Administrator accounts generally require enhanced monitoring. This includes monitoring for: […]
SIEM is not only for external attackers. It can also help detect […]
Ransomware presents a particularly interesting scenario for demonstrating the usefulness of a SIEM. Before mass encryption, […]
In a properly configured environment, SIEM enables the construction of a true audit trail. This traceability […]
The SIEM can also help audit teams answer certain questions: The capacity […]
For the financial entities concerned, the European DORA regulation significantly strengthens the requirements related to […]
The European NIS2 directive strengthens requirements for cyber risk management, management […]
The SIEM is not just a technical tool. It can also help demonstrate that the company […]
The correlation is highly dependent on the accuracy of the timestamps. For example: Firewall: 10:32:14 Server: […]
An often overlooked point is that logs are a target. An attacker who wants to delete […]