Research Library / Case Studies /

Fintech

A Renowned Fintech Company Gets SOC Expertise Onboard

A well-recognized Australian fintech needed round-the- clock eyes on its endpoints, cloud services and applications. Payatu built and ran its Security Operations Center from scratch, monitoring over a million log entries a week across CrowdStrike, Splunk, Azure Sentinel and Fortinet.
SOC Monitoring

At a glance

INDUSTRY

Fintech

CLIENT PROFILE

A well-recognized Australian fintech responsible for personnel data, customer data, business systems and brand integrity

SERVICES

SOC Monitoring

ENGAGEMENT

24x7 outsourced Security Operations Center build and monitoring

key Numbers

1,072,772

Fortinet Log Entries Monitored Weekly

926,960

Salesforce Production Log Entries Monitored Weekly

19/19

Alerts Triggered and Investigated (100%)

Key Takeaways

  • Client – A well-recognized Australian fintech responsible for personnel data, customer data, business systems, intellectual property and brand integrity.

  • Problem – The client needed round-the-clock monitoring, detection and response across its devices, cloud services and applications, with no existing SOC infrastructure in place.

  • What Payatu did – Stood up a 24x7 SOC covering CrowdStrike, Splunk, Azure Sentinel, AWS CloudTrail, Salesforce, Office 365 and Fortinet, deployed honeypots on-prem and in AWS, and ran every alert through an SLA-bound Jira workflow.

  • Outcome – The client gained continuous visibility into its threat landscape, with 100% of triggered alerts investigated and proactive threat intelligence, including CVE advisories such as Follina, shared on an ongoing basis.

the challenge

Why the client called us in

Fintech cyberattacks don't just cost money, they erode customer trust and put compliance obligations at risk. This well-recognized Australian fintech understood that responsibility and wanted round-the-clock monitoring, protection, detection, investigation and response for its personnel data, customer data, business systems, intellectual property and brand. The company had no existing SOC infrastructure, so everything, from tooling to process to staffing, needed to be built from scratch, under a limited timeline and strict regulatory constraints on permissions.

  • Get complete visibility into the threat landscape across endpoints, software, servers and third-party services
  • Establish 24x7 monitoring, detection and response capability where none existed before
  • Investigate and close every alert within defined SLAs

‍

scope of engagement

What was in scope

  1. Devices allotted to employees, such as mobiles and laptops
  2. Applications installed on all devices
  3. Device activities such as logins from an unexpected user, IP address or application
  4. Cloud services such as Azure and AWS
  5. Azure Outlook, One Drive and audit log monitoring to detect and respond to phishing and brute-force attempts
  6. Access to files shared outside the client's organization
  7. Logging of all operational infrastructure devices (mobiles, laptops, AWS servers) to CrowdStrike
  8. Salesforce, Fortinet, Sentinel and Office 365 monitoring
  9. AWS device and application logging to Splunk
  10. Proactive automated and manual monitoring of logged data
  11. WordPress site logging to Splunk
  12. Honeypot deployment and alerting across on-prem and AWS infrastructure
  13. 24x7 staff availability to respond to emergencies
  14. Alert investigation and closure within agreed SLAs

Our Approach

How Payatu ran the engagement

01

Threat Landscape Assessment
Payatu's SOC team mapped the client's full threat landscape, including endpoints, software, servers, third-party services and traffic flowing between devices, and designed a detailed monitoring plan.

02

Multi-Platform Monitoring Deployment
The team stood up logging and monitoring across Azure Sentinel, AWS CloudTrail, Salesforce, Microsoft 365, Fortinet firewalls and CrowdStrike endpoint protection, plus honeypots on-prem and in AWS.

03

SLA-Driven Alert Workflow
A Jira-based ticketing workflow was implemented, covering initial triage, investigation, input requests and conclusion, so every alert is tracked from open to close within agreed SLAs.

04

Ongoing Threat Intelligence and Advisory
The SOC team continuously shares recommendations based on emerging threat trends, including CVE advisories such as Follina, along with defense guidance tailored to the client's environment.

Key findings

What we found

Cloud & Identity Monitoring
Azure Sentinel tracked suspicious user activity, phishing alerts, malware in the Azure environment, unfamiliar login locations and new OAuth application registrations.
Endpoint Risk Visibility
CrowdStrike monitoring flagged outdated software, risky executed scripts and unresolved CVEs across mobiles, laptops and cloud PCs.
SaaS and Email Abuse Signals
Salesforce and Office 365 monitoring surfaced anomalous login geography and account lockout sources, while Azure Sentinel triggered 19 alerts, all investigated and closed.

the outcome

Results and Impact

Payatu's SOC team gave this Australian fintech the always-on visibility it didn't have before, turning a blank slate into a fully monitored environment spanning endpoints, cloud services and SaaS applications. Every alert moved through a defined SLA workflow, and the team kept the client ahead of emerging threats with proactive intelligence.

‍

  • Built a 24x7 SOC from scratch, covering endpoints, cloud, SaaS and network infrastructure

  • Monitored over 1 million Fortinet log entries and close to 930,000 Salesforce log entries every week

  • Investigated and closed 100% of the 19 alerts triggered by Azure Sentinel

  • Delivered proactive threat intelligence, including CVE advisories such as Follina, to keep the client ahead of active threats

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment