FOTC
  • Products
    • Google Workspace
    • Google Cloud
    • Google hardware
    • Zendesk
    • Pipedrive
    • Worksmile
    • Workvivo
  • Services
        • Google Workspace
          • Google AI
          • Migration
          • Technical support
          • Management
        • Google Cloud
          • Cloud engineering as a service
          • Path to the cloud
          • Landing Zone
          • Cost audit
          • Google Cloud Care
  • Training
    • Google Gemini
    • Google Workspace fundamentals
    • Advanced Google Workspace
    • Google Workspace for administrators
  • Customers
  • Company
    • About us
    • Partner Program
    • Careers
    • Blog
Contact
ro pl hu en
  • Privacy policy

Detect suspicious cloud behavior before spotting the cost

Cloud cost anomalies can be the first signal of a security incident. FOTC’s Cloud Anomaly Detector continuously monitors Google Cloud billing behavior, detects unusual spending, and directs critical events to the people who can react before the problem escalates.

Book a cloud cost & security review
Billing cost / hour — EU Production
CRITICAL
Behavioral baseline vs actual spend
ANOMALY DETECTED
Gemini API · €8,420 exposure
owner notified · escalation started
00:00 01:00 02:00 03:00 03:42
906x
maximum detected increase in daily spending
SecOps × FinOps × CloudOps
one connected operational process
Solution for
Google Cloud environments
Built in response for
real operational incidents
Used by our
customers
Continuous anomaly
monitoring
Combining SecOps × FinOps ×
CloudOps
  • Product
  • How it works
  • Use cases
  • Case study
  • Pricing
  • FAQ

Receiving a bill is a bad time to discover anomalies

Without behavioral monitoring, an API key leak remains invisible until someone opens the billing dashboard or, worse, receives an invoice for cloud costs. A Google alert regarding suspected abuse is sent only to the environment owner. Once an incident is detected, the damage can already be significant. Our Cloud Anomaly Detector closes this gap: alerts are sent simultaneously to you and to the FOTC team, allowing you to detect threats early on and respond calmly.

A weekend without monitoring –
peace that turns into a fire


00:00 API key exposed in a public repository.
00:18 Unauthorized requests to a paid API begin.
02:40 Cloud costs accelerate – no threshold configured.
06:15 No one has opened the billing dashboard.
09:00 Finance still sees nothing unusual.
Monday The invoice reveals the incident. Margin is gone.

No oversight → Leak → Abuse → Detection on the invoice → Emergency action

A weekend with FOTC anomaly detection –
rapid response, no major consequences


01:45 pm Massive use of stolen keys is beginning.
04:30 am The first data of the day is sent to the billing export system; the detector triggers an alarm and escalates the issue.
Morning The customer starts the day with an alert that provides the full context, rather than finding out everything from an invoice a month later.

Detection → Context → Ownership → Escalation → Response

Cost is a security signal –
it doesn't spike without a reason

Unexpected spending growth in Google Cloud is rarely just a billing issue. Very often, it is an operational symptom of unauthorized activity, credential leakage, or a misconfiguration that needs to be addressed before costs compound.

Common causes indicated by the cost signal


  • Leaked or stolen API key
  • Compromised service or user account
  • Crypto mining or abusive workloads
  • Uncontrolled test workloads
  • Misconfiguration or automation error
  • Unexpected scaling or deployment error

Unusual cloud cost behavior


  • Sudden hourly spikes
  • Daily increases multiple times above the average
  • Sustained growth
  • Unusual patterns at the service level
  • Projected budget overruns

This is the layer FOTC monitors so that a cost surge becomes an immediate signal to react, not a surprise on your invoice.

An alert is just the beginning. Behavioral observation allows you to see the change.

Native Google Cloud alerts are an important element of cloud governance, but an alert alone doesn't stop an incident. It lacks behavioral context, severity classification, and a defined operational path from notification to response.

Standard alert alone
Useful, but still just a notification.

