Detection & Response

Log Management & SIEM SIEM

A platform that collects and correlates firewall, server, identity, cloud and endpoint logs in one place, raises alerts on suspicious patterns and provides legal retention.

When you need it

  • If you have log retention obligations (BDDK (Turkish banking regulator), PCI DSS, the CBDDO Information and Communication Security Guide, Turkish Law No. 5651)
  • If you have a security team or SOC to watch the alerts
  • If you cannot answer "what happened" after an incident

When you do not need it

  • If nobody watches the alerts, a SIEM is just an expensive log archive. For small/mid-sized organizations, an MDR service (the provider runs the SIEM) + a legal log archive is the better investment.

High-value sources first: identity (AD/Entra), EDR, firewall, VPN, email. Collecting everything blows up the cost.