Monitoring for Delete Network Security Group Rule events gives insight into network access changes and may reduce the time it takes to detect suspicious activity.
Recommended Mitigation
Under Monitor -> Alerts, create an alert for 'Microsoft.Network/networkSecurityGroups/securityRules/delete'.