Monitoring rules are most effective when configured with your organization's specific context in mind. The following use cases illustrate how different industries and teams can configure rules to reduce noise and surface the threats that matter most to their environment.
Each example includes a suggested target audience, a recommended rule configuration, and a real-world scenario showing the rule in action. Use these as starting templates and refine the criteria based on your own technology stack, geography, and risk tolerance.
Financial Services & Fintech
Target audience
Security Analysts, Fraud Teams, CISOs
Financial institutions face a unique combination of high-value targets, regulatory scrutiny, and sector-specific threats. This rule configuration focuses on fraud schemes, payment system attacks, and threat actors known to target banks and fintech platforms.
Suggested rule configuration
Target industry: Finance and Insurance
Location: your primary operating region(s)
Types of threats: Ransomware, Data Breach, Malware
Terms: PIX, Open Banking, TED, SWIFT, wire transfer, card skimming (in English only)
Threat actors: known financially motivated groups such as FIN7, Lazarus
Risk level: High or Critical
Use case example
Maria leads threat intelligence at a mid-size Brazilian bank. Her monitoring rule combines Location: Brazil, Industry: Finance, and Terms: PIX and Open Banking. Within days of activating it, she receives an alert about a new malware campaign targeting PIX transaction APIs. Her team patches the vulnerable endpoint before any transaction is compromised.
Retail & E-commerce
Target audience
Security Operations, IT Risk, Fraud Prevention Teams
Retail environments are exposed to payment fraud, credential stuffing, and seasonal attack spikes around high-traffic periods like Black Friday and Cyber Monday. Rules for this sector benefit from time-aware terms and e-commerce platform coverage.
Suggested rule configuration
Target industry: Retail and E-commerce
Types of threats: Data Breach, Injection Attacks, Malware
Terms: Black Friday, Cyber Monday, checkout, loyalty program, gift card (in English only)
Technologies: Magento, Shopify, WooCommerce, payment gateway
Risk level: High or Critical
Use case example
Lucas manages security at a large Brazilian retailer. Every October, he activates a seasonal rule with Terms: Black Friday and Cyber Monday scoped to Retail. This year, the rule surfaces intelligence about a skimming campaign targeting checkout pages using a JavaScript injection technique. Lucas shares the bulletin with his development team, who audit and harden their payment flow two weeks before the sales peak.
Healthcare
Target audience
Security Analysts, Compliance Officers, Hospital IT Teams
Healthcare organizations are high-value ransomware targets due to the critical nature of their operations and the sensitivity of patient data. Rules for this sector prioritize ransomware activity, medical device vulnerabilities, and electronic health record systems.
Suggested rule configuration
Target industry: Healthcare and Social Assistance
Types of threats: Ransomware, Data Breach, Exploit Attacks
Technologies: Epic, Cerner, medical IoT devices, DICOM systems
Terms: HIPAA, patient data, electronic health record, EHR, medical device (in English only)
Risk level: High or Critical
Use case example
Ana is the security lead at a hospital network. She configures a rule combining Industries: Healthcare, Types of threats: Ransomware, and Technologies: Epic. When a bulletin emerges about a ransomware group specifically targeting hospital scheduling systems via unpatched VPN appliances, her team receives the alert before the campaign reaches their region. They patch affected devices that same week.
Government & Public Sector
Target audience
Government CISOs, National Cybersecurity Teams, IT Directors
Government entities are frequent targets of nation-state actors, hacktivists, and espionage campaigns. Rules for this sector emphasize geopolitical threat actors, critical infrastructure, and politically motivated attacks.
Suggested rule configuration
Target industry: Public Administration
Types of threats: Cyber Attack, Data Breach, Social Engineering
Threat actors: known nation-state groups relevant to your region
Location: your country or region
Terms: government, ministry, election, public infrastructure, citizen data (in English only)
Risk level: High or Critical
Use case example
Carlos is the CISO of a federal government agency. He sets up a rule scoped to Industry: Public Administration, Location: Brazil, and Threat actors: known APT groups active in Latin America. During an election period, the rule flags a bulletin about a disinformation and credential-phishing campaign targeting government employees. His team issues an internal advisory and activates two-factor authentication enforcement across all ministry accounts.
Technology & SaaS
Target audience
Product Security Teams, DevSecOps, Security Engineers
Technology companies and SaaS providers are targeted through their software supply chain, cloud infrastructure, and developer toolchains. Rules for this sector focus on CVEs in widely used frameworks, cloud misconfigurations, and third-party dependency attacks.
Suggested rule configuration
Target industry: Technology and Software
Types of threats: Exploit Attacks, Supply Chain Attacks, and Data Breach
Technologies: AWS, Azure, GCP, Docker, Kubernetes, GitHub, npm, PyPI
Terms: zero-day, supply chain, dependency confusion, API key exposure (in English only)
Risk level: High or Critical
My technologies: your specific stack
Use case example
Rafael leads product security at a Brazilian SaaS startup. His rule includes My technologies, AWS and Kubernetes, combined with the term "supply chain and dependency confusion. When a bulletin surfaces about a malicious npm package impersonating a popular logging library, his team is alerted within hours. They audit their package lockfiles and find no compromise but update their CI pipeline to block unsigned packages going forward.
