the major firewalls in use today, including Palo Alto Networks, Cisco, Fortinet, Check Point, and SonicWall, so it extends infrastructure you already have.

Investigations and ongoing visibility

Cyfin supports two different workflows, and most organizations need both.

Ongoing visibility means scheduled reports and dashboards that show how web use trends over time across groups and departments. This is what makes an acceptable use policy meaningful rather than a document nobody verifies.

Investigations are targeted. When a specific concern arises, Cyfin can produce a detailed record for a single user over a defined period, with drill-down from a summary to the individual sessions and URLs behind it. Because the underlying data has already been filtered and reconstructed, what HR reviews reflects deliberate activity rather than background noise.

Generative AI tool usage

Employee use of generative AI is now part of the same conversation. Cyfin’s Artificial Intelligence category identifies AI platforms by name in reports, so you can see which tools are being used, by whom, how often, and for how long, and how that usage trends over time. That is the visibility most organizations need to enforce an AI acceptable use policy.

Seeing the actual text an employee submitted to an AI tool is a separate capability. It requires a firewall that exposes AI-specific log fields, such as Palo Alto Networks with its AI visibility add-on, and SSL inspection enabled. Where your environment supports it, Cyfin can surface that detail. Where it does not, you still get complete usage visibility. See our employee AI usage page for what applies to your firewall.

No agents on employee devices

Cyfin does not install software on endpoints. It reads the log data your firewall already generates. That means nothing to deploy or maintain on employee machines, no coverage gaps when someone uses a different device, and a monitoring approach that stays proportionate to the question being asked.

It is also worth noting why firewall-based reporting holds up. Infrastructure logs are a well-established basis for an employer to review activity on company-owned networks and equipment. Screen recording and keystroke capture tools sit in more complicated legal territory and generate volumes of data that no one realistically reviews. Accurate firewall-based reporting gives HR what it actually needs in a form it can use.

Getting an accurate picture

If your organization is reviewing employee web activity using raw firewall reports, you are working with data that overstates activity and obscures what actually happened. Accurate investigations start with accurate data, and accurate data starts with filtering out everything a human did not do.

See what Cyfin reports look like with your own firewall data. Start a free trial or request a sample report, no credit card required.


Cyfin by Wavecrest Computing has been purpose-built for employee web use reporting and investigations since 1996. Its noise-filtering engine and session reconstruction turn raw firewall log data into clear, human-only reports that HR and management can read, understand, and act on independently. https://www.wavecrest.net • 321-953-5351

Harnessing Revolutionary Tools: Lessons from the Internet and the Dawn of AI

Introduction

Thirty years ago, as the CEO of Wavecrest Computing, I witnessed the internet’s emergence as a transformative force, reshaping business operations with a magnitude that arguably surpasses Henry Ford’s assembly line. The introduction of early browsers like Mosaic and Netscape made the internet accessible to all, enabling instant communication, global collaboration, and unprecedented productivity. Today, we stand at the threshold of another revolution: the rise of artificial intelligence (AI) tools. Both the internet and AI are powerful instruments, but their potential is only realized through careful management. At Wavecrest, our products, Cyfin and CyBlock, have helped businesses navigate the internet’s challenges for decades. As AI reshapes the workplace, the lessons we’ve learned underscore the need for oversight, informed decision-making, and tailored strategies to maximize productivity, security, and compliance.

The Internet’s Transformative Impact

The internet’s arrival in the 1990s was a paradigm shift. Much like Ford’s assembly line standardized manufacturing, browsers democratized information, empowering businesses to operate globally and innovate rapidly. However, this power came with challenges. When internet access reached every employee’s desktop, businesses gained a revolutionary tool but often lacked the means to manage it effectively. Wavecrest was among the first to recognize this, developing Cyfin to provide actionable insights into employee web usage, addressing not just security but also productivity and legal concerns.

Ford’s assembly line succeeded because he trained workers, monitored performance, and iterated improvements. In contrast, many businesses deployed the internet without similar rigor. Acceptable use policies, often driven by legal departments, focused on liability but rarely harnessed the internet’s full potential. This gap—between the tool’s power and its management—persists, leaving companies vulnerable to risks and missed opportunities.

Challenges of Internet Access

The internet introduced three key challenges, each requiring careful oversight:

Security Risks: Research shows that 88% of data breaches stem from human error, such as clicking phishing links or mishandling data (Stanford Research: 88% Of Data Breaches Are Caused By Human Error). Employees, not external hackers, are often the weakest link, necessitating robust training and monitoring.

