Watching for attack.
WHAT TO MONITOR
Authentication failures Authorisation failures Transaction failure rates Velocity anomalies Notification verification failures Privileged actions Key usage
WHY AUTHORISATION FAILURES SPECIFICALLY
They indicate someone attempting to reach resources they should not.
WHAT TO BASELINE
Normal patterns by hour and day.
WHY
Deviation is only detectable against a baseline.
WHAT TO ALERT ON IMMEDIATELY
A spike in failed payments Notification forgery attempts Privileged actions outside normal patterns Any negative balance Ledger imbalance
WHY THOSE LAST TWO
They should be impossible, so their occurrence is definitive evidence of a fault.
WHAT TO CORRELATE
Events across systems, since attacks span them.
WHAT TO RETAIN
Logs long enough to investigate, within data protection limits.
WHAT TO PROTECT
The logs themselves, from alteration.
WHAT TO REVIEW REGULARLY
Alerts that fired, and whether each was useful Patterns in dismissed alerts
WHAT TO TEST
That alerting works, by generating a condition deliberately.
WHY
Untested alerting frequently does not fire.