forumNew topic

Vendors are trying to sell us a SIEM service — do we really need it at our size, and what does it actually do?

MMehmet C***Member
Job title
Store associate
Sector
Electrical-electronics
Organization type
120-person company
Joined
May 2025
Message
263
#1

We run an auto parts wholesale business in Bursa. We have 35 office staff, two accounting and ERP servers at headquarters, and a remote warehouse. Last week, our IT infrastructure provider ran a cybersecurity audit and told us that getting a SIEM service is an absolute must.

The quote they gave us is 45,000 TL for initial setup, followed by a monthly operational and monitoring (SOC) fee of 22,000 TL. Their reasoning was: "Your logs aren't monitored in real time, you're at risk regarding KVKK, and if an intruder gets in, you wouldn't notice for months."

What exactly is this SIEM service anyway? How is it different from standard firewalls or log collection tools? For an SME like us with no more than 40 PCs in total, is this system truly critical, or are they just trying to push an enterprise-grade solution onto us?

VVeli K***Member
Job title
Warehouse Manager
Sector
Logistics
Organization type
sole proprietorship
Joined
Jun 2022
Message
204
Most Helpful#2

Short answer: A SIEM service is a security setup that pulls log data from your network's firewalls, servers, user workstations, and applications into a single pool, cross-referencing events to spot suspicious behavior in real time. At your size, a package with 24/7 monitoring is usually overkill cost-wise and gets in the way of more pressing security basics.

The main difference between standard log management and SIEM is intelligence. Log management simply archives events in a safe; for instance, a user connecting via VPN in the middle of the night might look normal on its own, and bulk-downloading files from a server might look normal on its own too. SIEM correlates these two separate logs: it says, "This user never connects at night, and two minutes after logging in, they downloaded an accounting folder they don't have access to," and fires an alert.

However, a SIEM isn't something you can just set up and forget. For it to work properly, you need ongoing rule-tuning, false-positive filtering, and actual staff to investigate triggered alerts. That monthly 22,000 TL in the quote is there specifically to cover those monitoring hours.

As a 35-person distributor, SIEM shouldn't be your top priority. Before dropping that kind of cash, rolling out centralized endpoint protection, enforcing 2FA across your servers, and keeping regular, air-gapped backups will protect you far better. Unless you have direct banking integrations or strict regulatory mandates, securely archiving your existing firewall logs to a central server is plenty.

VVildan A***Member
Job title
Information Security Specialist
Sector
Agriculture
Organization type
two-branch business
Joined
Jul 2023
Message
114
#3

The vendor claiming "SIEM is mandatory for KVKK" is flat-out false. The law requires you to take reasonable technical measures to secure personal data and maintain an audit trail for retrospective review, but it never mentions SIEM software by name. If you can store basic access logs with valid timestamps, you're already meeting the minimum legal baseline. They're just selling fear to close a deal.

OOnur A***ExpertCommunity member
Joined
Nov 2025
Message
64
#4

We're an architecture firm with 55 employees. Two years ago, spooked by similar talk, we signed up for one of these services at 18,000 TL a month. For six months, all they did was send us standard weekly PDF reports. When we dug in, the system was churning out three hundred false alarms a week, none of which were actual threats. Once the contract ended, we cancelled, upgraded our endpoint licenses instead, and cut our costs to a third.

AAli T***Member
Job title
Call center representative
Sector
Paper
Organization type
workshop
Joined
Jul 2024
Message
269
#5

A SIEM engine is only as good as its correlation. You have to feed it Active Directory events, switch traffic, and firewall logs. In an office with 40 PCs, how many meaningful security events are you realistically generating in a day? Most alerts will just be "Ahmet mistyped his password three times." Paying an external vendor thousands of liras every month just to watch that makes zero sense.

İİbrahim T***New member
Job title
Graphic Designer
Sector
Energy
Organization type
chain store
Joined
Jun 2026
Message
90
#6

they told our boss the exact same story and then a ransomware hit our office server anyway. simply because someone in accounting opened a fake invoice attachment and we didnt even have 2fa enabled. they told us if we had siem wed just get to watch the virus spread in real time lol. fix your basic weak spots first imo.

