What it is and what it does
A SIEM centralizes and analyzes logs. A security operations center, or SOC, is the people and operating process that review alerts and coordinate response. Buying log storage does not create round-the-clock response. CISA: logging and monitoring for business systems.
What that means for your business
A suspicious administrator sign-in at 2 a.m. may appear in several systems. Central monitoring can connect the activity, but the business still needs a named responder with authority to disable access or isolate a device.
Is this a baseline system?
Important systems should produce usable logs and high-risk alerts should have an owner. A dedicated SOC or SIEM depends on scale, consequence, regulatory expectations and the support model.
Will insurance ask about it?
An insurer may ask about detection, EDR, monitoring and incident response. State the actual hours, systems covered, retention and authority to act. Do not describe an alert-only service as managed response.
See the insurance sources and how to interpret the levels.
Minimum operating position
Logging for identity, endpoints, firewalls and critical applications; protected retention; high-risk alerts; and a documented escalation path.
When the business needs stronger protection
Central correlation, after-hours coverage, threat hunting, tested containment authority, investigation records and regular tuning against business changes.
Evidence to request from IT
- Log source inventory and retention periods.
- Sample high-risk alert through resolution.
- Coverage hours, response commitments and escalation contacts.
What belongs in the budget
Separate data ingestion and retention from analyst coverage. Include onboarding, tuning, investigation, after-hours response and incident support.
A documented incident
InfoTrax: years of activity went undetected
The FTC alleged ineffective intrusion detection and file-integrity monitoring while an attacker repeatedly accessed sensitive information. FTC: InfoTrax monitoring and network separation failures, 2019.
What this case shows: Logs create value only when the right activity is captured, reviewed and escalated. This does not imply that a named SIEM product was required.
Sources and scope
- CISA: logging and monitoring for business systems
- FTC: InfoTrax monitoring and network separation failures, 2019
The baseline and stronger-protection positions are editorial planning guidance. Confirm your company’s required controls and insurance answers with the accountable IT owner and broker.