On August 10, 2026, five U.S. federal agencies and South Korea’s national police force issued a joint advisory on a ransomware operation called Gunra. Two details in it matter more than the malware. The crews do most of their scouting between 10 p.m. and 6 a.m. And on the way through, they delete the access logs and clear the command history.
So the morning after, the record of what happened is missing.
For most small offices, the answer isn’t another security product. It’s deciding where that record lives. Logs kept only on the machine that got hit die with it. Logs sent off the device survive. Your cloud accounts keep a separate trail, but it covers less than owners expect, and it doesn’t last forever.
Three Places Your Activity Record Can Live
Every computer in your office writes down what it does. Who signed in. What software started. When an account got created. That file sits on the same hard drive as everything else, which is the whole problem. An attacker with admin rights can erase it as easily as they can erase a spreadsheet.
Here’s how the three common setups compare on the things that decide your next week.
| Where the record lives | Survives a wiped machine | How far back you can look | What it covers |
|---|---|---|---|
| On each machine only. | No. It sits on the drive the attacker controls. | Weeks, until the file fills up and overwrites itself. | That one computer or server. |
| Cloud account logs only. | Yes. It lives on someone else’s servers. | A fixed window set by your subscription tier. | Email and file sharing. Not your local network. |
| Sent off the device as it happens. | Yes. The copy leaves before the cleanup starts. | As long as you pay to keep it. | Desktops, servers, firewalls, and cloud accounts together. |
What Survives After Someone Cleans Up
Off-device wins this one, and it isn’t close.
The joint federal advisory is specific about the cleanup. These actors mask their presence by deleting system and network access logs, and they clear the command history that would show what they typed. That’s not a side effect of encryption. It’s a deliberate step, taken while they still have the run of the place.
Local logs lose that fight by design. They’re a file on a disk, and the intruder owns the disk. A copy that already left the building can’t be reached the same way. This is also why ransomware detection depends less on catching the encryption and more on noticing the quiet week before it, when the odd logins and new admin accounts are still recorded somewhere readable.
How Far Back You Can Look
This one usually decides whether you ever learn the truth.
Intrusions aren’t discovered on day one. They’re discovered when a customer calls about a strange invoice, or when files stop opening. By then the first sign-in might be six weeks old. A local log that holds three weeks of activity can’t answer a six-week-old question, and neither can a cloud plan whose retention window closed last month.
The gap between the break-in and the discovery is where the cost accumulates, which is the same reason stolen logins go unnoticed for days at most companies. Set your security log retention longer than your realistic discovery time. For a small office, ninety days is a sane floor. A year is better if the data is regulated.
Finding out what you have today takes one conversation. Ask whoever runs your systems two questions: where do the records from our server go, and how many days do we keep them? If the answer to the first is “they stay on the server,” the second question has already answered itself.
What Each Option Actually Covers
Cloud logs are good at one job and blind to the rest.
If someone signs into your email from an unfamiliar country, that’s recorded, and you can go read it. Useful. But your cloud platform never sees the file server in the closet. It doesn’t see the firewall, the backup appliance, or the workstation where the first bad attachment opened. Those are exactly the machines a ransomware crew moves through, and they’re the ones with local-only logs.
Closing that gap is the ordinary work behind monitoring agents that report off the device. Each machine sends what it’s doing to a system it can’t itself edit. O&O Systems runs that as a standing service for Treasure Coast clients, alongside patch management and IT asset management, because a log you never collected is indistinguishable from one an attacker deleted.
The Question You Will Be Asked First
Owners assume the first question after an attack is whether the files come back. It isn’t.
These crews run what the advisory calls a double-extortion model. They copy your data out first, encrypt it second, then threaten to publish what they took if you don’t pay. So the questions that arrive on day two come from your customers, your insurer, and sometimes your state: did anything leave, and whose information was in it?
Answering that means showing which accounts were used, which folders were opened, and how much moved. Those records are exactly the ones the cleanup targets. Without them you’re guessing, and both directions of guessing are costly. Notify everyone and you’ve alarmed your whole client list over a file share nobody touched. Notify too narrowly and you find out later, in a worse room, with less credibility.
Which Setup Fits Your Office
Not every business needs the full build. Find yourself below.
Everything you own is already in the cloud
Six people, no server, email and files both hosted. Cloud logs plus a longer retention setting will cover most of what you’d need to reconstruct. Check what your current plan actually keeps, and for how long. Most owners have never looked, and the default is shorter than they assume.
You still run a server, a shared drive, or line-of-business software
Now cloud logs cover maybe half your risk. The machines holding your working files write their records locally, where they can be erased. This is the case for collecting off the device, and it’s the same infrastructure that makes round-the-clock IT monitoring possible in the first place. One system, two benefits.
You handle health, financial, or client records under a compliance rule
Treat off-device retention as required, not optional. When a regulator or an insurer asks what was accessed, “we can’t tell” is an expensive sentence. The advisory notes these crews demand that victims start negotiating within five to seven days. That’s not much time to work out what you lost while also deciding what to do about it.
If you’re not sure which of these you are, a free security risk assessment will show you what’s already exposed across your email, cloud, website, and infrastructure, including which weaknesses are exploitable today.
Where Sending Logs Off the Device Costs You
It’s fair to say what this option gives up.
You’re adding a monthly line item, and storage grows with your headcount. More than that, collection alone changes nothing. A pile of logs nobody reads is a filing cabinet, not a defense. The value only shows up when something reviews them and raises a hand, and when somebody knows what to do next. That’s the part small offices skip, and it’s why an incident response plan written on a calm Tuesday is worth more than any single tool.
There’s also an honest limit. Off-device logs tell you what happened. They don’t undo it. Recovery still rests on backups you’ve actually tested.
Frequently Asked Questions
Can deleted logs be recovered after an attack?
Sometimes, partially, and it’s slow and expensive. Specialists can occasionally pull fragments from a disk if the machine is preserved and nobody reuses it. Assume most of it is gone. That recovery cost, paid once, usually exceeds years of simply keeping a second copy somewhere safe.
Does antivirus software keep its own record?
It keeps a record of what it blocked, which is not the same as a record of what happened. If an attacker signs in with a real password your antivirus has nothing to flag, so nothing gets written. The quietest intrusions are the ones that never trip a tool.
How long should a small business keep security logs?
Ninety days is a reasonable floor for most small offices, because it’s longer than the typical gap between a break-in and the moment someone notices. Regulated data pushes that to a year. Whatever you choose, write it down, then confirm the system is holding to it.
See What’s Exposed Before Someone Else Finds It
You can’t fix a gap you can’t see, and the machines that would tell you are the same ones an intruder edits on the way out. Start with an outside view instead.
O&O Systems will run a free security risk assessment on your domain and show you what’s visible from the internet right now: email and cloud exposure, website and infrastructure weaknesses, SSL and TLS grades, and which of those a stranger could act on. It costs nothing, and it’s a far better starting point than a log file you’re hoping still exists.