Introduction
The Cloud Evidence Gap in IoT Investigation
IoT device investigation recovers evidence from the device itself — storage contents, memory artefacts, firmware images, configuration records. What it cannot recover is the platform-side record of how that device communicated with its cloud backend, what commands it received, what telemetry it sent, and what authentication events preceded the incident. This platform-side evidence frequently contains the most complete record of incident timeline and attacker activity available — and it resides on cloud infrastructure that device-level investigation cannot reach.
For SaaS organisations providing IoT device management, telemetry analytics, or connected device orchestration, the cloud-side evidence they hold on behalf of customers is forensically significant — and the forensic preservation obligations that significance creates are not yet universally understood. When customers experience IoT incidents and require platform-side forensic evidence, the SaaS provider's response determines whether the investigation can be completed or whether critical evidence has been lost to routine retention policies.
This gap is becoming commercially significant. Enterprise customers in regulated sectors are increasingly asking SaaS IoT platform providers specifically about forensic evidence preservation — what logs are retained, for how long, at what granularity, and how they would be made available for a formal forensic investigation. Providers whose answers demonstrate that forensic evidence considerations have been built into platform design are demonstrating a governance maturity that procurement processes in financial services, healthcare, and critical infrastructure are beginning to reward.
What Cloud IoT Platform Evidence Actually Contains
Understanding what cloud IoT platforms hold forensically — and what their default retention behaviour does with it — is the starting point for building meaningful forensic evidence preservation.
-
Device authentication logs: Every device connection, authentication event, certificate presentation, and credential use is recorded on the platform. These records establish which devices connected, when, from which network endpoints, and whether authentication was successful or failed — evidence directly relevant to incident timeline reconstruction.
-
Telemetry data streams: The continuous stream of sensor readings, status updates, and operational data sent by devices to the platform. Anomalies in telemetry patterns — sudden value changes, transmission gaps, unusual data volumes — are forensic indicators of device compromise, manipulation, or interference.
-
Command and control records: Every command sent from the platform to devices — configuration updates, firmware push notifications, operational instructions — is logged. These records are directly relevant to investigations involving unauthorised device commands or backdoor command channels.
-
API access logs: Every API call made to the platform — device registration, data retrieval, configuration update, firmware deployment — is recorded with caller identity, timestamp, parameters, and response. API log analysis identifies unauthorised access, credential misuse, and data exfiltration events that occurred through legitimate API channels.
-
Provisioning and deprovisioning records: Device registration, certificate issuance, access policy assignment, and removal events — evidence relevant to insider threat investigations and supply chain compromise analysis.
The Retention Policy Problem
Most cloud IoT platforms apply default retention periods to log data that are optimised for cost management, not forensic investigation. Thirty-day default retention for telemetry streams, ninety-day retention for API access logs, and seven-day retention for real-time event data are common configurations that create forensic evidence gaps for investigations initiated more than a few weeks after the incident.
The organisations that discover these retention characteristics after an incident are consistently surprised. They assumed that cloud platforms retain comprehensive logs indefinitely. They did not review the retention configuration of their IoT platform before the investigation required them to. The evidence they needed had been deleted by routine retention policies operating exactly as configured — and there is no recovery from that loss.
-
Default retention periods on major cloud IoT platforms vary significantly by log type — and the most forensically significant data categories are frequently subject to the shortest retention periods.
-
Retention period extension typically requires proactive configuration — it does not happen automatically when an incident is identified unless legal hold procedures are activated immediately.
-
Third-party SaaS IoT platforms may not offer configurable retention at all — making pre-contractual forensic retention negotiation the only mechanism available for preserving investigation-critical evidence.
Why Enterprise Customers Are Starting to Ask
Enterprise customers in regulated sectors are increasingly including forensic evidence preservation in their SaaS IoT platform due diligence requirements. The driver is not theoretical governance concern — it is the experience of IoT incidents where platform-side evidence was needed and was not available because retention had not been addressed before the incident.
-
Financial services enterprise customers are asking SaaS IoT providers to demonstrate that platform logs relevant to incident investigation are retained for periods sufficient for forensic investigation — as a condition of contract execution.
-
Healthcare enterprise customers require evidence that connected medical device platform logs are retained in compliance with data breach investigation requirements — with specific questions about authentication log retention and telemetry stream preservation.
-
Critical infrastructure customers operating through SaaS IoT management platforms are including forensic evidence access and retention provisions in contractual requirements — specifying minimum retention periods, log granularity, and evidence production procedures for regulatory investigations.
What a Forensically Prepared SaaS IoT Platform Looks Like
SaaS IoT platforms that have built forensic evidence preservation into their architecture share several characteristics that distinguish them from platforms where retention is an afterthought.
-
Configurable retention with extended options: Offering customers the ability to configure retention periods beyond defaults — including extended retention for security-relevant log categories that investigations most frequently require.
-
Forensic evidence access procedures: Documented procedures for how forensic investigators can access platform logs, including the authentication requirements, format specifications, and chain-of-custody considerations relevant to forensic evidence acquisition.
-
Legal hold support: A defined process for implementing legal hold on platform logs when customers notify the provider of an incident — extending retention beyond default periods for the duration of the investigation.
-
Log granularity and completeness: Retention of authentication, telemetry, API access, and command logs at the granularity needed for forensic timeline reconstruction — not aggregated data summaries that lose the individual event records investigations require.
How Codec Networks Helps: Building IoT Platform Forensic Evidence Capability
Codec Networks' IoT Forensics service provides SaaS IoT platform providers with the forensic evidence preservation guidance and investigation support they need to satisfy enterprise procurement requirements and conduct complete investigations when incidents occur.
-
Platform Forensic Evidence Assessment: We assess the forensic evidence preservation characteristics of the SaaS IoT platform — retention periods, log granularity, access procedures, and legal hold capability — producing the gap analysis and implementation roadmap that enterprise customer requirements demand.
-
Retention Configuration Advisory: For configurable cloud IoT platforms, Codec Networks identifies the specific retention settings needed to preserve investigation-critical log categories for forensic investigation periods — aligned to the incident investigation timelines that applicable in-country norms and regulations specify.
-
Contractual Forensic Provision Development: We develop the forensic evidence retention, access, and cooperation provisions that SaaS IoT platform providers can include in enterprise customer contracts — demonstrating proactive forensic governance rather than reactive evidence production.
-
Platform-Side Forensic Investigation: When incidents occur, Codec Networks conducts the cloud platform forensic investigation — acquiring and analysing the authentication, telemetry, API, and command log evidence that device-level investigation cannot recover.
-
Customer-Facing Forensic Documentation: We produce the platform forensic evidence documentation that enterprise customers require for their own regulatory submissions, insurance claims, and legal proceedings — formatted to the evidentiary standards applicable to each customer's regulatory context.
Conclusion
Cloud IoT platform forensic evidence is among the most complete records of connected device activity available to investigations — and among the most commonly lost to retention policies that were never configured with investigation requirements in mind. SaaS IoT platform providers that build forensic evidence preservation into their platform architecture are not just improving their own governance — they are providing their enterprise customers with the investigation capability that incident response requires.
The enterprise procurement processes that are beginning to require forensic evidence retention documentation from SaaS IoT providers are not going away. Providers that build the capability proactively will be in a significantly stronger commercial position than those that build it reactively under deal-specific pressure — or that discover its absence under incident investigation conditions where the evidence window has already closed.
