Newsletter Issue #14
Changing Your SIEM Shouldn’t Impact The Continuity Of Your Evidence.
Own the collection layer. Control the cost. Keep your options open.
Cybersecurity architecture is entering another period of change.
Security teams are consolidating platforms. Legacy SIEMs are being reconsidered. AI-native security platforms are emerging, Databricks launched Lakewatch, an open security Lakehouse SIEM, in March 2026, and it will not be the last. Cloud security architectures continue to expand. Data volumes are increasing. And organisations are being asked to demonstrate better security outcomes while controlling the cost and complexity of the technology stack.
IDC’s December 2025 survey found 84% of respondents agreed or strongly agreed that their organisation is prioritising security platformisation. At the same time, concern about dependency remains one of the barriers preventing organisations from consolidating as aggressively as they might otherwise choose.
There is a reason for that tension.
Consolidation can simplify security operations.
Dependency can restrict them.
Nowhere is that distinction more important than in logging.
Many organisations understandably think about log collection, storage, analytics and investigation as parts of their SIEM deployment.
But they do not have to be all linked.
Your SIEM is where you analyse security data. It does not have to own how that data is collected.
And if you decide to replace your SIEM, you should not automatically have to replace thousands of agents, reconstruct every forwarding rule, redesign your retention strategy or rebuild the security-data pipeline from the endpoint upwards.
Changing your SIEM should be a routing decision, not an endpoint project.
That distinction is becoming more important as both attacks and security data continue to accelerate.
Verizon’s 2026 DBIR, its 19th edition, covering more than 22,000 confirmed breaches across 145 countries, found that vulnerability exploitation now accounts for 31% of breaches, overtaking credential abuse (13%) as the leading initial access vector for the first time in the report’s history. Third-party involvement rose to 48% of breaches, a 60% year-on-year increase. Ransomware appeared in 48%. And only 26% of CISA Known Exploited Vulnerabilities were fully remediated during the period, down from 38%.
CrowdStrike’s 2026 Threat Hunting Report found that 88% of observed exploitation involving a published proof of concept occurred within 48 hours of release during the first half of 2026. Vishing intrusions doubled over the same period, and monthly device-code phishing attempts rose fifteenfold.
IBM, meanwhile, puts the global average cost of a data breach at a record US$4.99 million, up 12%, with AI-driven attacks up 56%, and mean time to identify and contain back up to 247 days, reversing five consecutive years of improvement.
| THE NUMBER THAT SHOULD SHAPE YOUR ARCHITECTURE
A 43-day median time to remediate a known-exploited vulnerability, against a 48-hour median time to exploitation, is not a patching gap you can close by patching faster. It is a gap that has to be covered by detection and by evidence, which means the telemetry has to already be collected, retained and searchable before the alert, not provisioned after it. |
Security teams therefore need more visibility.
But more visibility does not have to mean:
More SIEM ingestion.
More cost.
More dependency.
More disruption when things change.
This issue of Snare Insider looks at the architecture sitting underneath those challenges, and why maintaining control of the security evidence layer may be one of the most important decisions organisations make about their future SOC.
In this issue
- Global Cyber Threat Pulse
- Threat Spotlight: The Tools You Trust Are Becoming Attack Paths
- The Security Data Cost Problem Is Really an Architecture Problem
- Dependency Starts Earlier Than Most Organisations Realise
- Quick Read: Consolidation Without Dependency
- Quick Read: The Rise of Portable Security Data
- The Snare Perspective: Separate the Evidence Layer From the Analytics Layer
- AskSnare: Your Investigation Capability Should Be Portable Too
- Quick Read: 10 Questions to Ask Before Your Next SIEM Renewal or Migration
- Key Takeaway
- Sources & Resources








