Are SIEM’s dead ?

Are SIEM’s dead ?

The SIEM is Dead. And We Killed It. When I first deployed a Security Information and Event Management (SIEM) system back in 2004, it felt revolutionary. Centralized log collection, correlation, and visualization promised a definitive edge in threat detection. But that was an era of limited log sources and rigid perimeters. I warned early on that unbounded data ingestion would eventually choke the system. By 2012, while consulting for a multinational logistics corporation, that nightmare became reality. I was tasked […]

Digitization – the big challenge for IT security

Digitization – the big challenge for IT security

While researching for this article, I was struck by how casually “digitization” is thrown around as a boardroom buzzword. It is treated as an abstract umbrella term for a hyper-connected society moving at breakneck speed, with almost nobody in executive leadership considering the catastrophic operational fallout. For enterprises, this digital transformation is the modern equivalent of the 19th-century Industrial Revolution. Back then, no one could accurately predict how mechanization would reshape labor, supply chains, and state power. Today, corporate leaders […]

The SOC methodology

The SOC methodology

Take a close look at the SOC workflow extract below. (I have omitted shift handovers and routine administrative tasks to focus on the core mechanics). Remember the fundamental rule: The Security Operations Center (SOC) is built for rapid triage and event processing. If an event is known or structurally simple, the SOC routes it to the responsible operational division (Networking, Server Administration, IT Security). If an event is highly complex, anomalous, or completely unknown, it is immediately escalated to the […]

The CSIRT methodology

The CSIRT methodology

If you have been following my briefings, the article on the C4ISR Methodology will resonate here. Many of those military operational procedures map perfectly onto building a highly functional SOC, CSIRT, and Digital Forensics unit—provided we adapt them correctly. Let’s explicitly define the operational elements: SOC (Security Operations Center) Standard Definition: A centralized unit dealing with organizational and technical security issues. In physical security, it monitors facility access, lighting, and alarms. In IT (often called an ISOC), it is a […]

C⁴ISR: What we can learn from the military

C⁴ISR: What we can learn from the military

C⁴ISR stands for Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance. Since 2005, I have engineered, reorganized, and optimized Security Operations Centers (SOCs) and Computer Security Incident Response Teams (CSIRTs) for critical infrastructure. This includes deployments for Saudi Telecom, Saudi Aramco, and serving as Global SOC Manager at RadarServices in Vienna, leading up to 30 analysts in a 24/7 “Follow the Sun” operation across three global time zones. What consistently surprised me was the sheer operational chaos within these units: […]

Security Issue Employees – Awareness is a must

Security Issue Employees – Awareness is a must

As detailed in my previous briefing, human awareness is often the only effective countermeasure against sophisticated attacks. Technology fails where human manipulation begins. To defend against social engineering, organizations must execute a rigorous, strategic awareness program that actually motivates employees rather than boring them to death with compliance checklists. For anyone in IT security—and specifically for executive management—I mandate reading Kevin Mitnick’s “The Art of Deception”. If you have the opportunity to attend one of his lectures, do it. I […]

How I take over your business

How I take over your business

In 1987, I drove my instructor at Comparex to absolute despair. I exploited a basic security flaw on a 3270 screen controller for terminals attached to a /370 mainframe. Back then, batch files executed with higher priority than executables. I engineered a batch script that created a ripple effect across the screen, endlessly printing: “I’m a little virus.” Every executed command subsequently copied a payload of dummy batch files across all connected terminals. It sounds like a prank—and it was—but […]

Why cyber-security is not effectively lived (in European) companies and organizations

Why cyber-security is not effectively lived (in European) companies and organizations

For years, European enterprises treated cybersecurity as an afterthought. Now, the EU has delivered a brutal wake-up call: GDPR mandates penalties of up to 4% of global revenue. That is a boardroom-level threat. I view this as a desperately needed warning shot. Every credible market analysis concludes that roughly 60% of companies are fundamentally underperforming in their cyber defense. The question is, why? Small and Medium Enterprises (SMEs): Security is treated as a zero-budget item. Elite talent is either unavailable […]

Introduction to this blog

Introduction to this blog

European enterprises are finally feeling the regulatory chokehold from the EU and German lawmakers regarding cybersecurity. And rightly so. For decades, corporate leadership ignored evolving attack vectors, resulting in the massive, unchecked hemorrhage of intellectual property, patents, and trade secrets. However, the blame does not rest solely on the board. This vulnerability is the result of systemic failure: incompetent industry consulting, legislative lag, obsolete university curricula, a severe deficit of European security vendors, a talent drought, and a catastrophic inability […]