FOTC
  • Products
    • Google Workspace
    • Google Cloud
    • Google hardware
    • Chrome Enterprise Premium
  • Services
        • Google Workspace
          • Google AI
          • Migration
          • Technical support
          • Management
        • Google Cloud
          • Cloud engineering as a service
          • Path to the cloud
          • Landing Zone
          • Cost audit
          • Google Cloud Care
          • Cloud anomaly detector
  • Training
    • Google Gemini
    • Google Workspace fundamentals
    • Advanced Google Workspace
    • Google Workspace for administrators
  • Customers
  • Company
    • About us
    • Partner Program
    • Careers
    • Blog
Contact
ro pl hu en
  • Privacy policy

Detect suspicious cloud behavior before spotting the cost

Cloud cost anomalies can be the first signal of a security incident. FOTC’s Cloud Anomaly Detector continuously monitors cloud billing behavior, detects unusual spending, and directs critical events to the people who can react before the problem escalates.

Book a cloud cost & security review
Billing cost / hour — EU Production
CRITICAL
Behavioral baseline vs actual spend
ANOMALY DETECTED
AI model API · €8,420 exposure
owner notified · escalation started
00:00 01:00 02:00 03:00 03:42
906x
maximum detected increase in daily spending
SecOps × FinOps × CloudOps
one connected operational process
Solution for
cloud environments
Built in response for
real operational incidents
Used by our
customers
Continuous anomaly
monitoring
Combining SecOps × FinOps ×
CloudOps
  • Product
  • How it works
  • Use cases
  • Case study
  • Pricing
  • FAQ

Receiving a bill is a bad time to discover anomalies

Without behavioral monitoring, an API key leak remains invisible until someone opens the billing dashboard or, worse, receives an invoice for cloud costs. A cloud provider alert regarding suspected abuse is sent only to the environment owner. Once an incident is detected, the damage can already be significant. Our Cloud Anomaly Detector closes this gap: alerts are sent simultaneously to you and to the FOTC team, allowing you to detect threats early on and respond calmly.

A weekend without monitoring –
peace that turns into a fire


00:00 API key exposed in a public repository.
00:18 Unauthorized requests to a paid API begin.
02:40 Cloud costs accelerate – no threshold configured.
06:15 No one has opened the billing dashboard.
09:00 Finance still sees nothing unusual.
Monday The invoice reveals the incident. Margin is gone.

No oversight → Leak → Abuse → Detection on the invoice → Emergency action

A weekend with FOTC anomaly detection –
rapid response, no major consequences


01:45 pm Massive use of stolen keys is beginning.
04:30 am The first data of the day is sent to the billing export system; the detector triggers an alarm and escalates the issue.
Morning The customer starts the day with an alert that provides the full context, rather than finding out everything from an invoice a month later.

Detection → Context → Ownership → Escalation → Response

Cost is a security signal –
it doesn't spike without a reason

Unexpected spending growth in the cloud is rarely accidental. Behind the number, there is almost always a technical cause or a security incident.

Common causes indicated by the cost signal


  • Leaked or stolen API key
  • Compromised service or user account
  • Crypto mining or abusive workloads
  • Uncontrolled test workloads
  • Misconfiguration or automation error
  • Unexpected scaling or deployment error

Unusual cloud cost behavior


  • Sudden hourly spikes
  • Daily increases multiple times above the average
  • Sustained growth
  • Unusual patterns at the service level
  • Projected budget overruns

This is the layer FOTC monitors so that financial signals become security questions early.

An alert is just the beginning. Behavioral observation allows you to see the change.

Native cloud alerts are an important part of managing your cloud environment. We combine them with behavioral detection, context, accountability, and operational response.

Standard alert alone
Useful, but still just a notification.

  • Reacts only to static thresholds
  • Messages can be overlooked
  • Accountability is unclear
  • No context of the account or service
  • No escalation path
  • No operational actions
Detection & response process
A clear path from unusual spending to action.

