Cybersecurity Glossary

SIEM

A system that collects logs from everywhere and raises alerts on suspicious patterns.

What SIEM means

Security information and event management gathers logs from servers, cloud services, firewalls and endpoints into one place, correlates them, and alerts when a combination looks dangerous. It answers questions no single system can, such as whether the same account signed in from two countries within an hour.

Why SIEM matters for small businesses and nonprofits

A full deployment is heavy for a small organisation, but a light version covering identity, email and endpoints is realistic and is often what a cyber insurer or a larger client asks about.

What to do about SIEM

Three steps to deal with SIEM

  • Start by centralising identity and email logs, where the highest value signals are
  • Define a small number of alerts that a real person will act on
  • Set a log retention period long enough to investigate a slow intrusion

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.