  • Reacts only to static thresholds
  • Messages can be overlooked
  • Accountability is unclear
  • No context of the account or service
  • No escalation path
  • No operational actions
Detection & response process
A clear path from unusual spending to action.

  • Behavioral detection against baseline
  • Severity classification (Critical/Warning + “confirmed as planned” status)
  • Customer and billing account mapping
  • Service-level cost context
  • The event is logged in the CRM and assigned to the account manager
  • Critical event escalation
  • Expert analysis and response support

See how the
Cloud Anomaly Detector works

One continuous task loop that turns billing behavior signals into a response with an assigned owner, escalation, and (if needed) expert support.

01

Monitors

Continuously observes Google Cloud billing accounts (any size, any currency).

02

Learns

Builds a behavioral baseline of normal spending for each account individually.

03

Detects

Flags statistically significant deviations – spikes, sustained growth, overruns.

04

Classifies

Assesses severity based on size, value, duration, persistence, and rate of growth.

05

Notifies

Delivers to the team: channel alert, CRM task, account owner assignment.

06

Escalates

Routes critical events with phone or pager escalation (in the appropriate package).

07

Reacts

Includes expert analysis, source identification, and impact-reduction support.

PRODUCT DASHBOARD

Monitor changes in the product dashboard

This is your near real-time command center. Real threats are visually separated from expected activity, enabling operators to act on signal, not noise.

Active anomalies
7
across 12 billing accounts
Critical now
1
escalation in progress
Monitored accounts
12
in various currencies
Financial exposure
€10.4k
estimated, last 24h
Gemini API CRITICAL
EU Production · detected 03:42 CET
€8,420
+12,480% vs baseline
Generative AI Vertex AI
Owner: Cloud Operations Escalated CRM task created
BigQuery MEDIUM
Analytics-PL · detected 01:10 CET
€1,240
+310% vs baseline
BigQuery Storage
Owner: Data Platform In analysis CRM task created
Compute Engine MEDIUM
Staging-EU · detected 22:50 CET
€760
+180% vs baseline
Compute Engine
Owner: SRE Acknowledged Muted — duplicate
Vertex AI EXPECTED
ML-Research · detected 14:05 CET
€2,010
+7.6× — planned workload
Vertex AI GKE
Owner: ML Team Confirmed as planned Owner confirmed
Anomaly trend — 24h ▲ rising
00:0012:00Now
Top services by spend share
Generative AI / Gemini 62%
Vertex AI 18%
BigQuery / Storage 12%
Compute Engine / GKE 8%
🛡️
Monitoring operates continuously, and critical incidents have a dedicated escalation channel to FOTC engineers.

Dashboard available in Polish and English; designed for the customer portal.

See live demo

Read the story of a customer who significantly reduced losses after a key leak thanks to the FOTC Cloud Anomaly Detector

One of our customers had a billing account with a stable, low daily cost. An unauthorized event raised spending hundreds of times above the norm. By using the Cloud Anomaly Detector, it was caught in the first cycle, classified as critical, and rightly maintained as critical when the unusual level persisted.

Daily cost vs baseline
1st cycle
time to detection
Held critical
did not adapt to abuse
Stable low baseline
Account with predictable, low daily costs.
Cost explodes
Spending increased hundreds of times above the norm within a few hours.
Detected & classified as critical
We detected the event in the first cycle and maintained it as critical the next day as the abuse continued.
Source identified
We identified a leaked Gemini API key and contacted the customer.
Exposure mitigated
The customer rotated the keys and stopped the abuse within a few hours, limiting further costs.

One leaked key can turn a quiet weekend into a massive cloud bill.

Not every anomaly is an attack

In the second case, a customer's daily cost increased ~7.6× above the norm. Our Cloud Anomaly Detector identified this, generated an alert, created a CRM task, and assigned an account owner, who confirmed it was planned work. The value of detection also lies in quickly distinguishing expected from malicious activity.

Read the full analysis of both incidents

Limit the harmful impact on your business and margin

Implementing anomaly detection translates into business outcomes that affect not only IT but also security and finance areas.