RRıdvan A***Veteran
Job title
Software developer
Sector
Leather
Organization type
two-branch business
Joined
Jan 2024
Message
12
#7

Do you have clients like major auto manufacturers or international partners that run mandatory audits on you? Sometimes tier-1 industrials contractually require their suppliers to maintain specific security certifications or real-time monitoring. If you're not under that kind of external compliance pressure this offer looks way too lavish for your setup.

NNuri K***Expert
Job title
Graphic Designer
Sector
Jewelry
Organization type
cooperative
Joined
Jan 2025
Message
222
#8

Before locking that money into a SIEM service, check off these three items: 1) Do your accounting and ERP servers have any ports directly exposed to the internet? 2) Are your backups kept in an environment physically isolated from the network? 3) Is centrally managed, licensed endpoint protection running on every single machine? If not, a SIEM will just let you watch the building burn.

AAycan Ş***ExpertCommunity member
Joined
Apr 2026
Message
259
#9

Politely decline the proposal and just bump up the log storage capacity on your current firewall. Hook up an external storage unit, point the logs there, and verify your daily backups—that's more than enough. Instead of paying 22,000 TL a month, put that budget toward your IT staff or upgrading your hardware infrastructure.

İİbrahim T***Member
Job title
Marketing director
Sector
Advertising and promotion
Organization type
medium-sized business
Joined
Nov 2023
Message
125

Doki · Backup setup · 2023

#10

At a logistics company I used to work for, management jumped on this with the same enthusiasm. Within the first month, the flood of alerts forced the IT team to mute all notifications. By the fourth month, with alerts muted, we didn't even notice a server getting encrypted. It's not about the software; it's about the caliber of the analyst watching the console, and an SME budget unfortunately won't buy you that tier of expertise.

note: I wrote this based on my own experience, it might not apply to everyone.

ZZafer P***MemberCommunity member
Joined
Dec 2024
Message
411
#11

There is something to watch out for. When making a decision, first look at what data you have on hand.

Correct me if I'm wrong.

OOrhan T***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Mar 2023
Message
348

Doki · E-commerce infrastructure · 2023

#12

The most overlooked point about what is a SIEM service is this: Don't rely on a single measure; go layer by layer.

Good luck with that.

HHilal Y***Member
Job title
Information Security Specialist
Sector
Advertising and promotion
Organization type
sole proprietorship
Joined
Sep 2022
Message
419

Doki · Backup setup · 2023

#13

I'll try it. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

That's all, sorry if I went on too long.

NNecati E***MemberCommunity member
Joined
Jan 2024
Message
3
#14

Let me share what happened to me; it might be useful. If you scold false alarms, nobody will report again.

When making decisions, write down the worst-case scenario too, not just the best. If I were you, I'd go this route.

FFatih E***Member
Job title
Operations manager
Sector
Consulting
Organization type
medium-sized business
Joined
May 2023
Message
26
#15

I agree.

VVahide K***Member
Job title
Content Editor
Sector
Advertising and promotion
Organization type
workshop
Joined
Apr 2023
Message
148
#16

I agree with this. If it's your first time, start small; scaling comes later.

NNecati B***Member
Job title
Intern
Sector
Cleaning services
Organization type
8-person team
Joined
Sep 2024
Message
44
#17

I think differently. Taking notes for two weeks yields better results than a six-month estimate.

If 2FA is on, a stolen password alone is useless. That's all, sorry if I went on too long.

VVolkan Ö***Expert
Job title
Intern
Sector
E-commerce
Organization type
early-stage startup
Joined
Oct 2022
Message
51
#18

We got stuck at the same point for a while. If you get three different answers on a topic, the question was asked wrong.

Hope this helps.

EErcan Ç***Member
Job title
Graphic Designer
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Aug 2023
Message
57
#19

I agree with this... If you scold false alarms, nobody will report again.

AAycan Ö***MemberCommunity member
Joined
Jul 2023
Message
321
#20

I'll argue the opposite, don't get mad. If permission and scope aren't in writing, don't start that test.

The biggest time-waster for us was not knowing who had the final say. That's all, sorry if I went on too long.

Reply