A company should, in particular, ask itself the following questions:
- Do we have a centralized view of security events?
- Do we know how to detect unusual connections?
- Are we monitoring privileged accounts?
- Do we keep the logs long enough?
- Are the logs protected against modification?
- Are our systems synchronized in time?
- Do we know how to reconstruct the chronology of an incident?
- Are we monitoring cloud environments?
- Are we monitoring identities?
- Do we have any documented use cases for detection?
- Are our SIEM rules tested?
- Are we measuring false positives?
- Do we have a procedure in place when a critical alert appears?
- Do we know who analyzes the alerts outside of business hours?
- Have we tested our ability to detect ransomware?
- Have we tested the detection of lateral movements?
- Do we know which MITRE ATT&CK techniques we are capable of detecting?
- Are our logs sufficiently protected to be used in an investigation?
- Have we assessed the true cost of storage and analysis?
- Is our SIEM strategy aligned with our risk analysis?
If several answers are negative, the problem is not necessarily the absence of a SIEM.
It may be more fundamental: the company may still lack a real cybersecurity detection and monitoring strategy.
The SIEM should therefore be considered not as the first step, but as one of the building blocks for constructing this capability.