They should preserve the relevant transaction and positioning data, reconstruct the timeline, and test whether the flow pattern matches known forms of coordinated pressure. The immediate objective is not to prove motive in one step, but to assemble enough evidence for a defensible escalation, review, or external referral.
Why the first response should be evidentiary, not accusatory
A market event that appears manipulated should be treated as a reconstruction problem first and a causation problem second. The immediate goal is to freeze the evidentiary record, preserve the order and account context, and avoid premature conclusions that can distort both escalation and later regulatory review.
That means teams should capture the fills, quotes, order lifecycle events, account identifiers, timestamps, venue context, and any related communications before the data ages out or is normalised away by downstream systems. If that preservation step is weak, later analysis becomes narrative driven instead of event driven.
What the reconstruction needs to prove
The useful question is not simply whether the market moved sharply, but whether the flow pattern shows coordinated pressure, layering, spoofing-like behaviour, wash-like interaction, or other forms of suspicious sequencing. The reconstruction should show how orders, cancellations, executions, and position changes relate over time, because manipulation patterns usually emerge from sequence, not from one isolated print.
Teams also need to separate price impact from attribution. A pattern can be unusual without proving intent, and intent can rarely be established from one dataset alone. The better standard is whether the assembled record is coherent enough that another reviewer could follow the chain of events and reach the same intermediate conclusions.
When a market event becomes a defensible escalation
The threshold for escalation is usually reached when the event can be described with specific evidence, a bounded time window, and a clear explanation of why the activity departs from expected trading behaviour. That includes showing which instruments, accounts, strategies, or venues were involved, and whether the same pattern appears across related time slices or related names.
At that point the case can move from surveillance review to formal compliance, legal, exchange, or regulatory referral. Good escalation packages make it easy to see what is known, what remains uncertain, and which records would materially change the assessment if obtained next.
Risk and Threat Considerations
Manipulation risk is highest when teams rely on partial logs, delayed data capture, or weak linkage between orders and positions. In that situation, suspicious activity can be reframed as ordinary volatility, while the actual pattern of coordinated pressure is lost before it can be tested.
Failure mechanism: The team cannot reconstruct order intent or sequence accurately because the underlying transaction, venue, and position records were not preserved at sufficient fidelity or granularity.
Impact: Surveillance loses defensibility, escalation becomes harder to support, and a potentially reportable event can remain unresolved or be dismissed as noise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1595 — Active Scanning | Pattern reconstruction depends on observing suspicious collection and sequencing of market events. |
| Recommendation — Correlate observed event sequences to detect staged or coordinated activity patterns. | ||
| NIST CSF 2.0 | DE.CM-01 — Monitoring for Anomalies and Events | Market surveillance depends on monitoring anomalous trading and preserving event evidence. |
| RS.AN-03 — Analysis of Events | The question is about analysing a suspicious event to determine whether it is manipulatively coordinated. | |
| RC.RP-01 — Recovery Plan Execution | Escalation after suspicious market activity requires a repeatable response path and preserved evidence. | |
| Recommendation — Monitor abnormal market activity and retain records needed for later review. Analyse the event trail to determine whether the pattern supports escalation. Execute a documented response path that preserves evidence for referral and review. | ||
Practitioner Guidance
What to prioritise: Preserve the smallest complete evidence set that can still support an independent review, including order events, fills, cancels, positions, and related timestamps. If those records are split across systems, establish the time base and entity keys before trying to interpret the event.
What to verify: Confirm that the reconstructed timeline is internally consistent across surveillance, market data, and book or position records. If the sequence cannot be aligned cleanly, treat that as a data-quality problem that must be resolved before any stronger conclusion is drawn.
Practitioner takeaway: The best surveillance outcome is not an immediate finding of manipulation, but an evidentiary package strong enough that the next reviewer can test the same event without depending on the original analyst’s judgment.
Related resources from NHI Mgmt Group
- How should security teams handle third-party access that looks legitimate after a supplier breach?
- How should security teams prioritise restoration after a ransomware event?
- What should security teams do after a manufacturing ransomware event?
- How should security teams use an IAM conference toolkit to advance identity governance after an event?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org