→ Back to Home
Incident Management

Enterprises Risk Breach Detection by Discarding Critical Log Data for Cost Savings

A recent report from Help Net Security, based on a Dynatrace survey, reveals a concerning trend among large enterprises: a widespread practice of discarding critical log data to cut costs, which significantly compromises their ability to respond effectively to cyber breaches. The survey of 450 senior IT leaders found that approximately half of these organizations either discard or fail to collect an average of 86% of their logs, even after initial filtering and aggregation. Furthermore, many also impose strict limits on how long they retain the logs they do keep. This cost-saving measure creates a substantial blind spot for security teams. Logs are the fundamental record of activity within applications and infrastructure, capturing errors, events, and actions in chronological order. They are indispensable for threat hunting, incident response, and forensic analysis. When a security investigation is launched, log data is often the first resource sought. However, if this data has been sampled away or deleted due to retention policies, the evidence needed to understand and mitigate a breach is simply gone. The article points out that intrusions can remain undetected for weeks or even months. By the time an alert triggers an investigation, the relevant log entries might have long since been purged, leaving investigators without the necessary trail to follow. This disconnect often stems from a governance issue, where the teams responsible for log retention (e.g., observability, platform engineering, or cost control) operate under different mandates and spending targets than the security teams who rely on this data for incident resolution. Adding to this complexity is the increasing adoption of AI workloads, which generate significantly higher volumes of log and telemetry data. This surge in data translates to higher ingestion, storage, and query costs, intensifying the pressure on organizations to reduce logging expenses. While AI itself can contribute to the problem by increasing data volume, the article also subtly hints at a future where AI agents might consume and act on logs, making the integrity and availability of log data even more critical. Tampered or injected log entries could potentially mislead automated systems. Ultimately, the decision to discard logs, driven by cost, directly impacts an organization's security posture, potentially leading to extended downtime, loss of client trust, and exorbitant recovery costs.
#log management#incident response#cybersecurity#data retention#cost optimization#forensics
Read original source