Todd Schryer, CGI Federal

Todd Schryer

Director

In the years since the 2020 SolarWinds cyberattack, agencies have worked to strengthen logging practices, but it has not been easy for many of them. Earlier federal guidance created cost, scale and feasibility challenges.

The SolarWinds attack had consequences spreading far beyond the breached company, disrupting supply chains across multiple industries and the federal government.  It exposed how deeply adversaries could infiltrate trusted environments and underscored the need for stronger detection, visibility and response capabilities. 

Today, agencies face renewed urgency to modernize logging, but with a more flexible path forward. The May release of OMB Memorandum M 26 14 offers an opportunity to rethink what effective logging looks like in 2026 and beyond, and how to build a strategy that is both resilient and achievable.

Why agencies must rethink logging now

Cyber threats targeting federal environments continue to evolve in speed, sophistication and intent, and at an accelerating rate. Logging is one of the most valuable tools agencies have to detect abnormal behavior early, investigate incidents quickly and restore trust after a breach. Yet logging also requires balancing several trade offs:

  • Visibility vs. cost: Capturing months of actionable data is essential for modern forensics, but long-term retention can strain budgets and storage systems.
  • Breadth vs. relevance: Creating more logs does not automatically mean deriving better insight. Agencies need the right sources, not just more sources.
  • Consistency vs. agility: Logging policies must remain standardized enough for cross agency coordination while adapting to unique mission requirements.

M 26 14 directly addresses these challenges through a shift toward outcomes focused, risk based logging. It replaces rigid and prescriptive directives with guidance that empowers an agency to tailor logging to its mission, maturity and threat environment.

A new paradigm: visibility guided by risk

At the core of M 26 14 are two foundational capabilities:

Continuous Event Monitoring (CEM) – focused on real-time behavioral monitoring and anomaly detection, enabling agencies to identify suspicious activity before it escalates.

Threat Hunting, Investigation, Response and Forensics (THIRF) – focused on deep forensic analysis, root cause investigation and evidence based response after an incident occurs.

Together, these functions give agencies a more balanced, flexible model in which they monitor continuously, investigate comprehensively and retain enough data to enable timely, accurate decision-making.

Another significant aspect of M 26 14 is Cybersecurity and Infrastructure Security Agency’s (CISA) role in a new Logging Reference Architecture (LRA). The LRA, released on August 20, is designed to unify expectations, clarify maturity levels and support agencies in developing an actionable Agency Logging Plan within 90 days. Subsequent milestones at 120, 180 and 320 days are intended to accelerate progress while recognizing that agencies are starting from different baselines.

Why modernization must start now

Across federal missions, agencies are already preparing for M 26 14. Based on CGI’s experience supporting the federal cybersecurity ecosystem—and especially our work across CISA’s Continuous Diagnostics and Mitigation (CDM) program—three insights stand out:

Early preparation matters.
The paradigm shift introduced by M 26 14 is substantial. Agencies that begin identifying priority log sources, retention requirements and monitoring gaps today will be better positioned to meet upcoming deadlines.

Unifying CEM and THIRF creates real operational value.
The CDM DEFEND F Shared Services Platform (SSP) 2.0 delivers centralized ingestion, log aggregation, search capabilities and analysis through CGI’s Consolidated Log Aggregation Solution (CLAS) and the CDM Security Information and Event Management as a Service (SIEMaaS) offering, reducing operational complexity and strengthening forensic investigations.

Mature logging is about quality, not volume.
CDM DEFEND F CARE Watch operations provide continuous visibility, monitoring and remediation across federal environments. This is especially important because the logs that consistently matter most are not always the ones that are prioritized first. Agencies benefit when they focus on high value indicators and mission specific risk, an approach fully aligned with M 26 14.

These insights reflect a broader trend. Agencies need logging architectures that deliver clarity, speed and actionable visibility across both monitoring and forensic workflows. Design architectures to avoid clutter and sprawl, which can easily proliferate if not protected against.

Leveraging OMB guidance to strengthen federal cybersecurity

M 26 14 represents a meaningful evolution in federal cybersecurity. It gives agencies room to design logging strategies grounded in mission, risk and outcomes while still meeting federal expectations for visibility and accountability. As agencies navigate this transition, they have a chance to reshape how logging fortifies cybersecurity end to end, from threat detection to investigation and on to response.

The question now is how quickly and confidently agencies can align their capabilities with this new model. Agencies that take a strategic, phased approach will be best positioned to improve resilience and meet the demands of today’s threat landscape. 

By partnering with CGI, agencies can benefit from our unique expertise and services around federal cybersecurity in general, and log management programs in particular, to fully exploit the opportunity that M-26-14 introduces. To explore the practical ways to turn this evolving landscape into meaningful business outcomes, fill out the form below.

Connect with our cyber experts

About this author

Todd Schryer, CGI Federal

Todd Schryer

Director

Todd Schryer is a Director in CGI Federal’s cybersecurity practice and a Certified Information Systems Security Professional (CISSP).