Skip to main content

5 posts tagged with "SIEM Plus"

View All Tags

From 40,000 Alerts to Fewer Than 10 Cases a Day: What Alert Fatigue Really Costs Security Teams

· 6 min read
James Yip
Managing Director

Security teams are not short on alerts. They are short on time, context, and attention.

A 2025 survey of 2,058 security leaders found that 59% receive too many alerts, while 52% described their SOCs as overworked. Security Magazine’s summary of the research also found that many teams lose investigation time because their security data is difficult to manage and disconnected across tools.

The human cost is just as clear. In the 2025 ISC2 Cybersecurity Workforce Study, 48% of respondents said they felt exhausted from trying to keep up with new threats and technologies, while 47% felt overwhelmed by their workload. ISC2’s study surveyed more than 16,000 cybersecurity professionals and decision-makers.

This is alert fatigue: the point where every notification starts to look the same, every investigation feels urgent, and analysts have to spend more energy deciding what to ignore than determining what matters.

It is not a company-specific problem. It is an operational problem affecting security teams everywhere.

AI on Top of SIEM: What SIEM AI Needs to Reduce Alert Fatigue

· 10 min read
James Yip
Managing Director

At 9:02 on Monday morning, a public-facing firewall starts recording a port scan.

By 9:05, the SIEM has generated 5,000 alerts. The IT lead opens the dashboard, sees a wall of red, and asks the question every small security team eventually asks:

“Can’t we just put AI on top of the SIEM and have it tell us what matters?”

It is a reasonable question. The right direction is, in fact, AI on top of SIEM. Your existing SIEM already collects events, applies detection rules, and stores the evidence. An AI layer can translate that output into priorities, explanations, and next actions.

That is the idea behind SIEM+, an AI security overlay for teams that want better triage and clearer security posture without replacing the SIEM they already operate.

A generic chatbot, a one-off LLM script, or a loosely connected AI copilot may produce an impressive answer to one alert. Security operations require something more durable: a system that remembers context, groups related evidence, respects data boundaries, tracks posture over time, and produces outputs people can act on and defend later.

AI security operations layer transforming noisy SIEM alerts into correlated incident cases

Why Auditors Don't Want Your Raw Logs: Building Audit Reports People Can Actually Read

· 6 min read
James Yip
Managing Director

Every audit season, the same scene plays out. A security team exports a mountain of raw logs, a spreadsheet of alert counts, and a screenshot of a dashboard covered in red and yellow blocks. They hand it to the auditor and hope for the best.

The auditor doesn't want any of that. They want one question answered clearly: "Can you prove this control is working, and show me the evidence?" If the answer takes twenty minutes of dashboard-squinting to extract, you've already failed the real test — not of your security posture, but of your ability to communicate it.

This is the problem we built the SIEM+ (siem.plus) Auditor View to solve. Not "more visibility." Comprehensible visibility — audit-ready by default, not audit-ready after a week of manual report building.

SIEM+ audit report turning raw alert noise into a board- and auditor-ready evidence pack

Why Static Dashboards Are Dead: Engineering the Dynamic Posture Score in SIEM+

· 4 min read
James Yip
Managing Director

In the cybersecurity industry, we have a terrible habit of equating “volume” with “risk.” If a traditional SIEM dashboard shows 10,000 alerts, the status indicator turns red, the posture score plummets to zero, and executives panic.

But as any Tier-1 SOC analyst knows, a simple automated port scan against a public-facing IP can generate 5,000 raw firewall drops in three minutes. That isn’t 5,000 separate critical threats; it is a single, low-level event.

When we built SIEM+ (siem.plus), we knew that if we just fed raw alert counts into a UI, we would be recreating the exact same “alert fatigue” we set out to destroy. We needed a way to translate noisy data lakes into a boardroom-ready metric that reflects actual risk.

Here is a deep dive into how we engineered the SIEM+ Dynamic Posture Score, our penalty decay algorithm, and how we force LLMs to map threats to compliance frameworks without hallucinating.

SIEM+ Dynamic Posture Score visualizing grouped cases and actionable risk

SIEM+ Managed SIEM: Cloud-Native Devo Security Monitoring | Eventus

· 6 min read
James Yip
Managing Director

For IT Directors, CISOs, and Security Operations Managers, the challenge is no longer whether the organization has enough security tools. The real challenge is whether a lean team can turn thousands of daily signals into the few decisions that truly matter.

Modern environments generate alerts from firewalls, endpoints, identity platforms, Microsoft 365, cloud workloads, SaaS applications, and network infrastructure. Many of those alerts are low-fidelity. Some are duplicates. Some are known false positives. A small number may indicate real business risk.

This is where SIEM Plus from Eventus comes in. SIEM Plus combines Devo's cloud-native SIEM with Eventus managed services, AI-enhanced noise reduction, and actionable ITSM workflows to help teams conquer alert fatigue without building a large internal SOC from scratch.