Captions · 1 July 2026
Quiet hours are not always good news
How to caption empty stretches on cybersecurity event charts so a quiet week is not mistaken for a clean week.
Empty space on a time series invites a story. Directors fill that space with relief. Analysts fill it with suspicion. The caption has to choose neither and state the cause if you know it.
Three quiet patterns show up constantly in UK estates. The first is a detector paused for a change window — often a Friday night, often poorly logged. The second is a site that closed for a bank holiday while the collector kept running, so the chart looks alive but the building was empty. The third is a feed that stopped without an alarm, which is the one that belongs in the risk column.
We draw known pauses as a shaded band, not as a dip in the line. A dip says volume fell. A band says we were not counting. If you do not know why a stretch is empty, the caption should say ‘cause not in the extract’ rather than ‘no incidents’. That sentence is uncomfortable in a board pack. It is also the sentence that stops last quarter’s outage being remembered as a good month.
When we prepare an incident trend briefing, the first revision often exists only to add those bands. Send the change calendar with the extract. It is cheaper than a second argument in the walkthrough.