SIEM should never be considered as a sole form of protection.
A mature cybersecurity architecture typically relies on several layers:
Prevention
- firewall
- MFA
- segmentation
- EDR
- hardening.
Detection
- SIEM
- EDR/XDR
- IDS
- monitoring.
Answer
- SOC
- SOAR
- incident procedures.
Resilience
- backups
- PRA
- PCA
- redundancy.
Governance
- policies
- risk management
- compliance
- audits.
The SIEM is primarily located in the following layers:detection + investigation + monitoring.