Mmastodon TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #6
Security experts stress log retention as core incident response practice
Original: The first questions in any incident are dull ones. What happened. Who logged in, from where, when. Every one of them is
Cybersecurity practitioner Adrian Hollister argues that incident response starts with mundane questions — what happened, who logged in, and when — all answerable only through logs. He highlights two recurring failure modes, including retention windows shorter than an attacker's patience, noting the UK's National Cyber Security Centre recommends keeping logs for at least six months.
Why now: Practitioners are debating common log management failures that undermine security incident investigations.
Adrian HollisterNCSCInfosec Exchange
Evidence
- The first questions in any incident are dull ones. What happened. Who logged in, from where, when. Every one of them is answered by logs or not answered at all. Two failure modes repeat. The first is retention shorter than the attacker's patience. The NCSC suggests six months… · adrianhollister@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/463419