€ 501,000

The cost of three days without monitoring (reported incident)

3 min 16 sec

The time it took for the automated system to take over a dozen or so projects (28 keys, 9 service accounts)

906x

An increase in the daily cost exposed by the detector at our client's site

04:30 am

The time when the CRITICAL ticket was sent to the team—before the client started their day

✓ Protection of margin and financial liquidity
✓ Reduced exposure to uncontrolled costs
✓ Faster response, clear accountability
✓ Fewer unexpected fires
✓ Visibility across billing accounts
✓ Governance and compliance support

Connect SecOps, FinOps, and CloudOps

Security

Treat unexpected spending as a possible threat signal and act before it becomes an incident report.

  • • Early detection of threat signals
  • • Investigation of keys, accounts, and permissions
  • • Strengthening escalation and on-call response procedures

Cloud Operations

Get clarity on which service changed, where, and who is responsible for it – without manual dashboard reviews.

  • • Rapid identification of unusual services
  • • Linking events with the right owner
  • • Shorter investigation time

Finance

Make cloud costs predictable and protect budgets and margins from unexpected expenses.

  • • Improved cost predictability
  • • Early detection of unusual spending
  • • Budget and margin safeguarding

Leadership

Gain visibility, define accountability, and limit operational and financial risk.

  • • Clear visibility across the estate
  • • Defined accountability and ownership
  • • Lower operational and financial risk

Discover the scope of service

As part of our cost anomaly detection service, we monitor and classify incidents and escalate them to the appropriate person—we do not directly interfere with your environment. You manage the dashboard yourself: you can view your billing, set rules, and configure email and SMS alerts.

Cloud Anomaly Detector

55 USD or 50 EUR/month

Get continuous detection and escalation.

Scope:
  • ✓ Customer dashboard—your billing information in our detector
  • ✓ Email and SMS alerts
  • ✓ Product updates
  • ✓ Incident analysis
  • ✓ Cost anomaly monitoring
  • ✓ Custom rule configuration
  • ✓ Monitoring by FOTC
  • ✓ Escalation and support
Let's talk

Cloud Care

Do you want us to take action, not just notify you?

As part of this managed service, FOTC operates within your environment with an agreed-upon scope of permissions:
  • ✓ we rotate keys
  • ✓ we lock compromised service accounts
  • ✓ we stop abuse
Let's talk

Test your operational readiness. At 03:00 AM, would your organization know?

Answer honestly. If any answer is unclear, your current alerting process may not be sufficient.

Security 1. Which key or credential was compromised?
Cloud Ops 2. Which billing account and customer are affected?
Cloud Ops 3. Who receives the alert, and do they see it after a few hours?
Security 4. Who is responsible for the response at 03:00 AM?
FinOps 5. How quickly can you reach the affected customer?
Security 6. Which mitigating actions can be taken without additional approval?
FinOps 7. Is the event malicious, or is it expected activity?
Readiness score
0 / 7 EXPOSED
Security 0%
Cloud Ops 0%
FinOps 0%

Multiple answers indicate gaps. The current alerting process may not suffice — a cloud cost & security review will close the gaps.

Check your readiness

PRIORITY ACTIONS

Schedule a cloud cost & security review

A cloud incident should not be detected only when costs are settled. Talk to our Google Cloud expert. We will review your alerts, permissions, and escalation process and show how anomaly monitoring will strengthen your environment.

Request a free consultation

Services
  • Cloud Infrastructure Strategy Roadmap
  • Landing Zone
  • Training
Products
  • Google Workspace
  • Google Cloud
  • Google Workspace for Education
Industry
  • Education
  • Gaming
  • Government
  • Healthcare
  • Retail
  • Small and medium businesses
Knowledge
  • Blog
  • Case Studies
  • NIS2 directive
Company
  • About us
  • Career
  • Contact
  • Partner program
  • Google Workspace Support
  • Privacy Policy
  • Regulations
Copyright © 2014 – 2026 Fly On The Cloud sp. z o.o. KRS: 0000500884, NIP: 8971797086, REGON: 022370270