AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / Practical controls

Practical controls

Audit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door

Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The salesperson who took the candidates with him

A 20-person recruiting firm loses its top biller to a competitor in June. He gives two weeks' notice, works them politely, hands back the laptop and is gone by the 14th. On the 30th the owner gets a call from a client: the competitor has just pitched them the exact three candidates the firm shortlisted the week before, with the same salary notes.

She asks her IT contractor to find out what happened. He can, partly. The Microsoft 365 audit log shows the salesperson exported the full candidate list from the CRM on the evening he gave notice, 11,400 records, and shared a folder called "templates" from his OneDrive to a personal Gmail address. It also shows he did the same thing in March. Before that the trail goes dark, because the audit log on the firm's licence only went back 90 days and nobody had extended it.

Sharing alerts were available. Nobody had turned them on. The data loss prevention rule that would have stopped a spreadsheet with 11,400 phone numbers leaving the tenant sat in the admin center, unconfigured, one click from the setting that would have flagged a 9 p.m. export.

The firm's lawyer asks for the evidence. The owner has 90 days of it and no idea when this started.

What the heck does this mean

An audit log is the record of who did what, in which system, at what time: who logged in, who exported, who shared a folder, who changed a permission. Every business platform keeps one. The questions are how far back it goes and whether anyone reads it.

Retention is how long the log is kept before it is deleted. The default is set by the vendor's licensing tier, not by your regulator, and the two rarely agree. Dwell time is how long an attacker or a bad insider operates before anyone notices. If dwell time is longer than retention, the evidence is gone before the question gets asked.

Data loss prevention, DLP, is the set of rules that recognizes sensitive data (a spreadsheet full of phone numbers, a file with patient IDs, a document marked confidential) and stops it being emailed out, shared publicly or copied to a personal drive. A log tells you what left. A DLP rule says it cannot.

The numbers that matter

Median dwell time for small businesses is measured in weeks, according to the Verizon 2026 Data Breach Investigations Report. Weeks of activity, against a log that may hold only days.

69% of monitored SaaS accounts in small-business tenants were unmanaged guest accounts, per the Kaseya 2026 SaaS Security Report. Two-thirds of the identities in your cloud may belong to people you never hired, and every one of them shows up in the data before it shows up in the log.

Regulators on both sides of the world agree on this one. NYDFS Part 500, the HIPAA Security Rule and Abu Dhabi's ADHICS v2 all require audit-log retention and review, and Dubai's NABIDH policies require an unalterable access log on every patient record. The log is not paperwork. It is the evidence you are expected to produce.

What to do this week

  1. Find out how far back your audit log goes, in Microsoft 365 or Google Workspace, the CRM and the line-of-business app. Write the number next to each. Anything under a year gets extended, or exported monthly to storage you control. (CIS 8 Audit Log Management)
  2. Turn on the alerts that already exist in your tenant: external sharing, mass download or export, new mailbox forwarding rule, admin role added, sign-in from a new country. Route them to a person, not a folder. (CIS 13 Network Monitoring and Defense)
  3. Build one DLP rule this week and one more each month. Start with the file that would hurt most: a spreadsheet with more than 100 phone or ID numbers, anything with a patient identifier, anything tagged confidential. Block it from leaving, or at minimum warn and log. (CIS 3 Data Protection)
  4. List every guest account and every external share in your tenant and remove the ones nobody can explain. That list is usually longer than the staff list. (CIS 5 Account Management)
  5. Write the offboarding step down: the day notice is given, export that person's activity for the last 90 days and read it; repeat on the last day. It takes an hour. It is the hour the recruiting firm wishes it had spent. (CIS 8 Audit Log Management)
  6. Once a month, read the log yourself. Ten minutes with coffee: biggest exports, newest shares, oddest sign-in times. The habit is worth more than the tool. (CIS 8 Audit Log Management)

Where AccuSights fits

Our assessment checks the four settings from the story: how far back the log goes, which alerts are on, which DLP rules exist, and how many guests and external shares live in your tenant. Most owners have never seen that last number. The Cyber Hygiene Test takes three minutes and asks for it. A 15-minute call with an engineer follows, with the rules worth building first at the top.

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets, and Protect watches the log 24/7 so an 11,400-record export at 9 p.m. is a phone call that night, not a client call three weeks later.

Questions people ask

How long should I keep security logs? A year is the practical floor for a small business, and longer wherever a regulator names a number. Attackers and bad insiders operate for weeks before anyone notices, and the investigator, the insurer and the lawyer will all want to know when it started. If your platform's tier cannot hold a year, export the log monthly to storage you control.

Does Microsoft 365 keep audit logs by default? It keeps them for a period set by your licence tier, measured in months rather than years, and the setting is easy to assume and easy to get wrong. Check it in the admin center this week instead of trusting a memory of what the default was. Then confirm logging is enabled for every workload, including SharePoint and OneDrive sharing events.

What is DLP and do I need it? Data loss prevention is a set of rules in your email and file platform that recognizes sensitive content and stops it leaving: block the email, prevent the public share, warn the user, write the event to the log. If you hold client lists, patient data, financial records or anything a competitor would pay for, you need at least the basic rules. Most business licences already include them. Turning them on is the missing step.

Ninety days of evidence for a problem that started in spring. The log did its job. Nobody had asked it to remember.

Controls this post maps to

CIS 8 Audit Log ManagementCIS 3 Data ProtectionCIS 13 Network Monitoring and Defense

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.