Legal Liabilities: Internet misuse can lead to lawsuits over harassment, copyright infringement, or data privacy violations. For example, inappropriate email use or unauthorized downloads expose companies to significant risks (Employment Liability Laws for Internet Usage). Legal-driven policies address these but often overlook productivity.

Productivity Losses: Studies estimate that 30-40% of workplace internet activity is non-work-related, costing U.S. businesses $63 billion annually (Employee Internet Management: Now an HR Issue). Social media, shopping, and entertainment distract employees, undermining efficiency.

These challenges highlight a critical truth: being informed is essential for effective decision-making. Without visibility into how employees use the internet, businesses cannot optimize its benefits or mitigate its risks.

The AI Revolution: A New Frontier

As we reflect on the internet’s impact, AI tools—large language models, automation platforms, and analytics engines—are ushering in a new era. Like the internet, AI promises to augment human capabilities, streamline tasks, and drive innovation. However, it also amplifies existing challenges and introduces new ones. Dropping AI onto employees’ desktops without oversight risks repeating the internet’s early mistakes, where enthusiasm outpaced management.

Security Risks: AI amplifies human error risks. A 2024 Gartner report notes that 40% of organizations faced AI-related security incidents due to employee misuse, such as inputting sensitive data into unsecured models (Gartner: AI Security Risks). Without monitoring, businesses cannot detect or prevent these vulnerabilities.

Legal Liabilities: AI raises complex legal issues, including data privacy violations and ethical concerns. Processing personal data with AI can violate regulations like GDPR, while AI-generated content may infringe copyrights or produce biased outputs (AI and Data Privacy Risks). Tailored policies are essential but must be grounded in real usage data.

Productivity Concerns: AI’s potential to boost efficiency is immense, but misuse can erode gains. A 2025 McKinsey study estimates that 20% of AI initiatives fail to deliver ROI due to poor integration (McKinsey: AI Productivity Challenges). Employees using AI for personal tasks or inefficient workflows—such as excessive prompt tweaking—can mirror the internet’s productivity losses.

Training Gaps: Effective AI use requires training, but generic programs miss the mark. Without data on how employees interact with AI (e.g., tools used, tasks performed), training cannot address specific needs, reducing its impact.

The Pitfalls of Generic Policies

Both the internet and AI suffer from a common issue: reliance on boilerplate policies. Internet acceptable use policies, often legal-driven, focused on liability but neglected productivity. Similarly, generic AI policies—such as blanket bans on public models or vague usage guidelines—fail to account for organizational nuances. A marketing team may need AI for creative content, while a finance team requires strict data controls. Without understanding actual usage, policies remain disconnected from reality, undermining productivity, security, and compliance.

The Role of Oversight: Lessons from Cyfin

Wavecrest’s experience with the internet offers a blueprint for managing AI. Cyfin addresses the internet’s challenges by transforming complex firewall logs into clear, actionable reports, enabling management and HR to monitor usage, identify risks, and optimize productivity. Unlike built-in firewall tools, which focus on traffic and security, Cyfin excels at reconstructing user actions, providing insights competitors cannot match. This capability is critical, as raw logs are voluminous and difficult to interpret, often leading IT and management to chase inaccurate data (The Significance and Role of Firewall Logs | Exabeam).

Extending this to AI, businesses need tools to track interactions with AI platforms—e.g., which tools are used, how often, and for what purposes. Cyfin’s adaptability positions it to deliver similar visibility, reporting on AI usage to inform policies, training, and security measures. For example, Cyfin could identify employees sharing sensitive data with AI models, spending excessive time on non-work tasks, or struggling with specific tools, enabling targeted interventions.

Best Practices for Harnessing Revolutionary Tools

To maximize the internet and AI’s potential, businesses should adopt these strategies:

  • Implement Comprehensive Monitoring: Use tools like Cyfin to gain visibility into internet and AI usage, providing management with data to make informed decisions.
  • Develop Tailored Policies: Base policies on actual usage patterns, ensuring they address productivity, security, and legal needs specific to your organization.
  • Prioritize Training: Tailor training to usage data, addressing gaps in skills or security awareness to enhance effectiveness.
  • Foster a Culture of Responsibility: Encourage employees to use these tools productively and safely, supported by clear expectations and monitoring.
  • Leverage Specialized Tools: Avoid relying on generic solutions like firewall logs, which lack the granularity needed for user-focused insights.

