UEBA (User and Entity Behavior Analytics) uses machine learning to model typical behavior of users and systems and detect deviations. If an employee suddenly logs in at night from an unusual country or accesses data outside their normal pattern, UEBA raises an alert. In an ISMS, UEBA complements rule-based detection with a behavioral component. It is particularly valuable for detecting insider threats and compromised accounts — scenarios where traditional signature-based tools fall short.