Under attack?
Detection engineering

SIEM platform expertise
and deployment

We are vendor-independent. The right SIEM is the one your teams can actually operate, the one your budget can carry over time, and the one that genuinely covers your perimeter — not the one at the top of the latest quadrant.

  • Splunk
  • Microsoft Sentinel
  • Elastic Security
  • OpenText ArcSight
  • Wazuh
  • SOAR & UEBA
Four kinds of engagement

Depending on the state of your platform

Acquisition and deployment

You are starting from a blank page. We run the sizing study, compare solutions against your real criteria — data volume, in-house skills, sovereignty constraints, total cost of ownership — then deploy the platform you choose.

Scoping · sizing · architecture · deployment · source onboarding · acceptance

Migration

You are changing vendor, or moving from an on-premise to a cloud model. We handle the porting of use cases, the preservation of history and the continuity of detection throughout the switchover.

Inventory of the existing estate · rule porting · dual run · cutover · decommissioning

Platform recovery

Your SIEM is in place but produces no value: too many false positives, missing sources, licences under-used or saturated. We establish a diagnosis and then a prioritised remediation plan.

Audit · configuration debt · licence cost optimisation · remediation plan

Compliance advice

Your platform has to meet a specific framework. We build the compliance matrix, identify the gaps and drive their resolution through to auditable evidence.

PCI-DSS · ISO/IEC 27001 · NIST CSF

Our method

How an engagement runs

The same sequence, whichever vendor is chosen and whatever the scale of the project.

1

Scoping

A free workshop: perimeter, assets to cover, detection objectives and technical constraints.

2

Design

Architecture, sizing, log source matrix and use case catalogue.

3

Deployment

Installation, source onboarding, normalisation and go-live.

4

Supported run

Support after go-live: rule tuning, response procedures, skills build-up.

5

Operations

Managed operation or a maintenance contract, with indicators and periodic review.

Platforms

Our technology coverage

We work equally with proprietary solutions and the open source stack, and we will say when one is a better fit than the other.

PlatformPositioningWhere we recommend it
Splunk Enterprise & Enterprise SecurityMarket reference, very rich functionallyLarge volumes, demanding analytics, a broad app ecosystem, a well-equipped in-house team
Splunk SOARResponse orchestration and automationResponse processes already formalised that you want to industrialise
Microsoft SentinelCloud-native SIEM, consumption-based billingOrganisations already invested in Microsoft 365 and Azure; choice of data region
Elastic SecurityExcellent cost-to-volume ratio, open foundationHigh log volume with budget constraints, an appetite for open source
OpenText ArcSightProven correlation heritage, SOAR and UEBAExisting estates to maintain or evolve, strong traceability requirements
WazuhOpen source foundation, no licence costConstrained budget, strong sovereignty requirement, a wish to control the whole chain
How a deployment unfolds

Six stages, a deliverable at each one

Each stage ends with a document you keep. You always know where the project stands and what has been decided.

1

Scoping

Design dossier and sizing study: volumes, retention, target architecture, running budget.

2

Platform

Detailed technical architecture, installation and commissioning of the components.

3

Onboarding

Source matrix, onboarding plan, agent deployment and data normalisation.

4

Detection

Use case catalogue and coverage tracking by MITRE ATT&CK technique.

5

Operations

Procedures for log management, updates and tier 1 incident response.

6

Handover

Training plan, skills transfer sessions, then a move to a maintenance contract if you wish.

The supported run, often overlooked

A SIEM that has been delivered is not a SIEM that has been adopted. We plan for support after go-live: refining rules against real traffic, backing you through the first incidents, building your analysts’ autonomy. That is where the project is won or lost.

Support for integrators

Technical expertise as a subcontractor

We work alongside integrators and IT departments that need to produce a credible technical proposal on a detection platform project without holding the corresponding SIEM skills in house.

We bring the technical rationale, the target architecture and the effort estimate. We can then stay engaged for delivery, in a consortium or as a subcontractor.

Tell us what you need

What we bring

  • Technical rationale for the chosen solution
  • Target architecture diagram and sizing
  • Delivery schedule and effort estimate
  • Description of deliverables and method
  • Profiles and skills that can be mobilised
  • Structure for the cost estimate

A SIEM project to scope?

Whether you are starting from scratch, migrating, or trying to recover an existing platform, the scoping workshop sets out the diagnosis and the realistic options.