  • Behavioral detection against baseline
  • Severity classification (Critical/Warning + “confirmed as planned” status)
  • Customer and billing account mapping
  • Service-level cost context
  • The event is logged in the CRM and assigned to the account manager
  • Critical event escalation
  • Expert analysis and response support

See how the
Cloud Anomaly Detector works

One continuous task loop that turns billing behavior signals into a response with an assigned owner, escalation, and (if needed) expert support.

01

Monitors

Continuously observes supported cloud platform billing accounts (any size, any currency).

02

Learns

Builds a behavioral baseline of normal spending for each account individually.

03

Detects

Flags statistically significant deviations – spikes, sustained growth, overruns.

04

Classifies

Assesses severity based on size, value, duration, persistence, and rate of growth.

05

Notifies

Delivers to the team: channel alert, CRM task, account owner assignment.

06

Escalates

Routes critical events with phone or pager escalation (in the appropriate package).

07

Reacts

Includes expert analysis, source identification, and impact-reduction support.

PRODUCT DASHBOARD

Monitor changes in the product dashboard

This is your near real-time command center. Real threats are visually separated from expected activity, enabling operators to act on signal, not noise.

Active anomalies
7
across 12 billing accounts
Critical now
1
escalation in progress
Monitored accounts
12
in various currencies
Financial exposure
€10.4k
estimated, last 24h
AI model API CRITICAL
EU Production · detected 03:42 CET
€8,420
+12,480% vs baseline
Generative AI AI Platform
Owner: Cloud Operations Escalated CRM task created
Data Warehouse MEDIUM
Analytics-PL · detected 01:10 CET
€1,240
+310% vs baseline
Data Warehouse Data Storage
Owner: Data Platform In analysis CRM task created
Virtual Machines MEDIUM
Staging-EU · detected 22:50 CET
€760
+180% vs baseline
Virtual Machines
Owner: SRE Acknowledged Muted — duplicate
AI Platform EXPECTED
ML-Research · detected 14:05 CET
€2,010
+7.6× — planned workload
AI Platform Managed Kubernetes
Owner: ML Team Confirmed as planned Owner confirmed
Anomaly trend — 24h ▲ rising
00:0012:00Now
Top services by spend share
Generative AI / AI model 62%
AI Platform 18%
Data Warehouse / Data Storage 12%
Virtual Machines / Managed Kubernetes 8%
🛡️
Monitoring operates continuously, and critical incidents have a dedicated escalation channel to FOTC engineers.

Dashboard available in Polish and English; designed for the customer portal.

See live demo

Read the story of a customer who significantly reduced losses after a key leak thanks to the FOTC sentinel

One of our customers had a billing account with a stable, low daily cost. An unauthorized event raised spending hundreds of times above the norm. By using the Cloud Anomaly Detector, it was caught in the first cycle, classified as critical, and rightly maintained as critical when the unusual level persisted.

Daily cost vs baseline
1st cycle
time to detection
Held critical
did not adapt to abuse
Stable low baseline
Account with predictable, low daily costs.
Cost explodes
Spending increased hundreds of times above the norm within a few hours.
Detected & classified as critical
We detected the event in the first cycle and maintained it as critical the next day as the abuse continued.
Source identified
We identified a leaked API key for the AI service and contacted the customer.
Exposure mitigated
The customer rotated the keys and stopped the abuse within a few hours, limiting further costs.

One leaked key can turn a quiet weekend into a massive cloud bill.

Not every anomaly is an attack

In the second case, a customer's daily cost increased ~7.6× above the norm. Our anomaly detector identified this, generated an alert, created a CRM task, and assigned an account owner, who confirmed it was planned work. The value of detection also lies in quickly distinguishing expected from malicious activity.

Read the full analysis of both incidents

Limit the harmful impact on your business and margin

Implementing anomaly detection translates into business outcomes that affect not only IT but also security and finance areas.

