Effective security monitoring depends on configuring alerts ahead of time so that potential attacks or system compromises trigger timely investigation. Key sources include antivirus, firewalls, EDR, IDS/IPS, and SIEM systems.
Monitoring & Alerting in IT
Being in IT, I would always monitor the systems that I was managing, and then I would have alerts that would come up. They would send me a text if something went down or something went awry. So there's some sort of monitoring and alerting that's happening.
If we're getting alerts, that could be an indicator that there's some sort of attack or compromise of our system, and we're going to want to investigate.
I think the key to this is that you're going to want to set up monitoring and alerting ahead of time, so that you understand what's happening on your network and are alerted when you need to do some further investigation. There's some tuning that happens with this, because it is a little tricky to make sure that you get it right, where you're not getting notified just off of anything, but off of the more critical things you are getting notified.
Just a few of the systems that we might get alerted off of:
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →