Direct Answer
Security Information and Event Management (SIEM) is a cybersecurity system that collects and analyzes security logs from different parts of your technology environment.
Computers, firewalls, Microsoft 365, security systems, and other technology can generate thousands of log entries and events. A technician cannot realistically read through all of them looking for the few events that require attention.
SIEM reads the logs, sifts through all the noise, and alerts your IT provider to the events that need attention.
This allows suspicious activity to be identified and investigated without requiring a technician to manually review thousands of individual log entries.
Why This Matters
Your law firm's technology generates security information throughout the day.
A user logs into Microsoft 365. A firewall records network activity. A computer detects suspicious behavior. An administrator makes a change. An unsuccessful login attempt occurs.
Most of this activity is normal.
The challenge is finding the events that are not.
Important security events can be buried among thousands of routine log entries. SIEM analyzes that information and helps separate normal activity from events that may require investigation.
Without that ability to sift through the noise, an important warning sign may go unnoticed.
Editor's Insight
The problem is not a lack of security information. It is having too much information for a person to realistically review.
Your systems may already be recording the evidence that something suspicious is happening.
But if that event is buried among thousands of routine log entries, who is going to find it?
SIEM turns an overwhelming amount of security data into alerts that your IT provider can act on.
How Does SIEM Find the Security Events That Need Attention?
1. Your Technology Generates Thousands of Log Entries
Your law firm's cybersecurity does not consist of one system.
Security information may come from:
- Microsoft 365
- Firewalls
- Computers and servers
- Endpoint security
- Cloud services
- User accounts
- Other security systems
These systems continually create logs containing information about what is happening.
Those logs can be extremely valuable when identifying suspicious activity, but there is far too much information for a technician to realistically read every entry and determine which ones matter.
2. SIEM Sifts Through the Noise
This is where SIEM becomes valuable.
SIEM collects security information from multiple sources and analyzes it to identify activity that may require attention.
Instead of asking a technician to search through thousands of routine events, SIEM does the sifting.
It can identify suspicious login activity, unusual account behavior, security alerts, and other events that warrant investigation.
The objective is not to treat every event as an attack.
It is to separate the events that may matter from all the normal activity surrounding them.
3. SIEM Alerts Your IT Provider When Something Needs Attention
Finding a suspicious event is only useful if someone knows about it.
When SIEM identifies activity that requires attention, it can generate an alert so the appropriate IT or cybersecurity personnel can investigate.
Depending on what happened, the response might include changing a password, disabling an account, investigating a computer, reviewing login activity, or taking other steps to contain a potential threat.
SIEM reads the logs, finds the events that need attention, and brings them to the attention of the people who can do something about them.
4. SIEM Works With Other Cybersecurity Safeguards
SIEM does not replace MFA, EDR, firewalls, email security, or other cybersecurity protections.
It works with them.
Different safeguards perform different jobs.
MFA helps prevent someone with a stolen password from accessing an account.
EDR can detect suspicious activity on a computer and act immediately to stop or contain it.
SIEM provides broader visibility by collecting and analyzing security information from multiple systems and alerting your IT provider when activity needs investigation.
These protections are more effective when they work together as layers rather than being treated as individual products.
5. SIEM Helps Document Cybersecurity Activity
Cybersecurity is not only about implementing safeguards. Law firms may also need to demonstrate that security activity is being monitored and addressed.
SIEM creates centralized records of security events and alerts that can help document what occurred and how suspicious activity was handled.
This can be useful when investigating a cybersecurity incident and when demonstrating that the firm has an ongoing cybersecurity program.
For law firms subject to cybersecurity or cyber-insurance requirements, that documentation can be important.
A Real-World Example
A law firm client received an email that appeared to come from a colleague. The attorney opened what appeared to be a PDF and entered her Microsoft 365 username and password into a fraudulent login page.
The attacker now had her password and immediately attempted to access the account.
MFA prevented the attacker from logging in, and the SIEM system issued an alert so the password could be changed.
Two different safeguards performed two different jobs.
MFA stopped the unauthorized access. SIEM made sure the attempted access did not go unnoticed.
Two Questions We Hear
If we already have EDR, why do we need SIEM?
Both are needed because EDR and SIEM perform different functions.
EDR primarily monitors computers and endpoints for suspicious behavior and can respond immediately to malicious activity.
SIEM collects thousands of log entries from multiple systems, performing an essential task that a technician cannot do.
Does SIEM prevent cyberattacks?
SIEM is primarily designed to provide visibility, detection, and alerts rather than serve as a replacement for preventive security controls.
Its value is helping identify suspicious activity so action can be taken.
That is why SIEM should be part of a layered cybersecurity approach that also includes safeguards such as MFA, EDR, firewalls, email security, backups, and cybersecurity awareness training.
How Avenue M Helps
Avenue M Computers has provided IT and cybersecurity services to law firms in New York since 2010.
We help law firms implement and manage cybersecurity safeguards designed to work together.
SIEM collects and analyzes the large volume of security information generated by the firm's technology, sifts through the noise, and alerts us when an event requires attention.
When an alert occurs, the objective is simple: determine what happened and take the appropriate action before the situation becomes more serious.
Three Key Takeaways
- Technicians cannot realistically review thousands of security log entries looking for the few events that matter. SIEM sifts through the noise and alerts your IT provider to events that need attention.
- SIEM complements safeguards such as MFA and EDR by providing broader visibility and alerting your IT provider when activity needs investigation.
- A security control can stop an attack, but SIEM helps make sure the attempted attack does not go unnoticed.
Related Articles
- What Is Endpoint Detection and Response (EDR), and Why Do Law Firms Need It?
- Why Is Multi-Factor Authentication (MFA) Essential for Law Firms?
- What Are the Biggest IT Mistakes Law Firms Make That Can Lead to Ransomware?
- What Happens During a Cybersecurity Risk Assessment?
- What Should Every Law Firm Include in an Incident Response Plan?
- What Cybersecurity Requirements Should NY and NJ Law Firms Meet?
Technology should help your law firm practice law more securely, efficiently, and confidently, not become another distraction.


