Skip to content
14 providers 54 configurations
Independent reseller · not affiliated with any provider Telegram

Cloud Security

Logging and monitoring from day one

You can only ever investigate what you were already recording.

Logging and monitoring from day one

Audit logging is the one control that cannot be applied retrospectively. Every other hardening step can be done later; the record of what happened last month either exists or it does not.

Enable these immediately

  • Control-plane audit logs: who called which API, when, from where.
  • Authentication events, including failures.
  • Changes to identity, permissions and policies.
  • Network flow logs, at least for anything internet-facing.
  • Access logs for storage holding sensitive data.

Protect the logs from the thing you are logging

An attacker with administrative access will delete evidence if they can. Ship logs to a destination the workload account cannot modify – a separate account or an append-only store – and restrict who can change retention settings.

Log storage decisions
Decision Guidance
Where they live A separate account or project where possible.
Who can delete them Ideally nobody; certainly not workload administrators.
Retention period Long enough for your obligations and investigations.
Storage class Move older logs to cheaper tiers rather than deleting.
Integrity Enable object locking or equivalent if available.

Alerts worth setting on security events

  1. Any use of the root or owner identity.
  2. Creation of a new administrative identity or access key.
  3. Changes to logging configuration or retention.
  4. Authentication from an unexpected country or an unusual pattern of failures.
  5. A sudden change in daily spend.

Five alerts, each rare and each meaningful. That is a channel people will still trust in six months.

Retention is a decision, not a default

Default retention is often short and set for convenience rather than for your needs. Investigations frequently reach back further than people expect, and some obligations specify a minimum. Set it deliberately and budget for the storage.

Summary

Turn logging on before the first workload, send it somewhere the account cannot edit, set retention on purpose, and keep a handful of high-signal alerts. This is the control you cannot add later.

Keep reading

More Cloud Insights

Securing a cloud account in the first hour
Cloud Security

Securing a cloud account in the first hour

The window between receiving credentials and finishing your security baseline is the riskiest part of the whole exercise. Close it quickly.

11 Sep 2026 2 min read

Next step

Find the account this article describes

Compare configurations by provider, with prices and full detail on every page.

Scroll to Top
Telegram