A SIEM project can fail if the company starts directly with:
“Which SIEM are we going to buy?”
The first question should rather be:
“What threat scenarios do we want to detect?”
Afterwards :
“What data do we need to collect to detect them?”
Then :
“How will we analyze and process the alerts?”
And finally:
“Which technology meets these needs?”
This approach helps avoid the syndrome of:SIEM installed but useless.