When every tool yells and nobody hears
A director showed us an inbox folder named “Security”. Two thousand unread messages. Endpoint alerts. Identity alerts. Sign-in reports. Backup warnings mixed in for flavour. Somewhere in that pile was a real attack chain. Nobody had time to find it.
That is the problem SIEM thinking solves for small and mid-sized firms. Not more noise. Better joining of signals, with humans who escalate the few that matter. Our required-stack page on SIEM is at /security-standard/security-stack/siem/. Read that for the program framing. Read this for the owner’s angle: how multi-step attacks hide, and how Continual Security Uplift keeps detection honest (see /one-plan/).
If your stomach dropped reading “two thousand unread”, you are not alone. Alert piles are a common Perth SME pattern. They feel like diligence. They behave like avoidance.
SIEM without the textbook fog
Security Information and Event Management means collecting security events, storing them, detecting patterns, and supporting investigation. In an SME, the useful version is managed detection with correlation, not a hobby lab of charts.
Example: a risky sign-in at 1am, a new mailbox rule at 1:10, and a suspicious process on a laptop at 1:25. Three separate tools might rate each event “medium”. Together they are a takeover in progress. SIEM-style detection is what makes “together” visible.
If your provider cannot show a correlated investigation, you may have logging. You do not yet have SIEM as an operating practice.
Forget the fantasy of a wall of screens. For a business your size, success looks like a short call that says what was joined up, what was done, and what will be hardened next. That is SIEM earning its keep.
Retention matters too. If logs vanish after a few days, fraud disputes and insurer questions get harder. Keep enough history to answer “what happened three weeks ago?” without a shrug.
Why quiet chains hurt Perth SMEs
Ransomware is loud at the end. The beginning is quiet. Credential use. Reconnaissance in email. A tool downloaded “for IT support”. A second account created. Lateral movement. Each step can look like a minor ticket.
Professional services, healthcare-adjacent practices, construction offices, and retailers across Greater Perth all run on Microsoft 365. Attackers know the default patterns. They do not need a custom exploit if alert fatigue does the work for them.
Insurance and customer questionnaires increasingly ask how you monitor and respond. “We get emails from our antivirus” is a weak reply. A SIEM-backed process with triage notes is stronger, and it is kinder to your future self during an incident.
Quiet chains also hurt reputation. A client who receives a fake invoice from your domain remembers the embarrassment longer than they remember your explanation about tooling.
A day in the life of useful triage
Morning: overnight alerts are enriched automatically. Benign patterns close with a reason. Two items need a human. One is a staff member on holiday. One is a privilege change that was not booked.
Afternoon: the privilege change is reversed, the admin workflow is tightened, and a note lands in the uplift backlog so the same path is harder next month.
Night: a correlated identity-plus-endpoint event triggers containment. You wake to a clear summary, not a scavenger hunt across portals.
That rhythm is what you are buying. Not a dashboard password. Not a monthly PDF of raw counts with no decisions attached.
What good managed detection feels like
You are not asked to live in consoles. You get occasional, clear escalations. Most noise never reaches you. Serious events come with actions already started: isolate, revoke, reset, preserve evidence.
Quarterly, you see trends and follow-ups. Detection rules got quieter. A Conditional Access gap found during an incident was closed. An old server finally entered the refresh plan because it could not produce trustworthy telemetry.
That loop is the point. Detection without uplift is whack-a-mole. Uplift without detection is paperwork.
Directors should be able to answer, in one minute, how monitoring works. If they cannot, the operating story is still inside the MSP’s head. Pull it out into reviews you can keep.
Microsoft 365 is a source, not a babysitter
Business Premium and Defender generate rich audit and alert data when configured. Native portals are powerful for engineers. They are not a 24/7 triage desk for a ten-person company.
A sensible model keeps Microsoft as the platform, finishes the controls, and feeds key signals into managed detection. EDR and ITDR remain essential inputs (see /security-standard/security-stack/edr/ and /security-standard/security-stack/itdr/). SIEM is how those inputs become one investigation culture.
Do not skip basics because you bought correlation. Patch. Train people. Test restores. Defence in depth is dull and effective.
Also finish the boring Microsoft work: audit logging on, devices enrolled, legacy auth off where possible. A SIEM cannot correlate data you never collected.
Questions that separate theatre from triage
Which log sources are live today? Who triages at 2am? What can they do without waiting for email approval? How are false positives reduced over time? Where do investigation notes reappear in your uplift plan?
Ask for one real correlated case from the last quarter. Listen for specifics: times, actions, follow-ups. Marketing adjectives are not specifics.
If the pitch is portal access for your office manager, be honest about whether that person will ever become a night analyst. Most will not. Design for that truth.
Write the answers down. Bring them to the next QBR. Providers who hate that habit are telling you something useful.
Put SIEM inside a program you can audit
Ask providers which sources are live, who triages after hours, and how findings enter your improvement plan. Then compare their answers to our SIEM stack page at /security-standard/security-stack/siem/.
At Stride IT, SIEM is required under Continual Security Uplift because we refuse to run disconnected alarms and call it security (see /one-plan/). Baseline checks readiness. Ongoing reviews check that investigations still turn into hardened controls.
If your current folder of unread security mail feels familiar, you do not need another forward rule. You need correlation, triage, and a partner who will decline work that leaves detection optional. Start there, and keep the SIEM page handy when you judge the answers you hear.
More alerts will not save you. Better joined-up response might. Put SIEM with EDR and ITDR on the required floor, run Continual Security Uplift so Secure Score and detection both move, and give Monday a quieter reputation.
Want the required-stack definition we run with clients? Read /security-standard/security-stack/siem/ and the Our One Plan.
