skip to content

Retention Against Dwell

Thirty days of telemetry cannot investigate an intrusion that began in March, so the horizon is argued from how long intruders go unnoticed. Interviewers want the reasoning, not the number.

on this pageshow

explore

questions

4

With 90-day SIEM retention, a partner reports an intrusion seven months old — what can you no longer answer?

level: juniorimportance: must knowfreq 62%

answer

  1. compliance floor, not investigative horizon
  2. the intrusion is older than the window
  3. months four to seven are simply gone
  4. cannot search is not searched clean
  5. retention is per-source, not one number

basics

~20 s

Anything about months four to seven. When access began, how it was obtained, and what it touched back then are unsearchable. You can describe only the last 90 days, and an empty result outside the window proves nothing.

solid answer

~50 s

A 90-day window chosen to satisfy an audit control answers the auditor's question — were records kept — not the defender's. The reported intrusion is roughly 210 days old, so about four months of it sit outside anything I can search. I cannot establish when access began, how it was obtained, what the account or host touched in that earlier period, or whether the activity was continuous. What I must not do is convert missing data into a negative finding: `we searched and found nothing` and `we could not search` are different statements, and only the second one is true here. Practically I would enumerate other copies with their own independent horizons — the identity provider's and SaaS platform's native audit trails, mail message-trace data, network flow kept on a different schedule — before concluding the period is unreadable, and I would state the searchable horizon explicitly in the report.

go deeper

for a junior

Be ready to say plainly that no data is not the same as no activity, and to state your searchable horizon before you state a conclusion about a period.

for a middle

An interviewer expects you to explain why retention is set per source, and to list which specific investigative questions a short window makes unanswerable rather than gesturing at lost visibility.

for a senior

Show that you enumerate independently retained sources at case opening, and that your case notes separate searched-and-clean from not-searchable so later readers cannot conflate them.

for a principal

Own the consequence: a demonstrated intrusion older than the window is evidence for changing the horizon, and you should be ready to turn one case into that argument without overstating it.

## What a retention setting actually promises Retention is a promise about how far back a search can reach. When it is set to 90 days because a control framework or a contract requires audit records to be retained for 90 days, the number has been sized to prove that records exist — not to cover the length of time an intruder can be present before anyone notices. Those are unrelated quantities, and they only look related because both are expressed in days. ## Dwell time is the quantity that should have set it Dwell time is the elapsed time between the earliest evidence of adversary activity in the estate and the moment the intrusion is detected. It matters here because the searchable horizon has to reach back past the start of the intrusion for any reconstruction to be possible at all. Two facts about dwell make a 90-day horizon fragile: - The distribution has a long right tail. Even where typical dwell is short, a meaningful share of cases run for many months. - Dwell is systematically longer when the intrusion is discovered by somebody else — a partner, a payment processor, a law-enforcement or sector-ISAC notification — than when it is found by the organisation's own detections. Externally-notified cases are exactly the cases where you most need deep history, and they are the cases most likely to be older than the window. This scenario is the second kind. A partner told you, and they dated it at seven months. ## The concrete gap Seven months is roughly 210 days. A 90-day window covers the most recent 90 of them. Roughly four months of the intrusion — including its beginning — is outside anything the SIEM can return. The specific questions that go unanswered: - When did the access start, and therefore what was the initial foothold. - What else did the account or host touch during those four months. - Was activity continuous, or did it pause and resume. - Were other identities or systems involved earlier and quiet since. - Did any of the data the partner is describing move during that period. What you can still answer is bounded and worth stating plainly: what happened inside the last 90 days, whether the activity is ongoing right now, and what the current state of the affected accounts and hosts is. ## The direction of the claim — the mistake to avoid The most damaging error at this point is to run a search over month five, get zero results, and write `no malicious activity in month five`. The data for month five does not exist. An empty result over a period you do not retain carries no information about that period whatsoever. Case notes should distinguish three states explicitly: searched and clean, searched and positive, and not searchable. Executives, auditors and lawyers all read the first and third as the same sentence unless you separate them. ## The SIEM is not always the only copy Before concluding a period is gone, enumerate what else holds records of it, because retention is per-source and rarely uniform: - The identity provider's own sign-in and audit trail, which has a platform-defined retention independent of whatever your SIEM ingested. - SaaS platforms' native audit trails and mail message-trace data, again with their own horizons. - Network flow or DNS resolver logs, often kept on a different schedule and much cheaper to keep long because the records are small. - Host-local artefacts that persist independently of any log pipeline, and backups or snapshots of the systems themselves. Each of these has a different horizon, so the honest answer to `how far back can we look` is a list, not a single number. ## What you take from the case Two outputs. First, the report says which periods were searchable and which were not, so nobody later mistakes an unsearchable month for a clean one. Second, the horizon itself becomes a finding: the window was set against a compliance minimum, the estate has now demonstrated an intrusion that outran it, and the next retention decision should be argued from how long intrusions actually go unnoticed rather than from the audit clause.

  • The partner asks whether the data they are seeing left your estate before the window opened. What do you tell them?
    That we cannot determine it from our telemetry, and why: the relevant period predates our searchable horizon. I would then say what we can determine — the state of the account and host now, and activity inside the last 90 days — and name any independently retained sources we are still checking. An honest unknown is usable by the partner; an implied negative is not, and it will be read as a denial.
  • Why does an intrusion reported by an outsider tend to be older than one your own detections find?
    Your detections fire on behaviour you anticipated, usually early in the activity, so the cases they catch are short by construction. An outsider notices the downstream consequence — data appearing somewhere, an address of yours seen in their environment — which only becomes visible after the activity has run for a while. So the externally-notified branch of the distribution is the long one, and it is the branch that most needs deep retention.
  • Does a 90-day window mean nothing before day 90 can ever be established?
    No. It means the SIEM cannot answer it. Platform-native audit trails, mail message trace, flow or DNS records kept on their own schedule, host artefacts and backups all have separate horizons, and some run far longer. The correct move is to enumerate sources and their individual retention at the start of the case rather than assuming one estate-wide number.

Keeping ninety days of records because an auditor asked is like keeping three months of receipts and then being asked to account for a purchase made last spring — the filing was compliant and the question is still unanswerable.

saying these in an interview costs you the question

  • Reads an empty search over an unretained month as proof of no activity
  • Treats the 90-day compliance minimum as a security requirement
  • Assumes the SIEM copy is the only copy of every source
  • Extrapolates backwards from in-window behaviour and calls it a finding
  • Reports the searchable period without ever stating what it was

context

open as a page

How do you set a log-retention horizon from a right-skewed distribution of observed intrusion dwell times?

level: middleimportance: should knowfreq 45%

basics

~10 s

Take a high percentile of dwell, never the median, then add the lag from discovery to first search plus the weeks the case runs. Treat your own dwell data as truncated at current retention.

open as a page

Your cold log archive rehydrates in nine hours and a live intrusion case needs eight-month-old sign-in logs — what do you do?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Start the narrowest possible restore immediately and keep working in parallel — nine hours only costs you the case if it is serialised. Then decide whether any containment action today actually depends on the restored data.

open as a page

A budget holder will fund six more months of security log retention only if you drop something else — how do you make the case?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Stop selling insurance and sell answerability: name the case questions the extra months make answerable and nothing else can. Offer an asymmetric horizon as the trade, and write down in advance what the shortened branch costs.

open as a page