Conclusion: A Call to Action

The internet transformed business, and AI promises to take this further. However, their power is only realized through proactive management. Ford’s assembly line succeeded because he monitored and optimized it; businesses must do the same with the internet and AI. Security risks, legal liabilities, productivity losses, and training needs demand comprehensive oversight, tailored policies, and actionable data. At Wavecrest, we’ve spent 30 years helping businesses navigate these challenges with tools like Cyfin, which deliver the insights needed to harness revolutionary tools effectively.

As we embrace AI, let us learn from the internet’s history. Being informed is critical—only with the most facts can we make the best decisions. Businesses unaware of tools like Cyfin or struggling to implement oversight risk squandering AI’s potential, just as many did with the internet. By investing in visibility and management, organizations can shape a future where these tools drive productivity, security, and innovation. Join us in harnessing the next revolution.

Cyfin v9.7.1 – Powering Scalable Enterprise Web Monitoring

At Wavecrest, we empower enterprises to monitor user activity with speed and precision, no matter how complex their network. We’re excited to introduce Cyfin v9.7.1, a release that boosts our platform’s ability to process massive datasets from today’s firewalls and gateways. With enhanced performance and trusted accuracy, Cyfin v9.7.1 delivers scalable web monitoring for businesses of all sizes.

Scalability for Expanding Networks

As network data surges, enterprises need monitoring solutions that keep up. Cyfin v9.7.1 delivers powerful performance upgrades, building on our expertise in supporting global organizations. These improvements ensure fast, reliable insights, even in data-heavy environments.

Key enhancements include:

  • Rapid Data Imports: Threading bulk inserts into our metric server accelerates processing of large log files, enabling seamless handling of enterprise-scale data.
  • Streamlined Parsing: An optimized parser with pre-configured patterns and efficient visit analysis processes complex logs quickly while preserving accuracy.
  • Faster Session Analysis: Threaded app lookups and a new timeout configuration speed up user activity reporting across your network.

These updates position Cyfin to tackle growing data demands with ease.

Precision You Can Rely On

Cyfin excels at delivering accurate user activity insights. With v9.7.1, refinements like improved doc ID handling and removal of outdated domain checks ensure your reports are dependable for productivity, security, and compliance.

Why Cyfin Leads the Way

Cyfin v9.7.1 is built to manage the rising tide of firewall and gateway data with efficiency and precision. Features like syslog SSL cert configuration by port add flexibility for enterprise needs. This release solidifies Cyfin’s place as a top solution for web monitoring.

Scale Without Limits

From small businesses to global enterprises, Cyfin v9.7.1 adapts to your network’s demands. Discover how Cyfin can elevate your monitoring—contact our team (mailto:support@wavecrest.net) or view the v9.7.1 release notes for more.

Thank you for choosing Wavecrest. Let’s drive your monitoring forward!

The Wavecrest Team

Understanding Employee Internet Monitoring: What Cyfin Reports Show You

IEmployee internet monitoring works best when it answers real questions for the people who need answers. Cyfin by Wavecrest Computing reports on how employees use the web, using your existing firewall logs, so HR and management can see what is happening and act on it independently.

An important distinction up front: Cyfin is a reporting product. It does not block or filter websites. It tells you what happened. If you also need to control access and enforce filtering policy, that is CyBlock, our companion product. This post is about what Cyfin’s reporting gives you.

Why accurate reporting matters

Raw firewall logs mix human activity with machine noise. Software updates, background app check-ins, and embedded trackers all get logged the same way as a deliberate visit. Reports built on that data overstate activity and obscure what an employee actually did.

Cyfin filters out non-human traffic and reconstructs browsing sessions before producing a report. What you read reflects employee-initiated activity, in a format a non-technical person can interpret.

What you can see and do

Policy compliance. A written acceptable use policy only works if you can verify it is being followed. Cyfin shows actual web use against your policy, so you can see where behavior falls outside your guidelines and follow up.

Workplace investigations. When a concern comes up about a specific employee, HR can run a clear, dated report and drill down to the detail, without asking IT to interpret log data.

Productivity insight. Managers can see how time is spent across categories such as social media, streaming, shopping, news, and AI tools, and how patterns shift over time.

