Logging, Alerting & Data Retention
9 checks · 2 sub-categories
When something goes wrong, the question is always the same: what did they access, and can you prove it? Under the Notifiable Data Breaches scheme you have 30 days to assess a suspected breach. Without logs and retention configured in advance, that assessment is guesswork — and guesswork usually means notifying everyone.
Visibility
Admin, login, Drive and Gmail audit logs available
We confirm which log sources are being generated, how far back they go on your licence, and where the gaps are.
- NDB scheme
- Essential Eight — Monitor and analyse event logs
Alert Center rules configured and routed to a human
Default alerts fire into a console nobody opens. We check which rules are on and whether notifications reach a monitored mailbox.
Custom alerts for high-risk events
Super admin grants, mass downloads, forwarding rule creation and suspicious sign-ins each deserve a named alert. We check for them individually.
Log export to BigQuery or a SIEM
Where retention beyond the console default matters, we check whether logs are exported and retained for a defined period.
Retention and investigation
Google Vault retention rules defined
Without a retention rule, deleted mail and files eventually purge — including evidence. We check default and custom retention rules across Gmail, Drive, Chat and Meet.
- Privacy Act APP 11
- TPB record-keeping (accounting)
- RACGP (health)
Legal hold capability tested
We confirm holds can be applied to individuals and OUs, and that the people who'd need to apply one know how.
Data regions and residency settings
Where a client or regulator requires data to stay in a defined region, we check the data region policy applied to your OUs.
Backup and recovery arrangements beyond Vault
Vault is retention, not backup. We check whether a genuine third-party backup exists for Gmail and Drive and how quickly a restore could actually happen.
Incident response contact details current in the console
Google sends security notifications to the contacts on file. We check they point to someone who still works there.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.