Blog / Practical controls
Practical controls
Audit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door
Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.
The salesperson who took the candidates with him
A 20-person recruiting firm loses its top biller to a competitor in June. He gives two weeks' notice, works them politely, hands back the laptop and is gone by the 14th. On the 30th the owner gets a call from a client: the competitor has just pitched them the exact three candidates the firm shortlisted the week before, with the same salary notes.
She asks her IT contractor to find out what happened. He can, partly. The Microsoft 365 audit log shows the salesperson exported the full candidate list from the CRM on the evening he gave notice, 11,400 records, and shared a folder called "templates" from his OneDrive to a personal Gmail address. It also shows he did the same thing in March. Before that the trail goes dark, because the audit log on the firm's licence only went back 90 days and nobody had extended it.
Sharing alerts were available. Nobody had turned them on. The data loss prevention rule that would have stopped a spreadsheet with 11,400 phone numbers leaving the tenant sat in the admin center, unconfigured, one click from the setting that would have flagged a 9 p.m. export.
The firm's lawyer asks for the evidence. The owner has 90 days of it and no idea when this started.
What the heck does this mean
An audit log is the record of who did what, in which system, at what time: who logged in, who exported, who shared a folder, who changed a permission. Every business platform keeps one. The questions are how far back it goes and whether anyone reads it.
Retention is how long the log is kept before it is deleted. The default is set by the vendor's licensing tier, not by your regulator, and the two rarely agree. Dwell time is how long an attacker or a bad insider operates before anyone notices. If dwell time is longer than retention, the evidence is gone before the question gets asked.
Data loss prevention, DLP, is the set of rules that recognizes sensitive data (a spreadsheet full of phone numbers, a file with patient IDs, a document marked confidential) and stops it being emailed out, shared publicly or copied to a personal drive. A log tells you what left. A DLP rule says it cannot.
The numbers that matter
Median dwell time for small businesses is measured in weeks, according to the Verizon 2026 Data Breach Investigations Report. Weeks of activity, against a log that may hold only days.
69% of monitored SaaS accounts in small-business tenants were unmanaged guest accounts, per the Kaseya 2026 SaaS Security Report. Two-thirds of the identities in your cloud may belong to people you never hired, and every one of them shows up in the data before it shows up in the log.
Regulators on both sides of the world agree on this one. NYDFS Part 500, the HIPAA Security Rule and Abu Dhabi's ADHICS v2 all require audit-log retention and review, and Dubai's NABIDH policies require an unalterable access log on every patient record. The log is not paperwork. It is the evidence you are expected to produce.
What to do this week
- Find out how far back your audit log goes, in Microsoft 365 or Google Workspace, the CRM and the line-of-business app. Write the number next to each. Anything under a year gets extended, or exported monthly to storage you control. (CIS 8 Audit Log Management)
- Turn on the alerts that already exist in your tenant: external sharing, mass download or export, new mailbox forwarding rule, admin role added, sign-in from a new country. Route them to a person, not a folder. (CIS 13 Network Monitoring and Defense)
- Build one DLP rule this week and one more each month. Start with the file that would hurt most: a spreadsheet with more than 100 phone or ID numbers, anything with a patient identifier, anything tagged confidential. Block it from leaving, or at minimum warn and log. (CIS 3 Data Protection)
- List every guest account and every external share in your tenant and remove the ones nobody can explain. That list is usually longer than the staff list. (CIS 5 Account Management)
- Write the offboarding step down: the day notice is given, export that person's activity for the last 90 days and read it; repeat on the last day. It takes an hour. It is the hour the recruiting firm wishes it had spent. (CIS 8 Audit Log Management)
- Once a month, read the log yourself. Ten minutes with coffee: biggest exports, newest shares, oddest sign-in times. The habit is worth more than the tool. (CIS 8 Audit Log Management)
Where AccuSights fits
Our assessment checks the four settings from the story: how far back the log goes, which alerts are on, which DLP rules exist, and how many guests and external shares live in your tenant. Most owners have never seen that last number. The Cyber Hygiene Test takes three minutes and asks for it. A 15-minute call with an engineer follows, with the rules worth building first at the top.
Our assessment is mapped to your regulators, and the read-only compliance agent shows your log retention, external shares and guest accounts against what your health, financial or free-zone regulator expects. We have no access and do not remediate; you or your IT partner set the rules, we show you where.
Questions people ask
How long should I keep security logs? A year is the practical floor for a small business, and longer wherever a regulator names a number. Attackers and bad insiders operate for weeks before anyone notices, and the investigator, the insurer and the lawyer will all want to know when it started. If your platform's tier cannot hold a year, export the log monthly to storage you control.
Does Microsoft 365 keep audit logs by default? It keeps them for a period set by your licence tier, measured in months rather than years, and the setting is easy to assume and easy to get wrong. Check it in the admin center this week instead of trusting a memory of what the default was. Then confirm logging is enabled for every workload, including SharePoint and OneDrive sharing events.
What is DLP and do I need it? Data loss prevention is a set of rules in your email and file platform that recognizes sensitive content and stops it leaving: block the email, prevent the public share, warn the user, write the event to the log. If you hold client lists, patient data, financial records or anything a competitor would pay for, you need at least the basic rules. Most business licences already include them. Turning them on is the missing step.
Ninety days of evidence for a problem that started in spring. The log did its job. Nobody had asked it to remember.
Questions people ask
How long should I keep security logs?
A year is the practical floor for a small business, and longer wherever a regulator names a number. Attackers and bad insiders operate for weeks before anyone notices, and the investigator, the insurer and the lawyer will all want to know when it started. If your platform's tier cannot hold a year, export the log monthly to storage you control.
Does Microsoft 365 keep audit logs by default?
It keeps them for a period set by your licence tier, measured in months rather than years, and the setting is easy to assume and easy to get wrong. Check it in the admin center this week instead of trusting a memory of what the default was. Then confirm logging is enabled for every workload, including SharePoint and OneDrive sharing events.
What is DLP and do I need it?
Data loss prevention is a set of rules in your email and file platform that recognizes sensitive content and stops it leaving: block the email, prevent the public share, warn the user, write the event to the log. If you hold client lists, patient data, financial records or anything a competitor would pay for, you need at least the basic rules. Most business licences already include them. Turning them on is the missing step.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill
An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.
Practical controlsMulti-Factor Authentication for a Small Business: Where It Belongs, Which Kind Works, and Why Outlook Alone Is Not Enough
Multi-factor authentication for a small business: the five doors it must be on, which kind survives a fake login page, and why Outlook alone is not enough.
Practical controlsSecurity Awareness Training for a Small Business: Why the Report Button Beats the Delete Key
Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.
