Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Stop new spend without destroying evidence or production, then allocate every cost to legitimate demand, waste, misconfiguration, or abuse.
Capture before evidence disappears
- Export cost and usage by account, service, region, resource, tag, operation, tenant, hour, and pricing dimension.
- Preserve audit logs, deployments, autoscaling, API use, access keys, new resources, data transfer, logs, snapshots, and support case IDs.
- Compare billing to traffic, business volume, security alerts, quotas, budgets, commitments, and the last normal period.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Disable resources? | Ownership and customer impact are known or spend is clearly malicious. | Quarantine suspicious identities and stop bounded resources; protect logs and snapshots before deletion. |
| Request a billing adjustment? | Cause and containment are documented and provider policy may apply. | Open a case promptly with exact resource IDs and times; do not assume credits. |
Proof that recovery worked
- Hourly spend returns to an explained baseline and no unowned resource, region, account, or data transfer remains.
- Security review accounts for credentials and actions behind suspicious consumption.
- Invoices, credits, commitments, taxes, and internal allocation reconcile with the provider.
Controls to put in place
- Use budgets, anomaly alerts, service quotas, per-environment accounts, and mandatory ownership tags.
- Restrict expensive services and regions; expire test resources automatically.
- Review unit cost per customer action and rehearse safe spend containment.
Create a tagged sandbox cost spike. Detect it from an hourly alert, identify its actor and resource, quarantine it, estimate invoice impact, and prepare a provider case.
Contact provider billing and security support when compromise, cryptomining, account takeover, or a material invoice is possible; involve finance before changing commitments.
What this means
The cause may be legitimate growth, a loop, abusive traffic, leaked credentials, forgotten resources, or pricing behavior. Turning off everything can destroy evidence and customer data.
Warning signs
- Budget or anomaly alerts show a sudden daily or hourly increase.
- Spend rises without matching users, revenue, or planned work.
- One service, region, model, resource, or usage type dominates.
- New resources or credentials appear in audit logs.
Recover now
First 15 minutes
- Break cost down by service, account, region, resource, and usage type.
- Preserve billing, usage, identity, and audit evidence.
- Cap or stop the specific runaway consumer safely.
- Revoke exposed credentials and contain abusive traffic when indicated.
Today
- Remove orphaned resources, retry loops, public workloads, or unintended scale.
- Contact provider billing support with exact anomaly times and actions.
- Estimate committed cost and cash-flow impact.
- Add per-service budgets, quotas, and cost-to-business metrics.
Verify recovery
- Hourly cost returns to an explainable range.
- No unauthorized resources or usage continue.
- Critical data and services remain intact.
- Alerts detect a repeat before material loss.
Prepare now
Access
- Billing and security investigation access is available to two people.
Backups and evidence
- Detailed billing and audit logs have useful retention.
Contacts and ownership
- Every major cost center has an owner and normal range.
Practice
- A cost anomaly can be traced to a resource and contained.
Common mistakes
- Deleting resources before preserving evidence.
- Setting only a monthly alert.
- Assuming every spike is provider error.