Web application use. See which web applications and services employees are using, including generative AI tools identified by name. That visibility is what tells you whether the tools in use align with what your organization has approved.

Training and policy refinement. Real usage data shows where guidance would help, so training addresses what people are actually doing rather than what you assume they are doing.

How it fits your environment

Cyfin is agentless. There is nothing to install on employee devices, because it reads the log data your firewall already produces. It supports the major firewalls in use today, including Palo Alto Networks, Cisco, Fortinet, Check Point, and SonicWall.

Key takeaways

  • Monitoring is not about mistrust. It is about having accurate information before making decisions that affect people.
  • Reports are only as good as the data underneath them. Filtering out non-human traffic is what makes web use reports usable.
  • HR and management can run their own reports, which keeps investigations moving and reduces the burden on IT.
  • Reporting and filtering are different jobs. Cyfin reports. CyBlock filters.

Learn more about Cyfin.


Cyfin by Wavecrest Computing has been purpose-built for employee web use reporting and investigations since 1996. Its noise-filtering engine turns raw firewall log data into clear, human-only reports that HR and management can read, understand, and act on independently. https://www.wavecrest.net • 321-953-5351ternetMonitoring #CyberSecurityEducation #WorkplaceProductivity #DigitalWorkplace #Cyfin

Introducing Our Latest Update: Artificial Intelligence Category for Cyfin and CyBlock

At Wavecrest Computing, we are committed to continually improving our products to keep pace with the ever-evolving digital landscape. Today, we are excited to announce a significant enhancement to our Cyfin and CyBlock products – the introduction of a new category: Artificial Intelligence.

What is the Artificial Intelligence Category?

As AI technologies become increasingly integral to various aspects of business and daily life, we recognized the need to provide our users with more precise and relevant categorization. Our new Artificial Intelligence category encompasses websites that employ AI technologies such as machine learning and deep learning to deliver human-like services.

This category includes platforms offering:

    • Chatbots: Interactive AI-driven customer service tools.
    • Productivity Tools: Applications designed to streamline workflow and boost efficiency using AI.
    • Summarizers: Services that condense information into digestible summaries.
    • Transcription Services: Tools that convert audio or video content into written text.
    • No-Code Solutions: Platforms enabling users to build applications without programming knowledge, powered by AI.
    • Multimedia Editing: Advanced AI-driven tools for editing images, videos, and audio.

    Why This Update Matters

    AI technologies are not just a trend; they are reshaping industries and transforming how we interact with digital content. By introducing this category, we aim to:

    • Enhance Visibility: Provide detailed insights into how and when AI technologies are being utilized within your organization.
    • Improve Management: Help IT administrators and management teams better understand and control the use of AI-based tools and services.
    • Stay Current: Ensure that our product offerings are aligned with the latest technological advancements, offering you the most up-to-date solutions.

    How It Works

    The Artificial Intelligence category is meticulously designed to target sites that are actively hosting AI functionalities, rather than those merely providing information about AI. This distinction is crucial for organizations looking to manage and monitor the practical use of AI tools in their operations.

    By leveraging our advanced categorization technology, Cyfin and CyBlock can now identify and report on AI-driven activities more accurately, providing you with a clear view of how AI technologies are impacting your network.

    Continuous Improvement

    This update is part of our ongoing commitment to enhance our products and provide our customers with the best possible tools for managing and understanding their web traffic. We are dedicated to adapting to the dynamic digital environment and ensuring that our solutions remain relevant and effective.

    Stay tuned for more updates as we continue to innovate and expand our product capabilities. If you have any questions or need assistance with the new Artificial Intelligence category, our U.S.-based expert technical support team is always here to help.

    Experience the Future of Web Filtering and Reporting with Wavecrest Computing

    To learn more about our Cyfin and CyBlock products and how the new Artificial Intelligence category can benefit your organization, visit our website or contact our support team today.

    Really? Is it really time to think about holiday shopping? Already?!

    Manage Holiday Web Usage with CyBlock

    Yes–now is the time. The holidays are right around the corner and definitely require attention now so your business can prepare for the increase in Web usage and the associated risks. There are many reasons for your business to pay close attention to Internet activity at this time of year (and all year). But there is one primary focus that could easily help with all the cyber risks to your business–managing the natural human vulnerability that cyber thieves take advantage of.

