Detection & Response
Log Management & SIEM SIEM
A platform that collects and correlates firewall, server, identity, cloud and endpoint logs in one place, raises alerts on suspicious patterns and provides legal retention.
When you need it
- If you have log retention obligations (BDDK (Turkish banking regulator), PCI DSS, the CBDDO Information and Communication Security Guide, Turkish Law No. 5651)
- If you have a security team or SOC to watch the alerts
- If you cannot answer "what happened" after an incident
When you do not need it
- If nobody watches the alerts, a SIEM is just an expensive log archive. For small/mid-sized organizations, an MDR service (the provider runs the SIEM) + a legal log archive is the better investment.
High-value sources first: identity (AD/Entra), EDR, firewall, VPN, email. Collecting everything blows up the cost.



