---
title: "Managed SIEM — the logs that connect everything"
description: "What a SIEM is, who really needs it — and who does not yet: central collection and 24/7 analysis of your security logs, as a per-data-source block."
canonical: "https://corevatis-redesign.pages.dev/en/services/managed-siem/"
lang: en
schema_type: WebPage
---
# Managed SIEM — the logs that connect everything

What a SIEM is, who really needs it — and who does not yet: central collection and 24/7 analysis of your security logs, as a per-data-source block.

## The short version

- **What:** Security logs from firewall, servers and cloud services collected centrally, retained, and analysed around the clock by analysts.
- **Why:** Individual systems see individual events. Only connecting the logs makes an attack pattern visible — and provides the audit evidence.
- **For whom:** Companies under NIS-2 or audit duties, with several sites or elevated protection needs. Not everyone needs it right away — we say honestly who does.
- **Billing:** Per connected data source per month, as its own position.

A good fit if:

- NIS-2, ISO 27001 or a customer audit demands logging and analysis
- Firewall, servers and cloud log diligently — but nobody looks
- After an incident it must be reconstructable what happened when

## What is a SIEM — in one sentence?

A SIEM (Security Information and Event Management) collects the **security logs** of all important systems — firewall, servers, Microsoft 365, network — in one place, retains them audit-proof, and analyses them in context: around the clock, by an analyst team, not by an inbox full of warning mails.

## Why individual alerts are not enough

Each of your systems already logs. But each sees only its slice. A real attack leaves traces **across several systems**: a rejected login at the firewall, a successful one at the server ten minutes later, then an unusual data outflow. Three systems, three unremarkable single events — a pattern only visible to whoever lays all three side by side.

The second reason is less comfortable: **evidence duties.** NIS-2, ISO 27001 and increasingly cyber insurers demand not only that you log — but that someone analyses, and that incidents can be reconstructed. A log that gets overwritten after 30 days and that nobody ever read does not satisfy that.

## Who needs it — and who does not (yet)?

Honest classification, because this is the block most often sold too early:

- **Needs it:** companies under NIS-2 or with ISO-27001/customer-audit duties; companies with several sites or elevated protection needs.
- **Benefits:** anyone who ever stood in front of the question "what actually happened here?" — without an answer.
- **Usually does not need it yet:** the 15-person business without regulation. There, [endpoint protection](/en/services/endpoint-schutz) and [identity protection](/en/services/identitaetsschutz) deliver the most protection per euro. We sell the sequence, not the maximum.

## What we take on

- Connecting the relevant data sources — firewall, servers, Microsoft 365, [network](/en/services/netzwerk-standort) — to central analysis
- 24/7 analysis by the analyst team; real incidents reach us as qualified findings, not raw data floods
- Retention that lets incidents be reconstructed months later
- The audit answer: to "how do you analyse security events?" you answer with a procedure, not a shrug

## Billing

Per connected data source per month, as its own position — [like every block](/en/services/add-ons). Which sources make sense for your size is set in the assessment — starting small works, for instance with firewall and Microsoft 365.

## FAQ

**Is this not enterprise technology?**
It was, for a long time — when SIEM meant: own platform, own staff, six figures. As a managed per-source block it is affordable for the mid-market today. Whether it is *necessary* is the better question — see above.

**We already have EDR — why SIEM too?**
EDR sees devices, ITDR sees accounts. The SIEM sees what happens between and around them — firewall, server services, network — and connects everything into one picture. It is the third layer, not a replacement for the first two.

## Related topics

- [IT security overview — operations plus protection blocks](/en/services/it-sicherheit)
- [Endpoint protection (EDR) — the guard on the device](/en/services/endpoint-schutz)
- [Identity protection (ITDR) — the guard on the account](/en/services/identitaetsschutz)

