An important distinction must be made. SIEM primarily improves visibility. And visibility […]
It would be dangerous to assume that a SIEM can replace: The SIEM primarily observes this […]
SIEM should never be considered a sole form of protection. A mature cybersecurity architecture […]
Mistake #1: Sending absolutely all logs. This often increases noise and cost. […]
The Purple Team combines the functions of the Red Team and the Blue Team. The Red Team simulates […]
A company shouldn't simply assume its SIEM works. The rules need to be tested. […]
A SIEM is never truly “finished.” The environment evolves: the rules must therefore evolve. The false […]
A SIEM should be evaluated using indicators. For example: MTTD (Mean Time To Detect) […]
A SIEM use case typically describes: Example: Use case: Compromise of a privileged account […]
A SIEM project can fail if the company starts directly with: “Which SIEM are we going to buy?” […]