CIO Brief: Storm-0558 and Paying Extra for Security Logs
Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.
The short version: In 2023, Chinese hackers read US government email by forging digital keys in Microsoft's systems. A government agency caught it — because it paid for detailed logs that many customers didn't have. Microsoft later expanded default logging after public pressure.
Why logging is a security decision
Logs are how you find out what happened during an incident. Without them, you may never know whether an attacker read email, downloaded files or what data they took. Logging decisions — what to keep, for how long — are often made by default, or to save money.
The business impact
- Undetected breaches without the right logs.
- Inability to answer regulators about what data was accessed.
- Higher notification costs when you must assume the worst.
Questions to ask your team
- If someone accessed our executives' email last month, could we prove it — and see exactly what was read?
- How long do we keep security logs?
- Are we paying for logs we need, or relying on defaults?
- Do we store logs somewhere attackers couldn't delete them?
What good looks like
Detailed audit logs enabled for email and files, retained for at least a year, copied to a separate security system, and tested regularly by running practice investigations.
The decision
Ask your team to run a five-minute test: "Show me every mailbox our CFO's account accessed yesterday." If they can't, fix logging before you need it.
- Storm-0558 (July 2023): A Stolen Signing Key and Forged Tokens Into Government Email Incident Teardowns
- How to Enable Expanded Audit Logging to Detect Mailbox Access How-To & Hardening
- Detecting Forged Token Mailbox Access: Defender XDR and Sentinel Hunting Queries Detection & Response