A budget holder will fund six more months of security log retention only if you drop something else — how do you make the case?
answer
- insurance is a losing frame
- sell answerability, not probability
- outsider-reported cases are the old ones
- bring the asymmetric horizon as the trade
- measure the oldest record you query
basics
~20 sStop selling insurance and sell answerability: name the case questions the extra months make answerable and nothing else can. Offer an asymmetric horizon as the trade, and write down in advance what the shortened branch costs.
solid answer
~50 sInsurance is a losing frame because it invites the reply that nothing has happened. I reframe to answerability: here are the questions a case asks — when did this access begin, was this account also used in March, did the data move before we were told — and the extra months are what makes them answerable. I ground it in dwell: intrusions outsiders tell us about are consistently older than our current window, so the window is sized to lose the worst cases. Then I bring the trade rather than waiting to be squeezed: keep authentication, DNS, control-plane and alert metadata twelve months because they are small; drop verbose endpoint and proxy telemetry to sixty days. I hand over the written list of what that makes unanswerable, so they buy a known gap. And on whether it has ever paid off, I answer honestly and offer to measure it.
go deeper
You will not lead this conversation, but understand that the retention window is a funded choice rather than a technical default, and that shorter windows cost specific answers.
Be ready to explain the asymmetry that makes the trade work: small high-value sources are cheap to keep for a year, verbose telemetry is not, and they answer different kinds of question.
Show that you name the losses of a shortened branch in advance and keep that list, rather than discovering the gap mid-case and calling it a surprise.
Own the negotiation: reframe insurance as answerability, arrive with the trade already designed, answer the payoff question honestly even when the answer is no, and commit to a measurement that decides it next time.
## Why the usual pitch fails `We need it in case we are breached` is an insurance pitch, and the budget holder's rational reply is that they have not been breached, that the premium is annual and rising, and that the platform bill is already a visible line. You will lose that argument on its own terms because it asks them to buy a probability from someone whose job it is to be worried. The frame that works is **answerability**. Retention does not reduce the chance of an intrusion; it decides which questions can be answered when one happens. That is a concrete, checkable claim, and it can be made specific. ## Make the questions specific Bring the actual sentences a case produces: - When did this access begin, and by what route. - Was this same identity used anywhere else in the estate in March. - Did the data our partner is describing leave before they told us. - Is the account we just disabled the only one involved, or the only one we can see. Each of those is a question a customer, a partner, a regulator or the board will ask, and each is answerable only if the record still exists. Note the direction of the claim carefully: extra retention does not tell you an intrusion happened, and it does not prevent one. It changes an unknown into an answer, and an unknown is what you otherwise have to say out loud to the person asking. ## Ground it in dwell, honestly The supporting evidence is the dwell distribution: how long intrusions run before anyone notices. Two features do the work. It is right-skewed, so the long cases are the expensive ones. And cases discovered by an outsider are systematically older than cases your own detections catch — so the current window is sized to fail precisely the situations where you have least control of the narrative. Declare the weakness of your own data too. Your measured dwell is truncated at your current horizon, because an intrusion older than the window is difficult to confirm at all. That makes your estimate a floor. Saying this unprompted buys more credibility than a confident number, and it pre-empts the obvious challenge. ## Bring the trade yourself Do not wait to be told to cut something. Arrive with the asymmetric horizon already designed, because it exploits a real asymmetry: cost scales with volume, value does not. | branch | sources | horizon | | --- | --- | --- | | long | authentication and sign-in, DNS, cloud and SaaS control-plane audit, detection and alert metadata | twelve months | | short | full endpoint process telemetry, proxy records, verbose application logs | thirty to sixty days | The long branch is small per record, so a year of it is cheap next to a month of the bulk, and it is the branch that answers the scoping questions above. That is the offer: the six months apply where they are affordable and load-bearing, funded by shortening the branch that mostly buys detail. ## Write down what the gap costs — before you take the money The part that makes this a professional decision rather than a hopeful one is naming the losses in advance. A short list, agreed with the detection owners and handed to the budget holder: - Beyond sixty days we can say an account authenticated to a host, but not what process ran there or what command line it carried. - We can say a host resolved a domain, but not which binary asked for it. - Reconstructing an older intrusion will be identity-shaped and coarse, and it will contain gaps we can point to but not fill. Now they are buying a known gap rather than an unpriced risk, and when a case later runs into that gap, it is a decision that was made rather than a surprise the security team failed to warn about. Keep the list where the next retention review will find it. ## The honest answer to `has this ever paid off?` If you have a case where you queried records older than ninety days and the result changed what you concluded or told someone, cite it: the date, the question, and what you would otherwise have had to say. One real example outperforms any amount of framing. If you do not have one, say so. Do not manufacture one — the person across the table can usually tell, and you will need them again next year. Then say what that absence does and does not mean: you have not yet had a case that reached back, which is either good fortune or evidence that you have not been finding long-dwell intrusions, and the two are indistinguishable from where you sit. Then offer the measurement that ends the argument next time. Record, for every case, the age of the oldest record actually queried. Within a year you have a distribution of real lookback depth, and the next retention conversation is settled with data from your own estate rather than with a published median and a worried tone. Committing to bring that number back — and to propose a cut yourself if it says the months went unused — is what turns a request into a position they can trust.
- You have never once queried data older than ninety days. Do you still ask for the six months?Yes, but you say it plainly, because the absence is ambiguous rather than reassuring: either no case has needed the depth, or you have not been detecting the intrusions that would. I would put the honest version on the table, lean on the fact that outsider-notified cases are the old ones and you cannot schedule those, and commit to measuring lookback depth per case so the next review is decided by evidence rather than by two opinions.
- How do you keep the shortened branch from quietly becoming a problem nobody remembers agreeing to?Write the unanswerable questions down at the moment of the trade, agreed with the detection owners, and attach that list to the retention decision. Review it whenever a case actually hits the gap, and record that it did. It converts a vague loss into a maintained artefact, and it means the next budget conversation opens with evidence of the gap being hit rather than another abstract request.
- The budget holder counters that the archive is cheap, so everything should simply go cold for a year. What is your response?Cold storage solves cost, not answerability under time pressure. Rehydration takes hours, and if the sources needed to scope a case are cold, every case starts with a wait during which a live adversary keeps operating. So the trade is not hot versus cold alone: the small scoping sources stay hot for the full horizon, and cold buys depth on the verbose bulk. That version is cheap and still lets an investigation begin immediately.
saying these in an interview costs you the question
- Pitches retention as insurance against an unquantified breach
- Invents a past case where the extra months paid off
- Accepts a shorter horizon without recording what it makes unanswerable
- Treats every source as needing the same retention period
- Offers no measurement that would settle the question next year