We assess how effective your SIEM and adjacent security tools are in your environment: more than 100 criteria across ten domains, drawn from a questionnaire, workshops with your team and read access to the running system. You get a vendor-neutral maturity rating, your largest gaps and a clear picture of what actually protects you.
Architecture, log sources, rule set, processes and operations — answered by your team.
Deepening open points, sense-checking the answers, capturing processes and responsibilities — with your security or IT team, and with your SOC or service provider if you wish.
Read-only, via a read role or screen sharing: data onboarding, rule set, alerting and operations. No configuration changes.
The assessment is vendor-neutral: Graydaxe does not sell SIEM or security tools. What we assess is the effect of the system you run, in your environment — independent of the product.
We assess ten domains with more than 100 criteria — from how log sources are connected, through architecture and rule set, to alerting and the question of whether operations survive an outage. The criteria are weighted by risk and produce a maturity rating per domain on a single scale.
In addition we place your detection coverage against known attack techniques — aligned with MITRE ATT&CK:
Not part of the assessment: Configuration changes to the SIEM or connected systems · development or tuning of detection rules · operations, monitoring or alert handling · simulated attacks, penetration tests or red team exercises
| Mode | Content | Result |
|---|---|---|
| Assess | A maturity assessment of one SIEM or security tool in your own environment | Maturity per domain, prioritised gaps, NIS2 references, concrete first steps |
| Compare | A weighted comparison of two SIEM systems against the same criteria, including a cost view across licensing, staff and third-party solutions | An overview of strengths and weaknesses with a reasoned recommendation as a basis for the decision |
| Migrate | A guided path to a target system: mapping of log sources and detection rules, risk and gap analysis, phased plan | Target architecture, a roadmap with effort estimates, support through the critical steps |
Assess is delivered as a self-contained engagement. Compare and Migrate are offered separately.
Anyone rebuilding, migrating or starting over after the assessment needs more than a list of gaps. Our consultants support target architecture, migration and compliance — on the same set of facts the report delivers.
No. Access is read-only, via a read role or screen sharing. We change no configuration, develop no rules and take over no operations.
Any SIEM, regardless of vendor, plus adjacent security tools such as XDR and vulnerability scanners.
Your security or IT team answering the questionnaire, taking part in the workshops, and read access to the running system. We define the scope together in the kick-off.
Neither. A health check tests configuration against the vendor's guidance; a penetration test proves exploitability. We judge how effective your system is in your environment — vendor-neutral and without intervening.
The scope depends on the system assessed and the tools included. We provide the pricing and billing model on request.
Tell us which SIEM you run and which tools belong to it. In the kick-off we define the goal and the scope together.
Tell us briefly what it’s about – we’ll get back to you within 1–2 business days.