There is one question I ask in a first meeting that changes the temperature of the room.
If someone had been reading your partners' email since March, how far back could you prove what they saw?
Almost nobody can answer it. Not because the firm is careless, and not because the IT is bad. The answer was set years earlier by a licensing decision, made on an ordinary Tuesday, by people who were solving a budget problem rather than an evidentiary one. Nobody in that conversation thought of it as a legal decision. It was.
Here is why it matters.
Investigative capability is bought in advance. It cannot be bought retrospectively. When an incident is found in September and it started in February, the question is not how good your forensic examiner is. The question is whether the record of February still exists. If it does not, no amount of money, urgency or expertise brings it back.
The report I have to write in that situation reads something like this. An unauthorised party had access to the environment. We can account for their activity over the most recent period. Records covering the earlier period are no longer available, so we are unable to determine what was accessed before that date.
Read that paragraph the way the people who will read it do.
Your insurer reads it as an unquantified loss. The regulator reads it as an inability to assess the scope of the breach, which affects what you have to tell people and when. Your client, whose matter may or may not have been sitting in the affected mailbox, reads it as "we do not know."
That is the cost of a retention setting.
What an investigation is actually built from
When we reconstruct an incident, we are not doing anything mysterious. We are assembling a timeline from records that systems generate automatically. There are six that matter in a typical law firm.
Mailbox and admin audit records. Who read what, who forwarded what, who created an inbox rule that quietly moved messages to a folder nobody opens, and who granted somebody access to a mailbox that was not theirs. In business email compromise, which is the most common serious incident in legal practice, this is the primary evidence.
Sign-in records. Where a login came from, on what device, and whether multi-factor authentication was actually satisfied or bypassed. This is what answers "was it really them", and it is usually the first place the story starts.
Endpoint telemetry. What ran on the laptop or server. Note that antivirus alerts are not telemetry. An alert list tells you about things that were already blocked. Telemetry tells you what happened, which is a different and far more useful thing.
Document management access history. Which matters were opened, by whom, and when. This is the record that answers the only question your client genuinely cares about.
Firewall and VPN records. Volume, timing and destination of traffic leaving the firm. This is how exfiltration gets measured rather than guessed at.
Backups. Not a log, but the only thing that lets you compare the environment as it is against the environment as it was.
Every one of those has a retention period. Most firms have never been told what theirs are.
What a mid-size firm typically retains
I am going to give ranges rather than absolutes, because the figures depend on your licensing and on whether anyone has configured anything. The point of this section is not for you to trust my numbers. It is for you to go and find yours.
For Microsoft 365, which is where most Australian law firms live, the published position is this.
Audit (Standard) retains records for 180 days. That default changed in October 2023, when it moved up from 90 days. Records generated before that date were kept for 90 days, which matters if you are ever asked to look at something historical. On Standard, you cannot extend that window. There is no setting. The records simply stop existing.
Audit (Premium), which comes with E5 and certain add-on licences, retains Exchange, SharePoint, OneDrive and Entra ID records for one year by default. Worth knowing: activity in everything else, including Teams, still sits at 180 days unless somebody has written a custom retention policy. The ability to write those policies is itself a Premium capability, so a firm on Standard cannot extend anything at all within the platform.
Sign-in records are on a shorter clock than most people expect. Microsoft Entra ID retains sign-in and directory audit logs for 30 days on the P1 and P2 tiers, and 7 days on the free tier. Some of that data is also ingested into the unified audit log and lives longer there, but the detailed version, which is often the version you want, is on the shorter timer.
Endpoint telemetry varies by product and tier, and the searchable hunting window is typically far shorter than the alert history. Firewall and VPN retention depends entirely on the device and whether anyone is shipping the logs anywhere. In small and mid-size firms, the honest answer is often days.
Backup retention is usually the best understood of the six, because somebody sold it to you as a product with a number attached.
So a firm running a common mid-market configuration, with no one having configured anything beyond the defaults, can generally reconstruct mailbox activity for about six months, sign-in detail for about a month, and network activity for about a fortnight.
Now hold that against how long intrusions go unnoticed. Industry reporting on dwell time moves around, but the consistent finding across every credible dataset is that the interval between compromise and discovery in a small or mid-size organisation is frequently measured in months, not days.
Those two facts do not fit together. That is the whole problem, and it is not a technology problem. It is a procurement decision that nobody framed correctly.
The conversation nobody treats as a legal decision
Somewhere in your firm's history, someone compared licence tiers. The comparison was almost certainly framed as features and cost per user per month. Security features appeared as a list of capabilities. Retention appeared, if at all, as a line item.
What was actually being decided was the maximum lookback period for any future investigation into your firm's conduct, your employees' conduct, or an attacker's conduct inside your systems.
Had it been framed that way, most managing partners would have asked a different question.
That is not a criticism of whoever made the call. It is an observation about how the decision gets presented. Nobody sells log retention. It has no user-facing benefit, it never demonstrates well, and it only becomes visible on the worst day the firm has.
The fix is to reopen the decision with the right frame. Not "do we need E5", which is a licensing question with an expensive default answer. Instead: given that we hold client data, run trust accounts and would have notification obligations after a breach, what is the shortest lookback period we are comfortable being able to offer a regulator, an insurer and a client?
If the answer is longer than what you currently retain, you have a gap with a known cost.
Two things worth changing this week
One. Extend or export your audit retention. If you hold Premium capability, custom retention policies are available to you and are probably not configured. If you are on Standard, extension within the platform is not possible, so the option is to export audit records on a schedule to storage you control, or to stream them into a SIEM. This is not expensive. It is just something nobody has been asked to do.
Two. Get sign-in data out of its short window. Sign-in logs can be routed into a long-term store so the detail survives beyond the default retention. This is generally the single highest-value change available, because identity is where these incidents start and 30 days is not enough.
Both are configuration. Neither requires new tooling. Both are worthless if you apply them after the incident.
The email to send
You do not need to understand any of this to act on it. You need six numbers, in days, in writing.
Send this to whoever runs your systems, internal or external.
Hi [name],
A governance question rather than a technical one. For each of the following, could you tell me how long we currently retain records, in days?
- Mailbox and admin audit records
- Sign-in records
- Endpoint telemetry
- Document management access history
- Firewall and VPN records
- Backups, and the date we last tested a restore
If any of these are shorter than twelve months, could you also tell me what extending them would involve and cost?
Thanks, [you]
Keep the reply. It is a governance record, it takes five minutes to read, and in a year's time somebody will be very glad it exists.
If four of those numbers come back shorter than a year, that is your security agenda for the next quarter. Not a product. A decision.
Back to the board question
If an attacker had been inside the firm for months, how far back could we reconstruct what happened?
It is one of five questions I think every law firm board or partnership should be able to answer, and it is the one most likely to produce silence.
The reason I keep returning to it is that unlike almost everything else in cyber security, this one has a definite answer, the answer is knowable today, and it is cheap to change while nothing is wrong.
It just cannot be changed later.
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.