SIEM and Security Tool Assessment

Does your SIEM detect attacks — or just collect expensive logs?

We assess how effective your SIEM and adjacent security tools are in your environment: more than 100 criteria across ten domains, drawn from a questionnaire, workshops with your team and read access to the running system. You get a vendor-neutral maturity rating, your largest gaps and a clear picture of what actually protects you.

Vendor-neutral. We do not sell SIEM. Built from real assessments and 15+ years of security practice.
GrayCheck · Assess · Maturity report
52%Reifegrad
1.55 / 3.00Overall maturity across 10 domains
Detection
low
Resilience
critical
Architecture
mature
Coverage
medium
Illustrative example · fictitious values · no customer data

Why it matters

A SIEM rarely fails on features — it fails on the gaps before and after it.

Gaps stay invisibleData, architecture, processes and operations decide whether detection works. Where it breaks usually only shows in a real incident.
Self-assessment does not reveal itAnyone assessing their own system is assessing their own work. Only read access to the running system shows what actually arrives.
Evidence needs proofNIS2, ISO/IEC 27001 and BSI IT-Grundschutz require demonstrable detection capability — a self-assessment is not enough.

How we assess

Three sources — only together a reliable picture.

SOURCE 1

Structured questionnaire

Architecture, log sources, rule set, processes and operations — answered by your team.

SOURCE 2

Workshops

Deepening open points, sense-checking the answers, capturing processes and responsibilities — with your security or IT team, and with your SOC or service provider if you wish.

SOURCE 3

Read access to the running system

Read-only, via a read role or screen sharing: data onboarding, rule set, alerting and operations. No configuration changes.

Sequence: kick-off → questionnaire → workshops → system review → analysis → result report and closing session. Typically six to nine working days from kick-off.

The assessment is vendor-neutral: Graydaxe does not sell SIEM or security tools. What we assess is the effect of the system you run, in your environment — independent of the product.


Ten domains

From the log source to resilience.

We assess ten domains with more than 100 criteria — from how log sources are connected, through architecture and rule set, to alerting and the question of whether operations survive an outage. The criteria are weighted by risk and produce a maturity rating per domain on a single scale.

In addition we place your detection coverage against known attack techniques — aligned with MITRE ATT&CK:

Initial Access
Execution
Persistence
Privilege Escalation
Lateral Movement
Exfiltration
Impact
coveredpartialgap
Illustrative example · no customer data

What you get

A report that answers the question — and names the next steps.

  • An overall maturity rating and a rating per domain on a single scale
  • Your largest gaps, prioritised by risk
  • Your detection coverage placed against known attack techniques
  • References to NIS2, ISO/IEC 27001 and BSI IT-Grundschutz
  • Concrete next steps and a closing session with your team

Not part of the assessment: Configuration changes to the SIEM or connected systems · development or tuning of detection rules · operations, monitoring or alert handling · simulated attacks, penetration tests or red team exercises


Three modes

Assess, compare, migrate.

ModeContentResult
AssessA maturity assessment of one SIEM or security tool in your own environmentMaturity per domain, prioritised gaps, NIS2 references, concrete first steps
CompareA weighted comparison of two SIEM systems against the same criteria, including a cost view across licensing, staff and third-party solutionsAn overview of strengths and weaknesses with a reasoned recommendation as a basis for the decision
MigrateA guided path to a target system: mapping of log sources and detection rules, risk and gap analysis, phased planTarget architecture, a roadmap with effort estimates, support through the critical steps

Assess is delivered as a self-contained engagement. Compare and Migrate are offered separately.


And afterwards?

Findings become an architecture.

Anyone rebuilding, migrating or starting over after the assessment needs more than a list of gaps. Our consultants support target architecture, migration and compliance — on the same set of facts the report delivers.

To consulting & architecture →

FAQ

Frequently asked questions

Does the assessment intervene in our SIEM?

No. Access is read-only, via a read role or screen sharing. We change no configuration, develop no rules and take over no operations.

Which systems can you assess?

Any SIEM, regardless of vendor, plus adjacent security tools such as XDR and vulnerability scanners.

What do we need to contribute?

Your security or IT team answering the questionnaire, taking part in the workshops, and read access to the running system. We define the scope together in the kick-off.

Is this a penetration test or a vendor health check?

Neither. A health check tests configuration against the vendor's guidance; a penetration test proves exploitability. We judge how effective your system is in your environment — vendor-neutral and without intervening.

What does the assessment cost?

The scope depends on the system assessed and the tools included. We provide the pricing and billing model on request.


Let us talk about your setup.

Tell us which SIEM you run and which tools belong to it. In the kick-off we define the goal and the scope together.