PS ProTech(305) 699-5652
← All posts

All professional firms

SIEM and MDR, explained for a firm without a security team

· PS ProTech · 3 min read

Security tools produce alerts. The question most small firms never ask is who reads them, and what happens at 2 am on a Sunday when one matters.

SIEM and MDR are the answer to that question.

The gap they fill

Your protection generates signals all day: a blocked file, a failed sign-in, a new device on the network. Almost all of it is noise. Occasionally, three or four ordinary-looking events add up to an attack:

  • A sign-in to a partner's mailbox from another country.
  • Ten minutes later, a new rule forwarding their mail to an outside address.
  • An hour after that, a sign-in to the document system from the same place.

Each one alone could be innocent. Together they mean someone is inside. Seeing that requires two things: all the signals in one place, and a person looking at them.

What SIEM is

SIEM stands for security information and event management. It's the "all in one place" part.

It collects records from across your firm, including computers, email, cloud accounts and the firewall, and looks for patterns across them. The mailbox example above only shows up when sign-in records and email records are read together.

It also keeps those records. If something goes wrong, you can go back and establish what happened and when. That history is often what regulators, insurers and clients ask for afterward.

What MDR is

MDR stands for managed detection and response. It's the "person looking" part.

It's a team of security analysts, working in shifts around the clock, who receive the alerts from your tools. When something looks real they investigate it, and if it is real they act: cutting a computer off from the network, locking an account, and calling you.

The important word is response. A monitoring service that only emails you an alert has handed the problem back to you. MDR deals with it.

How they fit with what you already have

  • Antivirus and EDR watch each computer and stop what they can on their own.
  • SIEM connects events across computers, email and accounts.
  • MDR puts trained people on top, at all hours.

A small firm can't staff this itself. One security analyst costs more than most firms' entire IT budget, and you'd need several to cover nights and weekends. Buying it as a service is the only way it makes sense.

Do you need it?

Not every firm does. Good protection on every computer, email security and multi-factor authentication stop most attacks without anyone watching.

Monitoring earns its cost when:

  • You hold information that would be seriously damaging if taken: privileged files, financial records, health details.
  • Clients or insurers require it. Security questionnaires from larger clients now ask whether you have round-the-clock monitoring.
  • You need to prove what happened. Without records, you can't tell a client what an attacker did or didn't reach.
  • You can't afford a slow response. Attacks often start outside working hours for exactly that reason.

What to ask a provider

  • Who is watching, and when? Around the clock, or business hours?
  • What will they do without asking me? Isolating a machine at 2 am should not wait for your permission.
  • What do they cover? Computers only, or email and cloud accounts too?
  • How long are records kept?
  • What do I receive each month? A report you can show a client is part of the value.

The short version

Protection stops what it recognizes. Monitoring catches what gets through and makes sure someone acts on it. For firms with regulated or highly sensitive client data, it's the difference between an incident caught in an hour and one discovered in a month.

SIEM monitoring and MDR are included in our Secure plan, along with the reporting that supports compliance. You can price it in the plan builder.

See what it costs for your firm.

Build a plan in two minutes. No call required.