    Did you know that most breaches are initially caused by employee error? “Ninety-two percent of all incidents are, and 84 percent of all data breaches were, unintentional or inadvertent in nature,” states an article from iapp.org. No matter what kind of data loss or breach it is, human error likely played a very important role.

    Shopping season can bring out even more human vulnerabilities than usual. Malicious Web sites can look real and carry what looks like legitimate product offerings, advertising can be more enticing with hard-to-resist discounts, and e-mails can come from legitimate e-mail addresses hacked by these talented criminals. Humans’ emotional nature can make it hard to resist when we are all looking for that special or hard-to-get gift. It is important to make sure your business–and your employees–are protected by an easy-to-setup solution that is comprehensive and proactive.

    This is easier than you think. Access to a comprehensive Web management solution will allow you to manage usage in a way that suits your unique business philosophy. This includes whether you want to allow or restrict access to certain Web sites at a particular time of day, monitor usage with reporting features by analyzing trends and tracking usage, or just meet compliance and regulation requirements.

    This time of year, it is important to spend some extra time paying attention to your organization’s Web use. But Web-use management should be part of your business process and security all year round. Find a solution that is flexible enough to grow or change with you throughout the year, and for this time of year … let them shop … and know you are still being proactive and secure.

    Cyfin® provides advanced User Behavior Analytics and Reporting for a wide variety of gateway devices and log file formats. Comprehensive yet easy to use, its customized reporting capabilities supply audience-specific information with reliable metrics, easy-to-read reporting dashboards, manager-ready detailed audit reports, and Smart Engine analytics. Cyfin is available in various deployment options: Cyfin Virtual Appliance and Cyfin Forensic.

    CyBlock® Employee Web Filtering and Monitoring Solutions provide advanced Web filtering, threat protection, comprehensive employee reporting, Smart Engine analytics, easy-to-use admin and manager portals, and more. Customers can easily configure CyBlock to monitor and manage compliance with their usage policies. CyBlock is available in various deployment options: CyBlock Virtual Appliance, CyBlock Cloud, and CyBlock Hybrid.

    Wavecrest has over 25 years of proven history of providing reliable, accurate Web-use management and Advanced Log File Analyzer products across various industries. IT specialists, business managers, HR professionals, Managed Service Providers, and Forensics Investigators trust Wavecrest’s Cyfin and CyBlock products to easily decipher and manage, and report on, real employee Web activity, manage cloud services, reduce liability risks, improve productivity, save bandwidth, and control costs. Trusted by small, medium, and large government and commercial organizations worldwide. For more information on the company, products, and partners, visit Wavecrest.

    Cyfin and CyBlock Version 966 Launch – A Milestone in Web Usage Analysis

    Wavecrest is excited to announce the launch of Cyfin and CyBlock Version 966, marking a significant advancement in our nearly three-decade journey of innovation. This release is not just an update; it’s a transformational shift in how organizations understand and manage employee web usage.

    Decoding Human Action from Data: Since our inception, our core objective has been to decode human action from raw firewall connection logs. We pioneered the focus on providing a comprehensive picture of employee web usage, going beyond the narrow lens of security and legal liability sites. Over the years, our relentless refinements have set the industry benchmark for complete web usage analysis, making our reports the preferred choice for HR and management teams.

    Introducing Session Metrics: With Version 966, we are proud to introduce our evolved smart algorithm that now generates ‘session metrics’. These metrics represent a breakthrough in monitoring and analyzing web usage. A session encapsulates a series of interactions an employee has with a website or online application within a set timeframe, beginning with the initial webpage visit and concluding after a period of inactivity or logout.

    Why This Matters: This advancement simplifies how IT, HR, and management teams interpret web usage data. Understanding how employees utilize the internet is crucial for identifying potential security threats, legal liabilities, and shaping a robust compliance policy. This policy is vital for enhancing productivity while simultaneously mitigating security risks.

    Commitment to Excellence: At Wavecrest, our commitment to excellence and innovation remains unwavering. Cyfin and CyBlock Version 966 is a testament to this commitment, offering unparalleled insights into employee web usage.

    Employee Internet activity–get the right information to the right people in the right format.

    We always think of a business’ audience as outside of the business, as in a sales or technical support relationship with a prospect or customer. But we all have an audience within the business that needs to be serviced, provided assistance, and kept happy. From an IT standpoint, these internal customers can be HR, operations, financial, legal, C-Suite, and more . . . literally everyone within the company. This is why it is important that IT be provided and supported with comprehensive, easy-to-manage tools that proactively help supply internal customers with the relevant, detailed, easy-to-consume information they need. Their focus should be on how to efficiently get the right information to the right people in the right format–especially when it is critical information like Internet usage.

