Skip to main content

SIEM

Security Information and Event Management

Illustration of SIEM

In short

A SIEM, security information and event management, collects the logs of every system in one place – firewall, servers, Microsoft 365, endpoints – and searches them for patterns that point to an attack. Single events are often harmless; their combination is not: five failed logins, then a successful one from abroad, then a large download. A SIEM sees that chain, which no individual system would flag.

The common mistake: a SIEM protects you

A SIEM prevents nothing. It detects and reports. Without someone reacting to the report, it is an expensive archive of alerts nobody has read.

More important than the choice of product is therefore who is watching at three in the morning. The combination of tool and people is called a SOC, a security operations centre.

When an SME needs one

Not every SME needs its own SIEM. A business with ten workstations on Microsoft 365 is often better served by the built-in detection and solid endpoint security than by a system nobody looks after.

A SIEM starts to make sense when several systems interact, sensitive data is processed or customers ask for evidence of monitoring – usually as a service rather than a project of your own.

For a Swiss company

Since 1 April 2025, operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity within 24 hours. For most SMEs this does not apply directly, but it can reach suppliers through their contracts with such operators.

Independently of that, data protection law applies: a breach of data security likely to result in a high risk for the people affected must be reported to the FDPIC (Art. 24 FADP). Only someone who recorded the events knows what needs reporting.

How we handle it

We run monitoring as a service with a person behind it, sized to the business. Often the detection already included in Microsoft 365 is enough – as long as someone reads it.

Where more is needed, a SIEM belongs to IT security, together with zero trust and a working backup for the case where detection comes too late.

Where this sits with us

Last reviewed:

A term in your quote that nobody explained?

In a strategy call we translate the offer in front of you – even when it did not come from us.

Back to the glossary

We use cookies to understand how this website is used and to improve it. Necessary cookies are always active; everything else only with your consent. More in our Privacy Policy