Detect suspicious cloud behavior before spotting the cost
Cloud cost anomalies can be the first signal of a security incident. FOTC’s Cloud Anomaly Detector continuously monitors cloud billing behavior, detects unusual spending, and directs critical events to the people who can react before the problem escalates.
cloud environments
real operational incidents
customers
monitoring
CloudOps
Receiving a bill is a bad time to discover anomalies
Without behavioral monitoring, an API key leak remains invisible until someone opens the billing dashboard or, worse, receives an invoice for cloud costs. A cloud provider alert regarding suspected abuse is sent only to the environment owner. Once an incident is detected, the damage can already be significant. Our Cloud Anomaly Detector closes this gap: alerts are sent simultaneously to you and to the FOTC team, allowing you to detect threats early on and respond calmly.
A weekend without monitoring –
peace that turns into a fire
A weekend with FOTC anomaly detection –
rapid response, no major consequences
Cost is a security signal –
it doesn't spike without a reason
Unexpected spending growth in the cloud is rarely accidental. Behind the number, there is almost always a technical cause or a security incident.
Common causes indicated by the cost signal
- Leaked or stolen API key
- Compromised service or user account
- Crypto mining or abusive workloads
- Uncontrolled test workloads
- Misconfiguration or automation error
- Unexpected scaling or deployment error
Unusual cloud cost behavior
- Sudden hourly spikes
- Daily increases multiple times above the average
- Sustained growth
- Unusual patterns at the service level
- Projected budget overruns
This is the layer FOTC monitors so that financial signals become security questions early.
An alert is just the beginning. Behavioral observation allows you to see the change.
Native cloud alerts are an important part of managing your cloud environment. We combine them with behavioral detection, context, accountability, and operational response.
Useful, but still just a notification.
- Reacts only to static thresholds
- Messages can be overlooked
- Accountability is unclear
- No context of the account or service
- No escalation path
- No operational actions
A clear path from unusual spending to action.
- Behavioral detection against baseline
- Severity classification (Critical/Warning + “confirmed as planned” status)
- Customer and billing account mapping
- Service-level cost context
- The event is logged in the CRM and assigned to the account manager
- Critical event escalation
- Expert analysis and response support
See how the
Cloud Anomaly Detector works
One continuous task loop that turns billing behavior signals into a response with an assigned owner, escalation, and (if needed) expert support.
Monitor changes in the product dashboard
This is your near real-time command center. Real threats are visually separated from expected activity, enabling operators to act on signal, not noise.
Dashboard available in Polish and English; designed for the customer portal.
See live demoRead the story of a customer who significantly reduced losses after a key leak thanks to the FOTC sentinel
One of our customers had a billing account with a stable, low daily cost. An unauthorized event raised spending hundreds of times above the norm. By using the Cloud Anomaly Detector, it was caught in the first cycle, classified as critical, and rightly maintained as critical when the unusual level persisted.
One leaked key can turn a quiet weekend into a massive cloud bill.
Not every anomaly is an attack
In the second case, a customer's daily cost increased ~7.6× above the norm. Our anomaly detector identified this, generated an alert, created a CRM task, and assigned an account owner, who confirmed it was planned work. The value of detection also lies in quickly distinguishing expected from malicious activity.
Limit the harmful impact on your business and margin
Implementing anomaly detection translates into business outcomes that affect not only IT but also security and finance areas.
The cost of three days without monitoring (reported incident)
The time it took for the automated system to take over a dozen or so projects (28 keys, 9 service accounts)
An increase in the daily cost exposed by the detector at our client's site
The time when the CRITICAL ticket was sent to the team—before the client started their day
Connect SecOps, FinOps, and CloudOps
Security
Treat unexpected spending as a possible threat signal and act before it becomes an incident report.
- • Early detection of threat signals
- • Investigation of keys, accounts, and permissions
- • Strengthening escalation and on-call response procedures
Cloud Operations
Get clarity on which service changed, where, and who is responsible for it – without manual dashboard reviews.
- • Rapid identification of unusual services
- • Linking events with the right owner
- • Shorter investigation time
Finance
Make cloud costs predictable and protect budgets and margins from unexpected expenses.
- • Improved cost predictability
- • Early detection of unusual spending
- • Budget and margin safeguarding
Leadership
Gain visibility, define accountability, and limit operational and financial risk.
- • Clear visibility across the estate
- • Defined accountability and ownership
- • Lower operational and financial risk
Discover the scope of service
As part of our cost anomaly detection service, we monitor and classify incidents and escalate them to the appropriate person—we do not directly interfere with your environment. You manage the dashboard yourself: you can view your billing, set rules, and configure email and SMS alerts.
Cloud Anomaly Detector
Get continuous detection and escalation.
