Häufig gestellte Fragen
What does a SIEM system actually do?
A SIEM (Security Information and Event Management) collects security-relevant log and event data from servers, network components, firewalls, identity services and applications such as the ERP in one central place. It converts these disparate raw data into a uniform format, enriches them with context and correlates them largely in real time against defined rules and behaviour patterns. In this way, individual events that are harmless on their own are only recognised as suspicious in context and reported to the security officers with prioritisation. The real added value thus lies less in mere storage than in this correlation and the early, prioritised alerting.
Is a SIEM worthwhile for mid-market ERP landscapes?
As headcount grows and sensitive business, financial and HR data resides in the ERP, the value of central security monitoring rises considerably, since traces of attacks otherwise remain scattered across many individual system logs. Cloud-based SIEM services can nowadays be operated on a usage-based basis and without in-house server infrastructure, which eases entry compared with classic on-premise installations. What is decisive, however, is less the tool itself than the question of whether the alerts triggered can actually be evaluated and processed, whether by an in-house team or an external service provider. A SIEM without sufficient analysis capacity mainly ties up budget and can generate false alarms without measurably increasing security, which is why the sensible setup varies by industry, size class and regulatory pressure.
What does a SIEM cost and how is the price composed?
Most SIEM solutions charge according to the volume of data ingested daily or annually, usually measured in gigabytes per day (GB/day), sometimes supplemented by workload- or capacity-based models. Cloud services such as Microsoft Sentinel are often billed per gigabyte ingested, with noticeably cheaper tiers for reserved daily quotas (commitment tiers), while established platforms such as Splunk are traditionally regarded as higher-priced and usually only quote specific amounts through sales. Open-source tools such as Wazuh or Elastic incur no licence costs per data volume but shift the effort to hardware, operations and maintenance. Since prices depend heavily on region, data volume and retention period, reliable statements are only possible on the basis of a specific quote and the realistically expected log volume.
Is a SIEM mandated by NIS 2?
The NIS 2 Directive and the German implementing act do not prescribe a SIEM by name, but they explicitly require affected companies to take measures for monitoring and logging as well as for detecting security incidents. In practice, a SIEM is therefore considered an obvious building block for meeting these requirements in an automated and verifiable way, especially since NIS 2 provides for a tiered reporting regime with short deadlines (early warning within 24 hours, follow-up report within 72 hours, final report after around one month). Due to the expanded thresholds, many mid-market companies and IT service providers now fall under binding security requirements for the first time that were previously not regulated to this extent. Whether and to what extent a SIEM is required should always be clarified in an individual legal and security assessment.
How does a SIEM differ from SOC, SOAR, EDR and XDR?
A SIEM is the collection, correlation and analysis layer that brings together events from many sources and generates alerts, while a SOC (Security Operations Center) is not a tool but the team and process that evaluates and handles those alerts. SOAR (Security Orchestration, Automation and Response) complements the SIEM with automated response workflows, such as locking an account, and is often integrated directly into modern platforms. EDR and the broader XDR (Extended Detection and Response) focus on detection and response on endpoints or across the entire security stack, and in some cases also feed data into the SIEM. Smaller organisations increasingly outsource operation and analysis to external providers, for instance as managed SIEM or managed detection and response (MDR), which differ mainly in how far the response to an alert goes.
Which ERP data does a SIEM typically monitor?
In the ERP environment, a SIEM primarily ingests the logs of login and authentication events, frequently via integration with directory services such as Active Directory or with single sign-on solutions, in order to detect unusual login patterns. In addition, the ERP's audit trail and changes to the underlying role and authorisation concept serve as data sources, making silent privilege escalations or access outside the usual scope of duties visible, for example. Conspicuous mass exports of master data or unusually high database queries via service accounts can also be assessed in the context of other systems. Decisive for effectiveness is less the number of connected sources than the quality of the data and the correlation rules tuned to them.
