Attack detection at mid-sized firms: run a SIEM yourself or outsource it?
2026-08-07 · by SECURITYSQUAD

The most uncomfortable number in information security is how long it takes before an attack is noticed at all. In its M-Trends 2026 report, Mandiant puts this dwell time at a median of 14 days – up from 11 the year before. Two weeks in which somebody looks around your network, escalates privileges and extracts data. The reason is rarely ill will; it is simply that nobody is watching.
What a SIEM does – and what it does not
SIEM stands for Security Information and Event Management. Put simply, it collects the security-relevant events from your systems – servers, firewalls, endpoints, cloud services – in one place, correlates them and raises an alarm when a pattern is wrong.
The value lies in the correlation, not the collecting. A failed login means nothing. Fifty failed logins, followed by a successful one, followed by a new administrator account and an unusually large data transfer at three in the morning – that is a story. No human assembles it from four separate log files; a SIEM does exactly that.
Equally important is what a SIEM is not. It prevents nothing. It is no substitute for endpoint protection, patching or backups. It is the early warning system, not the wall. If the basics are missing, start there rather than with detection.
Where running it yourself falls down
Setting up a SIEM is one thing; operating it usefully is another. Three things are almost universally underestimated.
The arithmetic of "around the clock". Staffing one seat continuously takes, across 168 hours a week plus leave and sickness, a realistic five to six full-time people. Not five to six hours – five to six posts. For most mid-sized companies that is not a budget question but an impossibility, not least because those people are barely available on the job market.
False positives. A freshly installed SIEM reports everything. Without tuning, the team drowns in alerts, and after a fortnight nobody looks any more – the real danger is not the missed alert but the numbed team. Maintaining rules and weeding out false positives is continuous work, not a setup task.
Connecting the data sources. A SIEM sees only what it is fed. If the logs from the domain controller, the firewall or Microsoft 365 are missing, blind spots appear exactly where attackers operate.
A managed SIEM closes precisely that gap: you get operation, tuning and assessment as a service, without building a team.
What to connect first
Not everything at once. The order that yields the most benefit per unit of effort:
- Identity – domain controllers and Microsoft 365. Almost every attack runs through an account.
- Perimeter – firewall, VPN access, externally reachable services.
- Endpoints – servers first, then clients.
- Critical applications – ERP, file shares, anything holding customer data.
After those four steps you see most of what an attacker has to do in order to make progress.
What it actually delivers
Attacks are detected while they are happening, not once the damage is done. At the same time a complete, traceable record accumulates – valuable for working through an incident and for evidence towards regulators and insurers.
Regulatory pressure now adds to this. Germany's NIS2 implementation act has been in force since 6 December 2025 and requires entities in scope to have measures for handling security incidents, including a reporting duty within 24 hours. That deadline only holds for those who notice the incident at all, and promptly. For operators of critical infrastructure, the BSI Act mandates attack detection systems outright.
How to recognise a workable provider
Ask about these five points before you sign:
- Where does the data sit? Logs contain personal data. Operation in Germany and a data processing agreement are not a luxury but a precondition.
- What happens when an alarm fires? Do you get an email or a phone call? Who decides, who acts, and within what time?
- Who owns the data and the rules? On switching providers, can you take your logs and detection rules with you, or do you start from zero?
- How long is data retained? Working through an incident needs months, not days.
- How is it billed? Volume-based models can surprise you unpleasantly the moment you connect a talkative data source.
Built for the mid-market
For exactly this need there is GUARDIANVIEW, our managed SIEM: built on the open-source platform Wazuh, operated in Germany, in tiers that match the organisation. No licence model that explodes with data volume, and no black box – the detection rules stay inspectable.
Attack detection stopped being the privilege of large corporations some time ago. The question is not whether somebody watches, but whether it has to be you.
As at August 2026. Dwell time per Mandiant M-Trends 2026 (published March 2026, based on 2025 data).
Read more: GUARDIANVIEW – Managed SIEM · Vulnerability Management · NIS2 for SMEs · IT forensics