How long is long enough?
This isn’t a hypothetical concern. As we have identified in other reports, according to IBM’s Cost of a Data Breach Report 2026, the average breach now takes 247 days to identify and contain, a figure that ticked back up this year after five straight years of improvement. That’s the better part of a year between the moment an attacker gets in and the moment the incident is actually closed out, and every day of that window depends on evidence that has to still exist somewhere.
A 30 or 90-day retention window, common once cost pressure forces a SIEM’s retention settings down, simply doesn’t reach that far back. By the time an investigation starts, the logs from the actual point of compromise may already be gone.
Compliance adds a second, separate reason retention needs to be measured in months and years rather than weeks.
ISO/IEC 27001:2022, the globally recognized standard for information security management, makes this explicit under Annex A Control 8.15 (Logging), which requires that logs be produced, stored, protected and analysed, backed by related controls covering monitoring activities (8.16), clock synchronization (8.17) and protection of records (5.33).
Sector-specific frameworks layer their own obligations on top: PCI DSS, HIPAA, SOX and GDPR all routinely require evidence retained well beyond a typical SIEM’s default window, independent of whether an incident has even been detected yet.
It’s also a useful lens for the security data layer itself.
Snare Agent handles the “produce.”
Snare Central handles “store” and “protect,” with retention configurable from 90 days to 7+ years to match whatever obligation applies.
AskSnare handles “analyse.”
Rather than a policy document asserting compliance, it’s an architecture that maps directly onto what the control actually asks for.