What is a SIEM — in one sentence?
A SIEM (Security Information and Event Management) collects the security logs of all important systems — firewall, servers, Microsoft 365, network — in one place, retains them audit-proof, and analyses them in context: around the clock, by an analyst team, not by an inbox full of warning mails.
Why individual alerts are not enough
Each of your systems already logs. But each sees only its slice. A real attack leaves traces across several systems: a rejected login at the firewall, a successful one at the server ten minutes later, then an unusual data outflow. Three systems, three unremarkable single events — a pattern only visible to whoever lays all three side by side.
The second reason is less comfortable: evidence duties. NIS-2, ISO 27001 and increasingly cyber insurers demand not only that you log — but that someone analyses, and that incidents can be reconstructed. A log that gets overwritten after 30 days and that nobody ever read does not satisfy that.
Who needs it — and who does not (yet)?
Honest classification, because this is the block most often sold too early:
- Needs it: companies under NIS-2 or with ISO-27001/customer-audit duties; companies with several sites or elevated protection needs.
- Benefits: anyone who ever stood in front of the question “what actually happened here?” — without an answer.
- Usually does not need it yet: the 15-person business without regulation. There, endpoint protection and identity protection deliver the most protection per euro. We sell the sequence, not the maximum.
What we take on
- Connecting the relevant data sources — firewall, servers, Microsoft 365, network — to central analysis
- 24/7 analysis by the analyst team; real incidents reach us as qualified findings, not raw data floods
- Retention that lets incidents be reconstructed months later
- The audit answer: to “how do you analyse security events?” you answer with a procedure, not a shrug
Billing
Per connected data source per month, as its own position — like every block. Which sources make sense for your size is set in the assessment — starting small works, for instance with firewall and Microsoft 365.
FAQ
Is this not enterprise technology? It was, for a long time — when SIEM meant: own platform, own staff, six figures. As a managed per-source block it is affordable for the mid-market today. Whether it is necessary is the better question — see above.
We already have EDR — why SIEM too? EDR sees devices, ITDR sees accounts. The SIEM sees what happens between and around them — firewall, server services, network — and connects everything into one picture. It is the third layer, not a replacement for the first two.