Visibility + Expertise
Why the strongest security strategy combines SIEM and MDR.
Organizations looking to improve cybersecurity may face a choice between implementing a Security Information and Event Management (SIEM) solution or relying on a standalone Managed Detection and Response (MDR) service. While MDR can provide valuable threat detection and access to security expertise, a SIEM provides something just as important: visibility across the entire technology environment. Rather than viewing a SIEM and MDR as competing solutions, it should be recognized that a SIEM provides the foundation for security monitoring, while MDR can provide the people and expertise needed to monitor and respond to threats around the clock.

One of the greatest advantages of a SIEM is its ability to collect and correlate information from many different systems. A SIEM can ingest logs from firewalls, servers, endpoints, Microsoft 365, cloud services, authentication systems, applications, and other network and security devices. A standalone MDR solution may primarily focus on the technologies supported by the MDR provider, such as endpoint, identity, email, or network security products. This can leave gaps in visibility. With a SIEM, an organization can bring these different sources together and identify activity that may appear harmless within one system, but becomes suspicious when correlated with activity elsewhere.
A SIEM also provides greater flexibility and control over security information. Organizations can add new log sources, create detection rules for risks specific to their environment, retain historical security information, and investigate events that may have occurred months earlier. This historical information can be especially important during incident investigations, when organizations often discover that an attacker was present long before the initial compromise was detected. Centralized logging can also support audit, regulatory, and compliance requirements by providing a consistent repository of security events rather than distributing that information across multiple security products and service providers.
None of this means that organizations should abandon MDR though. A SIEM provides great visibility, but someone still needs to monitor and interpret the information it generates. This is where MDR can provide significant value. An MDR provider can supply 24×7 monitoring, experienced security analysts, threat hunting, investigation, and incident response capabilities that many organizations cannot reasonably maintain internally. When an MDR service can leverage information collected by the SIEM, its analysts gain a much broader picture of what is happening across the organization instead of investigating alerts from a limited number of security tools.
At the end of the day, the strongest approach is not SIEM versus MDR, it is SIEM plus MDR. A fully managed SOC that includes both a SIEM and MDR creates a more complete security program and gives organizations a better opportunity to detect threats whenever and wherever they occur.
Original article by Adam Reynolds, CISSP. Information Security Officer, infotex
Read all of Adam’s articles here!