Three-quarters of cybersecurity professionals have reported that Security Information and Event Management (SIEM) reduces security breaches. This is according to an Alien Vault and Cybersecurity Insiders report, which surveyed 417 users.

em360tech image

SIEM Benefits

First and foremost, respondents identified the main benefits that they derive from their SIEM platforms. 23 per cent of respondents said that it allowed them to provide faster detection and response to security events. 14 per cent indicated that their SIEM platform enabled more efficient security operations, while 12 per cent reported better visibility into threats. Meanwhile, 8 per cent of respondents said it enabled better threat analysis, compliance posture, and prioritisation of indicators of compromise (IOC).

SIEM Use Cases

Overall, respondents cited monitoring, correlation, and analysis across multiple systems as the most important use case for SIEM. 68 per cent did so, but 62 per cent said that SIEM's ability to aid with the discovery of external and internal threats was the most significant. 51 per cent indicated that it was monitoring the activities of users, while the same number of people said monitoring server and database access was the most important. However, 38 per cent of users said that the platform was the most useful in providing compliance reporting.

SIEM is Reducing Breaches

An overwhelming majority (76 per cent) confirmed that their SIEM platform improved their ability to detect threats. Furthermore, these respondents also indicated that their use of SIEM had catalysed a "measurable reduction of security breaches" in their organisation. In terms of the individual percentages, 30 per cent said that it had reduced a significant amount of breaches. An additional 46 per cent said they saw some reduction in breaches, while 25 per cent reported no improvement.

However, 28 per cent stated that their ability to detect threats had improved greatly. 47 per cent said it had improved, 21 per cent declared nothing had changed, and 4 per cent indicated that their capabilities had worsened. Despite this, 46 per cent of respondents reported that their SIEM platform was the most effective at detecting unauthorised access. 42 per cent also said that it detected advanced persistent threats, while 37 per cent stated it had identified insider attacks. Respondents also said it had helped identify malware (35 per cent) and web application attacks (34 per cent). Hijacking of resources and denial of service attacks had the lowest detection rates at 29 per cent.