A common misconception is that SIEM is reserved for large companies.

That's not necessarily true.

An SME may need centralisation and monitoring capabilities, but its approach must be proportionate.

In particular, it could consider:

  • a SaaS SIEM
  • an outsourced SOC service
  • an MSSP
  • a log management solution
  • an integrated security platform.

The essential question is not:

“Are we big enough to have a SIEM?”

But: “What level of visibility and detection is necessary given our risk?”

Categories: