Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Storm-0558 and Paying Extra for Security Logs

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.

The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because it paid for detailed logs that many customers didn't have. Microsoft later expanded default logging after public pressure.

Why logging is a security decision

Logs are how you find out what happened during an incident. Without them, you may never know whether an attacker read email, downloaded files or what data they took. Logging decisions — what to keep, for how long — are often made by default, or to save money.

The business impact

  • Undetected breaches without the right logs.
  • Inability to answer regulators about what data was accessed.
  • Higher notification costs when you must assume the worst.

Questions to ask your team

  • If someone accessed our executives' email last month, could we prove it — and see exactly what was read?
  • How long do we keep security logs?
  • Are we paying for logs we need, or relying on defaults?
  • Do we store logs somewhere attackers couldn't delete them?

What good looks like

Detailed audit logs enabled for email and files, retained for at least a year, copied to a separate security system, and tested regularly by running practice investigations.

The decision

Ask your team to run a five-minute test: "Show me every mailbox our CFO's account accessed yesterday." If they can't, fix logging before you need it.

storm-0558 impactStorm-05582023

More on this story