Required for all clients
Security Information and Event Management (SIEM) is where security signals meet up and get sorted. Endpoints shout. Identity systems shout. Microsoft 365 logs shout. Without correlation and triage, those shouts become a pile of emails nobody finishes reading.
For Perth SMEs, the risk is not “we have no tools”. It is “we have tools that do not talk, and no one owns the night shift”. SIEM with managed detection turns scattered alerts into investigations with context: this login plus this process plus this mailbox change is one attack story, not three ignored tickets.
Stride IT requires SIEM as part of Continual Security Uplift (see /one-plan/). It sits with EDR and ITDR so response is joined-up. Details live at /security-standard/security-stack/siem/.
What SIEM is, in plain terms
A SIEM collects security events from places that matter, stores them long enough to be useful, and applies detection logic to spot patterns humans would miss when staring at one console. Then someone triages the output.
Without SIEM thinking, your world looks like separate smoke alarms in every room, all texting different people. With SIEM thinking, the alarms feed a desk that asks whether the kitchen and the hallway are on fire together.
For an SME, “SIEM” should not mean a vanity wall of charts. It should mean managed detection: ingest the right logs, detect common attack paths, escalate what matters with a sentence a director can understand, and keep a history for reviews and insurance questions.
SIEM is the glue. EDR tells you about device behaviour (see /security-standard/security-stack/edr/). ITDR tells you about account abuse (see /security-standard/security-stack/itdr/). SIEM helps connect those dots with Microsoft 365 audit signals so response is coherent.
Why Perth SMEs get hit without it
Attackers chain steps. Phish a user. Steal a session. Run a payload on a laptop. Create a mailbox rule. Move laterally to a file share. Each step may look minor in isolation. Together they are a breach.
Many local businesses buy “security packs” that email alerts to the owner or a junior tech. Alert fatigue sets in within a week. Real events hide in noise. The first clear signal is a customer complaint or a ransom note.
MSPs sometimes show a dashboard in a QBR and call it monitoring. If nobody triages after hours, and nothing correlates across products, you have reporting, not detection. Reporting is useful. It is not the same as stopping an active chain on a Sunday.
Perth firms also face supplier and customer pressure for evidence. “We take security seriously” needs logs, actions, and timelines. A SIEM-backed process gives you that trail. A folder of unread alert emails does not.
Budget fear pushes people to skip correlation. They keep one endpoint tool and hope. Hope fails quietly until it fails loudly.
What good looks like day to day
Good SIEM operations feel calm. Most alerts are auto-enriched and closed as benign with a reason. A few need human eyes. A rare few become incidents with containment steps across identity and endpoints.
You receive clear escalations: what was seen, why it matters, what was done, what you should tell staff, and what uplift follow-up is booked. No unexplained severity scores without a story.
Quarterly reviews show trends. Fewer noisy rules. Faster mean time to respond. A couple of serious events handled without drama. Directors can ask “what almost got us?” and get a real answer.
Retention is sensible. You can answer “what happened three weeks ago on that account?” without shrugging. That matters for fraud disputes and insurer questionnaires.
What bad looks like
Bad is a SIEM nobody tunes. Thousands of alerts. Zero investigations. Licences renewed because cancelling feels scary. Bad is logging everything forever with no detection content aimed at SME attack paths.
Bad is three products emailing three inboxes, each claiming to be “the SIEM”. Nobody owns priority. The loudest tool wins attention. The quiet, dangerous chain wins the network.
Bad is a pretty demo that dies after onboarding. Rules stay default. Microsoft 365 audit data never lands. Endpoint and identity streams are “phase two” forever.
If your provider cannot walk you through a correlated investigation from the last quarter, you do not have managed SIEM. You have a screensaver with a login.
How it fits with Microsoft 365 Business Premium and Defender
Business Premium and Defender produce valuable signals when audit logging, device enrolment, and identity protection are actually switched on and finished. Native Microsoft portals are excellent for admins who live in them. Most directors do not. Most small IT teams cannot staff 24/7 triage.
A managed SIEM approach uses those Microsoft signals plus endpoint and identity detections, then applies human triage. You are not replacing Business Premium. You are operating it as part of a detection system.
Common sense still rules. Patch. Limit admin rights. Train people. Test backups. SIEM will not save a business that never restores from backup. It will help you see the attack earlier so restore is a choice, not the only option.
Think of Defender and Business Premium as strong sensors and controls. Think of SIEM-backed managed detection as the process that turns sensor noise into decisions. EDR and ITDR feed that process; uplift work hardens what incidents reveal.
What directors should ask their IT provider
Ask which log sources are ingested today, not on a roadmap slide. Ask who triages after hours and what their playbook allows them to do. Ask for the last serious correlated alert and how long containment took.
Ask how false positives are reduced over time. Ask whether Microsoft 365 audit, identity risk, and endpoint alerts share one investigation workflow. Ask how findings become tickets that actually change Conditional Access, patching, or device hygiene.
Ask how SIEM evidence appears in Continual Security Uplift reviews. You want numbers and stories, not a screenshot of green charts.
If the pitch is “we will give you access to a portal”, walk away unless they also staff the portal. Directors buy response, not homework.
How SIEM ties to Continual Security Uplift
Continual Security Uplift is the operating system for finishing controls and proving improvement (see /one-plan/). SIEM is how detection work stays joined to that system. Baseline confirms sources and response readiness. Stabilise turns on the right ingest and trims noise. Continual reviews show investigations and follow-up hardening.
Without SIEM-style correlation and triage, EDR and ITDR become separate fire drills. With it, you get one narrative for the board and a cleaner Secure Score journey because incidents drive concrete control changes.
We require SIEM for every client. We will not run “endpoint only” and pretend identity and cloud signals do not matter. Full stack context sits at /security-standard/security-stack/, with this capability at /security-standard/security-stack/siem/.
SIEM done for SMEs is not a SOC fantasy with fifty analysts. It is disciplined collection, detection aimed at real attack paths, and humans who escalate with context. That is how Perth businesses turn Microsoft 365 and endpoint tools into something that works at 2am. If you want that inside a named uplift program, start with Baseline and expect us to decline if detection is treated as optional décor.
Further reading
What is SIEM? Making security alerts useful for Perth businesses
A longer owner’s guide on the same topic, written for Perth businesses comparing providers.
Read the blogWHAT YOU GET
One place where serious alerts get handled, not six products emailing the wrong person.
Response measured in hours, not “we will look when we are free”.
Audit-friendly history of detections and actions for QBRs and insurance renewals.
FREQUENTLY ASKED QUESTIONS
Is SIEM required for Stride IT clients?
Yes. Security Information and Event Management (SIEM) is required for every client under the Stride IT Security Standard. It is not an optional add-on. If you will not run it, we decline.
How does SIEM fit Our One Plan?
SIEM is part of the required detection and posture stack inside Our One Plan. It sits on top of Microsoft 365 Business Premium. We baseline it in the Baseline Review, implement it during Stabilise and Uplift, and review it in quarterly Continual reviews.
Do you sell this as a standalone product?
No. This stack runs as part of Our One Plan with Continual Security Uplift. We do not cherry-pick detection controls while leaving the rest of the Standard unfinished.
THE REST OF THE STACK
APPLY FOR BASELINE
We confirm Business Premium readiness and the full required stack, including SIEM, before we start.
Apply for Our One Plan