€ 501,000

The cost of three days without monitoring (reported incident)

3 min 16 sec

The time it took for the automated system to take over a dozen or so projects (28 keys, 9 service accounts)

906x

An increase in the daily cost exposed by the detector at our client's site

04:30 am

The time when the CRITICAL ticket was sent to the team—before the client started their day

✓ Protection of margin and financial liquidity
✓ Reduced exposure to uncontrolled costs
✓ Faster response, clear accountability
✓ Fewer unexpected fires
✓ Visibility across billing accounts
✓ Governance and compliance support

Connect SecOps, FinOps, and CloudOps

Security

Treat unexpected spending as a possible threat signal and act before it becomes an incident report.

  • • Early detection of threat signals
  • • Investigation of keys, accounts, and permissions
  • • Strengthening escalation and on-call response procedures

Cloud Operations

Get clarity on which service changed, where, and who is responsible for it – without manual dashboard reviews.

  • • Rapid identification of unusual services
  • • Linking events with the right owner
  • • Shorter investigation time

Finance

Make cloud costs predictable and protect budgets and margins from unexpected expenses.

  • • Improved cost predictability
  • • Early detection of unusual spending
  • • Budget and margin safeguarding

Leadership

Gain visibility, define accountability, and limit operational and financial risk.

  • • Clear visibility across the estate
  • • Defined accountability and ownership
  • • Lower operational and financial risk

Discover the scope of service

As part of our cost anomaly detection service, we monitor and classify incidents and escalate them to the appropriate person—we do not directly interfere with your environment. You manage the dashboard yourself: you can view your billing, set rules, and configure email and SMS alerts.

Cloud Anomaly Detector

55 USD or 50 EUR/month

Get continuous detection and escalation.

Scope:
  • ✓ Customer dashboard—your billing information in our detector
  • ✓ Email and SMS alerts
  • ✓ Product updates
  • ✓ Incident analysis
  • ✓ Cost anomaly monitoring
  • ✓ Custom rule configuration
  • ✓ Monitoring by FOTC
  • ✓ Escalation and support
Let's talk

Cloud Care

Do you want us to take action, not just notify you?

As part of this managed service, FOTC operates within your environment with an agreed-upon scope of permissions:
  • ✓ we rotate keys
  • ✓ we lock compromised service accounts
  • ✓ we stop abuse
Let's talk

Test your operational readiness. At 03:00 AM, would your organization know?

Answer honestly. If any answer is unclear, your current alerting process may not be sufficient.

Security 1. Which key or credential was compromised?
Cloud Ops 2. Which billing account and customer are affected?
Cloud Ops 3. Who receives the alert, and do they see it after a few hours?
Security 4. Who is responsible for the response at 03:00 AM?
FinOps 5. How quickly can you reach the affected customer?
Security 6. Which mitigating actions can be taken without additional approval?
FinOps 7. Is the event malicious, or is it expected activity?
Readiness score
0 / 7 EXPOSED
Security 0%
Cloud Ops 0%
FinOps 0%

Several answers are unclear. Your current alerting process might not be enough—a cloud cost and security review will close the gaps.

Check your readiness

PRIORITY ACTIONS

Schedule a cloud cost & security review

A cloud incident should not be detected only when costs are settled. Talk to our cloud expert. We will review your alerts, permissions, and escalation process and show how anomaly monitoring will strengthen your environment.

Request a free consultation

    FAQ - honest answers, no overpromises

    The system learns the normal spending behavior of each billing account (its typical hourly and daily patterns) and constantly compares current spending against this baseline. It marks statistically significant deviations: sudden hourly spikes, daily increases multiple times above the average, sustained growth, or projected monthly budget overruns, and then classifies each event by severity (Warning/ Critical) so that the most serious risks appear first. Because the baseline is calculated per account, an amount normal for one customer might be an anomaly for another. We monitor new accounts with large budgets using a separate detection system from the very first hours—without waiting for a history to build up.

    No. Static thresholds are supported and still useful, but the core is behavioral—each account is measured against its own learned baseline, not a single fixed number. This allows it to catch a significant change that a rigid limit would miss, i.e., spikes just below the threshold or costs growing gradually without crossing a hard limit, while still respecting your configured budgets.

