SIGNAL / 01Unknown internet-facing assets
Forgotten applications, test environments, open services, and shadow infrastructure create attack paths your team may not be monitoring.
- Unexpected public services
- Expired certificates or abandoned domains
- Untracked APIs and staging environments
Immediate move: map and validate your external attack surface.
SIGNAL / 02Unusual access and privilege changes
Repeated failures, impossible travel, dormant accounts, or unexpected admin rights can indicate identity compromise.
- MFA fatigue and repeated prompts
- Privilege escalation without approval
- Logins from unfamiliar locations
Immediate move: validate authentication and privileged access controls.
SIGNAL / 03Cloud permissions expanding quietly
Broad roles, public storage, exposed secrets, and inherited permissions can turn one error into organization-wide access.
- Public storage or databases
- Long-lived keys and embedded secrets
- Roles with excessive permissions
Immediate move: review identity, storage, secrets, and permission boundaries.
SIGNAL / 04Alerts without confident action
Unclear ownership, escalation, containment, or recovery can turn a manageable event into a business crisis.
- Alerts closed without validation
- Unclear incident ownership
- Untested recovery plans
Immediate move: test detection, escalation, containment, and recovery.