Auditing and logging, in plain English
Logging is your systems writing down what happened — who signed in, from where, what they changed. Auditing is a person periodically reading it. Most businesses have the first and not the second, which is how an incident gets discovered months later.
You do not need a security operations centre. You need the logs switched on, kept long enough to be useful, and looked at on a schedule.
Do this today
- Check that sign-in and audit logging is enabled in your email and file platform. On some plans it is off, or retained for only thirty days.
- Turn on alerts for the handful of things that are always worth knowing: a new administrator, a mail forwarding rule, a sign-in from a country you do not operate in.
- Put a recurring thirty minutes in the calendar to actually read them. A log nobody reads is storage, not security.
What good looks like
You would notice a stranger signing in within days, not months.
Retention is long enough that you could reconstruct what happened — an incident is usually found well after it began.
Want someone to just do this for you? Start a conversation — twenty minutes, free.
Last reviewed: September 2026