EDITS

Cyber Tips

Auditing and logging, in plain English

Logging is your systems writing down what happened — who signed in, from where, what they changed. Auditing is a person periodically reading it. Most businesses have the first and not the second, which is how an incident gets discovered months later.

You do not need a security operations centre. You need the logs switched on, kept long enough to be useful, and looked at on a schedule.

Do this today
  1. Check that sign-in and audit logging is enabled in your email and file platform. On some plans it is off, or retained for only thirty days.
  2. Turn on alerts for the handful of things that are always worth knowing: a new administrator, a mail forwarding rule, a sign-in from a country you do not operate in.
  3. Put a recurring thirty minutes in the calendar to actually read them. A log nobody reads is storage, not security.
What good looks like

You would notice a stranger signing in within days, not months.

Retention is long enough that you could reconstruct what happened — an incident is usually found well after it began.

Want someone to just do this for you? Start a conversation — twenty minutes, free.

Last reviewed: September 2026