Energy & Critical Infrastructure
Target audience
OT/ICS Security Teams, Risk Managers, CISOs
Energy companies and critical infrastructure operators face targeted attacks on industrial control systems, SCADA environments, and operational technology networks. Rules for this sector focus on ICS/OT-specific CVEs, threat actors with infrastructure mandates, and supply chain risks.
Suggested rule configuration
Target industry: Energy and Utilities
Types of threats: Cyber Attack, Exploit Attacks, Remote Code Execution
Technologies: SCADA, ICS, Modbus, Siemens, Schneider Electric, Honeywell
Threat actors: groups known to target critical infrastructure
Terms: power grid, pipeline, OT network, industrial control, firmware (in English only)
Risk level: Critical
Use case example
Fernanda is the OT security lead at a Brazilian energy utility. She configures a rule combining Industry: Energy, Technologies: SCADA and ICS, and Threat actors: groups associated with infrastructure attacks. When a new bulletin reports a campaign exploiting a known CVE in a SCADA platform used across South American utilities, she receives the alert the same day. Her team confirms the vulnerable version is in use at two substations and applies the patch within the maintenance window.
MSSPs (Managed Security Service Providers)
Target audience
SOC Analysts, Threat Intelligence Leads, Account Managers
MSSPs manage threat intelligence across multiple client environments simultaneously. The monitoring rules system supports this by allowing each analyst to follow rules independently and by enabling rule templates that can be adapted per client. MSSPs benefit from broad rules that surface cross-sector threats alongside client-specific rules for each vertical they serve.
Suggested rule configuration
Related to: the whole world (for cross-client threat visibility)
Types of threats: all relevant categories for your client base
Threat actors: top active groups globally and regionally
Risk level: High or Critical
Per-client rules: scoped by Industry + Location + My technologies for each account
Use case example
Beatriz leads the threat intelligence function at a Brazilian MSSP with 40 clients across finance, retail, and healthcare. She maintains a global rule for cross-sector intelligence, plus three client-specific rules for her highest-risk accounts. When a ransomware bulletin affecting the healthcare sector is published on a Tuesday morning, her rule surfaces it immediately. By noon, she has briefed two healthcare clients and one fintech client whose infrastructure overlaps with the affected vendor.
Telecommunications
Target audience
Security Operations, Network Security Teams, CISOs
Telecom providers are targeted for subscriber data, SS7 vulnerabilities, and network infrastructure attacks. Rules in this sector benefit from coverage of protocol-level exploits, insider threat indicators, and large-scale data breach activity.
Suggested rule configuration
Target industry: Telecommunications
Types of threats: Data Breach, Exploit Attacks, and Cyber Attack
Terms: SS7, SIM swap, subscriber data, VoIP, roaming, MVNO (in English only)
Technologies: network management platforms, billing systems
Risk level: High or Critical
Use case example
Diego manages security at a regional telecom operator. He configures a rule with Industry: Telecommunications and Terms: SS7 and SIM swap. A bulletin surfaces reporting a SIM swap-as-a-service operation targeting telecom subscribers in Latin America, with indicators pointing to insider access at the carrier level. Diego escalates internally and initiates an access audit on privileged billing system accounts.
Education
Target audience
University IT Security, K-12 Security Teams, EdTech Platform Security
Educational institutions store large volumes of student and researcher data and often operate with limited security budgets. They are frequent targets for ransomware, credential phishing, and research data theft. Rules for this sector focus on phishing campaigns, exposed learning management systems, and student data breaches.
Suggested rule configuration
Target industry: Educational Services
Types of threats: Ransomware, Social Engineering, and Data Breach
Technologies: Canvas, Moodle, Google Workspace, Microsoft 365
Terms: student data, FERPA, learning management, university, research data (in English only)
Risk level: Medium, High, or Critical
Use case example
Priya is the information security officer at a large university. She sets up a rule scoped to Industry: Educational Services, Technologies: Canvas and Google Workspace, and Types of threats: Ransomware and Social Engineering. A bulletin reports a spear-phishing campaign targeting university faculty credentials to access grant management portals. Priya issues a targeted awareness alert to research faculty and works with IT to enforce MFA on grant system logins.
Entertainment, Media & iGaming
Target audience
Platform Security, Trust & Safety, Anti-Fraud Teams
Entertainment and gaming platforms face account takeover campaigns, cheating infrastructure, DDoS attacks, and fraud targeting in-game economies and payment systems. iGaming platforms carry additional regulatory risk around player data. Rules for this sector benefit from terms specific to gaming fraud and platform abuse.
Suggested rule configuration
Target industry: Entertainment, Arts, and Recreation
Types of threats: Malware, Cyber Attack, Data Breach
Terms: account takeover, ATO, credential stuffing, in-game currency, cheat engine, bonus abuse (in English only)
Technologies: game server platforms, streaming infrastructure, payment processors
Threat actors: groups known for credential theft and account fraud
Risk level: High or Critical
Use case example
Thiago leads security at a Brazilian iGaming platform. He configures a rule combining Industry: Entertainment, Terms: account takeover and credential stuffing, and Threat actors: groups associated with ATO campaigns. A new bulletin details a credential stuffing toolkit being sold in underground forums, specifically targeting Brazilian gaming platforms. Thiago activates rate limiting on login endpoints and coordinates with the fraud team to flag accounts with anomalous login patterns before any player reports losses.
If you have any questions, feel free to reach out at [email protected] 😊