    No. Cloud Anomaly Detector focuses on detection, context, notification, and escalation—it does not turn off or modify resources itself. Any change in the environment, e.g., rotating a key, limiting an account, or stopping a workload, is a defined action involving a human. The scope of what FOTC can perform is agreed upon individually, so nothing changes without a clear mandate.

    Monitoring runs continuously, around the clock, including at night and on weekends when incidents are easiest to overlook. The human response—who acts, how quickly, and through which channel (chat, CRM task, phone, or pager)—depends on the scope of service and may be covered by a separate SLA. We consciously do not promise a single fixed response time here, as it is set to match actual agreement monitoring—patients. We also monitor ourselves: the freshness of Google’s billing data and the health of our own detector. A halted billing export alerts us just as much as a customer anomaly—silence in the data never means peace of mind for us.

    It does not replace but supplements, so we recommend keeping native alerts. Google Cloud budget alerts are an important element, but the alert itself is just a notification. FOTC adds an operational layer around it: behavioral detection against the baseline, severity classification, customer and account context, clearly assigned responsibility, an escalation path, and (in an expanded scope) expert response support.

    Cloud Anomaly Detector reacts quickly to sudden or significant anomalies, usually within its detection cycle. Two honest notes: Google Cloud billing data can have reporting delays, so the exact time depends on when consumption is reported, and a newly connected account needs a short learning period before a reliable baseline is established. It is also less suited for very slow, multi-week drift where the change in a single cycle is small—such a pattern is better caught by periodic cost reviews. We explicitly report accounts that we cannot yet evaluate (e.g., due to an insufficient history) as “unrated,” rather than showing them as “no anomalies.” You always know what is being monitored and what is not.

    Yes. The Cloud Anomaly Detector supports multiple billing accounts of various sizes and in different currencies from a single console and maps each anomaly to the correct customer, account, and owner. This ensures a large or multi-entity environment remains visible in one place rather than scattered across separate dashboards, and it’s clear who should react when a change occurs.n one place rather than scattered across separate dashboards, and it’s clear who should react when a change occurs.

    Yes, as part of the Cloud Care service or a separate Cloud Security Audit. This can include a review of IAM permissions and roles, service accounts and their keys, potential API key exposure, billing alert configuration, and escalation procedures. The goal is not just to resolve the current event but also to provide specific recommendations to reduce the risk of the same type of incident recurring.

    LLMjacking is a new phenomenon that involves the illegal acquisition of cloud credentials—not to steal data, but to obtain access keys to paid language models in order to use them at the victim’s expense or resell them. As part of the Cloud Anomaly Detector service, we regularly review whether your projects have spending limits for AI services (Gemini, Gemini Enterprise Agent Platform)—the primary targets of key theft—and recommend a limit based on actual usage. We also configure budgets with threshold alerts. Limits and alerts help quickly detect an attack, but they do not block it—nothing shuts down automatically, because every change in the environment is a human decision.

    Yes, you don’t need to have a billing account with FOTC. You can connect Cloud Anomaly Detector to any environment: all you need is a standard billing export to BigQuery and read access for our service account—you can grant it with just two clicks. We don’t install anything to run the service, and we don’t touch your resources—we only see billing data.

    Services
    • Cloud Infrastructure Strategy Roadmap
    • Landing Zone
    • Training
    Products
    • Google Workspace
    • Google Cloud
    • Google Workspace for Education
    Industry
    • Education
    • Gaming
    • Government
    • Healthcare
    • Retail
    • Small and medium businesses
    Knowledge
    • Blog
    • Case Studies
    • NIS2 directive
    Company
    • About us
    • Career
    • Contact
    • Partner program
    • Google Workspace Support
    • Privacy Policy
    • Regulations
    Copyright © 2014 – 2026 Fly On The Cloud sp. z o.o. KRS: 0000500884, NIP: 8971797086, REGON: 022370270