- ✓ Customer dashboard—your billing information in our detector
- ✓ Email and SMS alerts
- ✓ Product updates
- ✓ Incident analysis
- ✓ Cost anomaly monitoring
- ✓ Custom rule configuration
- ✓ Monitoring by FOTC
- ✓ Escalation and support
Cloud Care
Do you want us to take action, not just notify you?
- ✓ we rotate keys
- ✓ we lock compromised service accounts
- ✓ we stop abuse
Test your operational readiness. At 03:00 AM, would your organization know?
Answer honestly. If any answer is unclear, your current alerting process may not be sufficient.
Several answers are unclear. Your current alerting process might not be enough—a cloud cost and security review will close the gaps.
PRIORITY ACTIONS
Schedule a cloud cost & security review
A cloud incident should not be detected only when costs are settled. Talk to our cloud expert. We will review your alerts, permissions, and escalation process and show how anomaly monitoring will strengthen your environment.
Request a free consultation
FAQ - honest answers, no overpromises
The system learns the normal spending behavior of each billing account (its typical hourly and daily patterns) and constantly compares current spending against this baseline. It marks statistically significant deviations: sudden hourly spikes, daily increases multiple times above the average, sustained growth, or projected monthly budget overruns, and then classifies each event by severity (Warning/ Critical) so that the most serious risks appear first. Because the baseline is calculated per account, an amount normal for one customer might be an anomaly for another. We monitor new accounts with large budgets using a separate detection system from the very first hours—without waiting for a history to build up.
No. Static thresholds are supported and still useful, but the core is behavioral—each account is measured against its own learned baseline, not a single fixed number. This allows it to catch a significant change that a rigid limit would miss, i.e., spikes just below the threshold or costs growing gradually without crossing a hard limit, while still respecting your configured budgets.
No. Cloud Anomaly Detector focuses on detection, context, notification, and escalation—it does not turn off or modify resources itself. Any change in the environment, e.g., rotating a key, limiting an account, or stopping a workload, is a defined action involving a human. The scope of what FOTC can perform is agreed upon individually, so nothing changes without a clear mandate.
Monitoring runs continuously, around the clock, including at night and on weekends when incidents are easiest to overlook. The human response—who acts, how quickly, and through which channel (chat, CRM task, phone, or pager)—depends on the scope of service and may be covered by a separate SLA. We consciously do not promise a single fixed response time here, as it is set to match actual agreement monitoring—patients. We also monitor ourselves: the freshness of Google’s billing data and the health of our own detector. A halted billing export alerts us just as much as a customer anomaly—silence in the data never means peace of mind for us.
It does not replace but supplements, so we recommend keeping native alerts. Google Cloud budget alerts are an important element, but the alert itself is just a notification. FOTC adds an operational layer around it: behavioral detection against the baseline, severity classification, customer and account context, clearly assigned responsibility, an escalation path, and (in an expanded scope) expert response support.
Cloud Anomaly Detector reacts quickly to sudden or significant anomalies, usually within its detection cycle. Two honest notes: Google Cloud billing data can have reporting delays, so the exact time depends on when consumption is reported, and a newly connected account needs a short learning period before a reliable baseline is established. It is also less suited for very slow, multi-week drift where the change in a single cycle is small—such a pattern is better caught by periodic cost reviews. We explicitly report accounts that we cannot yet evaluate (e.g., due to an insufficient history) as “unrated,” rather than showing them as “no anomalies.” You always know what is being monitored and what is not.
Yes. The Cloud Anomaly Detector supports multiple billing accounts of various sizes and in different currencies from a single console and maps each anomaly to the correct customer, account, and owner. This ensures a large or multi-entity environment remains visible in one place rather than scattered across separate dashboards, and it’s clear who should react when a change occurs.n one place rather than scattered across separate dashboards, and it’s clear who should react when a change occurs.
Yes, as part of the Cloud Care service or a separate Cloud Security Audit. This can include a review of IAM permissions and roles, service accounts and their keys, potential API key exposure, billing alert configuration, and escalation procedures. The goal is not just to resolve the current event but also to provide specific recommendations to reduce the risk of the same type of incident recurring.
LLMjacking is a new phenomenon that involves the illegal acquisition of cloud credentials—not to steal data, but to obtain access keys to paid language models in order to use them at the victim’s expense or resell them. As part of the Cloud Anomaly Detector service, we regularly review whether your projects have spending limits for AI services (Gemini, Gemini Enterprise Agent Platform)—the primary targets of key theft—and recommend a limit based on actual usage. We also configure budgets with threshold alerts. Limits and alerts help quickly detect an attack, but they do not block it—nothing shuts down automatically, because every change in the environment is a human decision.
Yes, you don’t need to have a billing account with FOTC. You can connect Cloud Anomaly Detector to any environment: all you need is a standard billing export to BigQuery and read access for our service account—you can grant it with just two clicks. We don’t install anything to run the service, and we don’t touch your resources—we only see billing data.