Wall Street & Technology is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security

09:17 AM
Gaby Friedlander
Gaby Friedlander
Commentary
50%
50%

The #1 Myth about Security Information and Event Management (SIEM)

Probably the most popular myth deceiving IT security professionals today is that Security Information and Event Management (SIEM) software is a sufficiently-robust solution for keeping a close eye on sensitive data and – and to send alerts when anything suspicious happens to it. However, SIEMs can only report on logs they can see - therefore another type of user activity monitoring software is needed to ensure data remains secure.

Probably the most popular myth deceiving IT security professionals today is that Security Information and Event Management (SIEM) software is a sufficiently-robust solution for keeping a close eye on sensitive data and – and to send alerts when anything suspicious happens to it.

SIEMs do improve a company's ability to tighten security, since they can report on relevant logs that may lead to a data breach. However, there are major gaps in the data at their disposal. These gaping holes are perfect targets for someone to quickly and quietly penetrate a system or file that should be off-limits.

The reason for this serious vulnerability is due to the fact that SIEMs are limited and can only report on logs that they are able to read. In other words, SIEMs cannot see activity in all applications and system areas, meaning that they cannot see everything that happens on a server. The result is that many unauthorized server activities will never be reported or altered by any SIEM.

If you're one of those who thinks your stand-alone SIEM is doing its job of IT security for you, be aware that you could have just been breached and you don't even know it! Maybe if you're in the lucky 8% that do discover that your data has been breached, you will have only have a 66% chance of discovering as soon as months later. By then, who knows what havoc has already been wreaked?!

Luckily, there are a few solutions out there that can help protect those soft exposed underbellies. These user activity monitoring solutions are a MUST for any organization that has to protect sensitive data and/or comply with standards. Some of them can be easily integrated with SIEMs in order to completely eliminate user activity blind spots by video and easy-to-read text logs and every user action, in every application and system area (including hidden and underlying commands) and provides this data directly to the SIEM.

More Commentary
A Wild Ride Comes to an End
Covering the financial services technology space for the past 15 years has been a thrilling ride with many ups as downs.
The End of an Era: Farewell to an Icon
After more than two decades of writing for Wall Street & Technology, I am leaving the media brand. It's time to reflect on our mutual history and the road ahead.
Beyond Bitcoin: Why Counterparty Has Won Support From Overstock's Chairman
The combined excitement over the currency and the Blockchain has kept the market capitalization above $4 billion for more than a year. This has attracted both imitators and innovators.
Asset Managers Set Sights on Defragmenting Back-Office Data
Defragmenting back-office data and technology will be a top focus for asset managers in 2015.
4 Mobile Security Predictions for 2015
As we look ahead, mobility is the perfect breeding ground for attacks in 2015.
Register for Wall Street & Technology Newsletters
Video