This is the tenth and final stop in our walk through the OWASP Top 10. Looking back, it might have made more sense to begin here and work upwards, because good logging and monitoring is the thread that ties every other risk on the list together. If you cannot see what is happening across your systems, you cannot respond to any of the threats we have covered so far. So consider this less of an afterthought and more of a foundation.

A quick note on naming, because it matters. When this series was first written, OWASP listed this risk as A10:2017 – Insufficient Logging & Monitoring. In the current edition it has been renamed and moved up to A09:2021 – Security Logging and Monitoring Failures. The wording changed, but the core idea is the same: if you are not recording the right events and watching for trouble, attackers can come and go without anyone noticing.

What is it, exactly?

Think of a log as a diary for your systems. A personal diary tells you what you did and when. An organisation’s logs do the same thing, but for activity across applications, servers, networks and cloud services. Teams rely on these records and audit trails to troubleshoot problems, trace events, spot incidents and meet compliance obligations.

Security logging and monitoring failures happen when any link in that chain breaks. That might mean logs are missing the security details that matter, are formatted inconsistently, lack context, are stored insecurely, or are never actually reviewed. It also covers the final piece: even perfect logs are of little use if no one acts on them quickly enough to catch a breach in progress.

Why does this deserve a place on the OWASP Top 10 at all? Next to dramatic risks like injection or phishing, logging can feel like background admin. But the numbers tell a different story. IBM’s 2020 breach research found that, on average, it took organisations 280 days to identify and contain a data breach. Logs are the raw material your incident response relies on. Handle them well and you detect and contain problems faster, which saves money, time and reputation.

What are the consequences of getting it wrong?

The damage from poor logging is mostly indirect, which is exactly why it is easy to underestimate. Get it right, however, and you meaningfully reduce the impact of advanced persistent threats (APTs), ransomware, malware, insider threats and DDoS attacks, simply because you can see them coming and react in time.

When logging falls short, it undermines the three things security exists to protect:

  • Confidentiality – logs often contain sensitive information that attackers should never be able to reach. Poorly secured logs hand it to them.
  • Integrity – if attackers can access your log files, they can also alter or delete them, erasing the evidence of what they did.
  • Accountability – without reliable records, attacks and the people behind them become almost impossible to trace.

A well-known example shows how serious this can get. The 2016 “Vault 7” leak from the CIA exposed an enormous volume of classified material. According to the subsequent review, the breach was possible in part because user activity simply was not being monitored, and it went undetected for around a year. Even the most security-conscious organisations are not immune when the basics are missing.

How do you prevent it?

The good news is that strong logging and monitoring comes down to a handful of clear, achievable habits.

  • Decide what to log. Set a clear policy covering the events that matter: failed logins, suspicious network activity, and unusual behaviour on endpoints and in the cloud. Keep the format consistent so logs are easy to search and compare.
  • Bring it all together. Feed your logs into a central log management system, such as a SIEM platform, so everything lives in one place rather than scattered across systems.
  • Mind the easy-to-miss details. Synchronise timestamps to a single standard (UTC) so events line up across systems, and protect the logs themselves from tampering. Retain them for as long as your compliance and business needs require.
  • Watch, then act. Monitor user activity for suspicious behaviour and configure alerts so the right people are notified the moment something looks wrong.
  • Have a plan ready. Pair all of the above with an incident response plan, so that when an alert fires, everyone knows exactly what to do.

This is also where the right managed service earns its keep. Our Managed XDR and endpoint protection service brings logging, monitoring and rapid response together, watching across your endpoints and cloud around the clock so a quiet alert never becomes a 280-day problem. If building and staffing a full monitoring capability in-house feels out of reach, that is exactly the gap a managed offering is designed to fill.

Not sure whether you would spot a breach in progress? Let Rootsec put proper logging and monitoring in place with Managed XDR. Book a free consultation.

Logging gaps stay invisible until an incident exposes them. Our Managed XDR service covers the monitoring layer so they do not.