IT security intelligence. Since 2006.Cloudflare services ↗
TRUST-IT / Practical guide

Can your enterprise reconstruct a serious incident?

Logging is only part of investigation readiness. The real test is whether the right people can obtain, interpret and preserve the records needed for a business-critical question.

Preparing evidence handling and incident investigation procedures

Choose a scenario that crosses team boundaries

Use a realistic scenario such as a finance account compromise that affects a supplier conversation and shared documents. Map each system, provider and decision-maker involved. Ask what leadership would need to know about access, impact and recovery. Starting with a scenario reveals gaps that a list of installed security tools may miss. It also makes the readiness exercise relevant to business owners.

Check records, access and retention in practice

For each source, identify the relevant event types, time coverage, export method and person able to retrieve it. Verify a sample rather than relying only on configuration screenshots. Cloud retention can depend on licences, policies and the event involved; Microsoft documents those dependencies for its audit service. Record any limitations and who is responsible for resolving them.

Make provider responsibilities explicit

An outsourced provider may hold important records while the client retains the business risk. Review how an evidence request is authorised, what can be exported and which dependencies affect delivery. Identify an alternative contact if the normal administrator is unavailable. For group structures, check whether one entity can authorise access to another’s records instead of assuming that a shared brand means shared authority.

Practise the handling and decision trail

Run a controlled exercise that includes evidence requests, secure exchange, time-zone reconciliation and a record of changes made during response. Test how IT, security, management and advisers coordinate. The aim is to expose practical friction before an incident: unavailable permissions, unclear approval, incomplete exports or reporting that arrives without sufficient context. Assign each gap to an owner with an acceptance test.

Connect readiness to the wider risk programme

NIST SP 800-61 Revision 3 places incident response within cybersecurity risk management, connecting preparation with detection, response and recovery. Use that broader perspective when prioritising improvements. A logging change should support a decision, a response procedure or a recovery check. The exercise is complete when the organisation has both an evidence picture and an actionable improvement plan.

Repeat after material changes

Acquisitions, tenant migrations, new AI services and provider changes can alter the evidence landscape. Add readiness questions to change review and periodically retest critical sources. Record the date, scope and result so leadership understands what has actually been demonstrated. This produces a more reliable basis for response than a plan whose assumptions have never been exercised.

Further reading

Put the guidance to work

Evidence-source mapping, logging and retention review, preservation procedures and scenario exercises for investigation readiness.

Forensic readiness

What’s your next
technology challenge?

Talk to our team