    Internet usage is a leading concern for companies due to risks from employee misuse, unsanctioned cloud applications, phishing e-mails, and more. Pepper Hamilton LLP, Attorneys at Law note, “Companies often are surprised to learn that their biggest security threats come from their own employees. These risks range from the use of weak passwords to clicking on corrupt internet links to theft of sensitive data.” IT needs to not only maintain the system to keep the business’ digital environment running and secure but they also need to supply critical employee Web-use information to others within their organization. These internal customers are not prepared to dig through and interpret large amounts of technical data. They require the information be easily supplied to them for when, where, and how they need to use it. So what does “the right information to the right people in the right format” really mean?

    What is the right information?

    When it comes to Web-use risks, the human factor, that is, the employee, must be the focus. Without knowing the human behavior in the organization it is impossible to define what is normal and flag anomalies that may indicate unintentional mistakes or malicious acts, identify workforce productivity changes, or determine whether an employee is in compliance with corporate policy, and more. If there is reporting on Web traffic in the organization, it may still be inadequate in showing the relevant human behavior in the workplace. It is important to reduce the “noise” that happens in data when supplying information to the internal customers. The right information means clear, pertinent, easy-to-consume information for, more than likely, a nontechnical audience.

    Who are the right people?

    It would likely be easier to just say everyone. Most employees use some form of the Internet for work functions. If they don’t, they still likely have access to the Internet through company Wi-Fi or during their break. Even then, the business is responsible for the Web use occurring on their network at any time. Knowing this, it is understandable that many people in your organization want easy access to employees’ Web activity information. Managers may want to address productivity issues, HR personnel may want to investigate a Web-use liability issue, and IT staff themselves will want to watch network performance and security. Getting the relevant information to a specific audience in the company is important and increases overall efficiency and productivity. The right people means that the information supplied to that user is specific to their responsibility. Extraneous information not only makes the recipient’s process of deciphering the data more difficult and time-consuming, but it is also a data security issue by sharing unrelated company data with others, even within the company.

    Which is the right format?

    When you view something and it just has so much information or is just difficult to read, do you actually retain or even understand the information? With mission-critical operations looming, IT no longer has time to spend on walking a recipient through report information. Requested Web-use information should be in an easy-to-read and actionable format. Having reporting dashboards can provide important benefits especially when they can be customized to offer different types of analyses for different users and therefore serve different purposes. Customizable charts and interactive, drill-down reporting features with specifically relevant information increases understanding and ends up supporting clear business decision-making. So, the right format is about allowing for flexibility for each recipient to view information in a number of different formats.

    So then . . . what is needed to get the right information to the right people in the right format and how can Wavecrest help?

    Smart Engine analytics! Without the Smart Engine and its analytics, the reporting components could not provide the adequate information that your company needs to manage employee Web use. The Smart Engine makes technical data usable and manager-ready. Smart Engine analytics provide pertinent, detailed analysis, permitting the review or investigation of trends, policy violation, Internet misuse, security issues, and ultimately, human behavior occurring in the workplace.

    With its precise, industry-leading algorithms, the Wavecrest Smart Engine is used by charts and reports to present accurate and up-to-date Web-use data. It performs functions such as determining visits and time online from Web traffic, and categorizing URLs into logical groups based on content. The Smart Engine is the key to providing understandable, easy-to-consume, manager-ready information–more precisely, the right information for right people in the right format.

    Time is precious, especially in business. Getting the right information to the right people in the right format should be easy–especially when it is critical information like Internet usage. Let us help.

    About Wavecrest

    Wavecrest has over 25 years of proven history of providing reliable, accurate Web-use management, User Behavior Analytics, and Advanced Log File Analyzer products across various industries. Managed Service Providers, IT specialists, HR professionals, Forensics Investigators, and business managers trust Wavecrest’s Cyfin and CyBlock products to manage the human factor in business Internet usage — comprehensive filtering and Web-use reporting, managing cloud services, reducing liability risks, improving productivity, saving bandwidth, and controlling costs. Trusted by small, medium, and large government and commercial organizations. For more information on the company, products, and partners, visit Wavecrest.