Do you need a SIEM
at 150 people?
Often the honest answer is not yet. Here is the test that decides it, and what a SIEM has to include before it is worth paying for.
Probably not yet, unless one of two things is true.
You need a SIEM if a compliance regime requires log retention and search (HIPAA, PCI DSS, CMMC Level 2, SOC 2, or an insurer asking), or if an incident would cross between several systems and you need one place to reconstruct it.
You do not need one yet if everything runs on Microsoft 365 and some laptops, you have no compliance obligation, and nobody would read the alerts. In that case endpoint detection that somebody actually watches is the better purchase, and a SIEM is an expense that buys a dashboard.
When you do need one, the thing that decides whether it is worth it is not the software. It is whether somebody reads what it produces.
Two questions
that settle it.
You probably do need one
- A compliance regime with a log-retention clause: HIPAA, PCI DSS, CMMC Level 2, SOC 2, or a cyber-insurance renewal that now asks the question
- More than a handful of systems that matter — identity, cloud, a line-of-business app, a file server — where an incident would cross between them
- A customer security questionnaire asking how long you keep logs and who reviews them
- An incident in the past where you could not reconstruct what happened, because the evidence had already rolled over
You probably do not, yet
- Everything runs on Microsoft 365 and a handful of laptops, with no compliance obligation
- Nobody would read the alerts, and nobody is being hired to
- You do not yet have endpoint detection deployed and watched, which is the higher-value purchase first
- The honest driver is that a vendor told you that you need one
If you are in this column, we will tell you so. Start with managed detection and response instead and come back to the SIEM question when compliance or complexity forces it.
The license is rarely
the expensive part.
Traditional SIEM pricing is driven by how much data you send it. That sounds reasonable until you notice the incentive it creates: you log less to control cost, and the gaps you leave are exactly the ones an investigation needs. Worse, the month you have an incident is the month your volume spikes, so the bill arrives with the bad news.
Vijilan runs an index-free engine specifically so volume does not become a surprise invoice, and ThreatLog™ is included from the ThreatDefend™ Essential tier rather than sold alongside it. That is a packaging decision rather than a technical boast: a small company should not have to forecast its own log growth to know what it is spending.
The genuinely expensive part of a SIEM is the operating. Tuning it so the alerts mean something, writing the detections, and having somebody awake to read the output are what turn stored logs into an answer. That work does not appear on a license quote and it is most of the value.
What it has to include
to be worth it.
Somebody who reads it. A SIEM nobody watches is worse than no SIEM, because it creates the appearance of coverage. If you are not hiring an analyst, buy it as a service where the reading is included.
Identity, not just infrastructure. Small companies are overwhelmingly compromised through accounts rather than through servers. If the SIEM is not correlating Active Directory, Entra ID and Microsoft 365 activity, it is watching the wrong door.
Retention you can actually search. Archived logs you cannot query quickly are a compliance artifact, not an investigation tool. The question to ask a vendor is how long the data stays hot and searchable, not how long it is kept.
A path out of it. If you outgrow the entry tier, the next step should be an upgrade rather than a migration. NextDefend™ is where estates go when correlation has to reach across cloud, SaaS, network and third-party sources rather than the endpoint and identity alone.
Start with what is already exposed.
ThreatAssess™ is a free external attack surface assessment. Give us a domain and see what an attacker sees today. It is a better opening than a SIEM quote, and it frequently changes what you buy first.
The ones people
actually ask.
Does a small business actually need a SIEM?
Often not yet. If you run Microsoft 365 and some laptops, have no compliance obligation, and nobody would read the alerts, a SIEM is an expense that buys you a dashboard. Endpoint detection that somebody actually watches is the better first purchase. Where a SIEM does become necessary is when a compliance regime demands log retention and search, or when an incident would cross between several systems and you need one place to reconstruct it.
What is the difference between a SIEM and EDR for a small company?
EDR watches what happens on your endpoints and can act there. A SIEM collects and correlates records from everything else as well: identity, cloud, firewalls, SaaS, servers. For a company of 25 to 250 people the practical sequence is usually EDR first, operated by somebody, then a SIEM when compliance or estate complexity makes the gaps expensive.
What does a SIEM cost a small business?
The license is rarely the problem. Traditional SIEM pricing is driven by data volume, so cost scales with how much you log and becomes unpredictable exactly when an incident makes you log more. Vijilan runs an index-free engine specifically so log volume does not turn into a surprise invoice, and ThreatLog™ is included from the ThreatDefend™ Essential tier rather than being sold as a separate product.
How long should a small business keep security logs?
Your compliance regime usually sets the floor: PCI DSS and HIPAA both expect a year of retrievable records, and cyber-insurance questionnaires increasingly ask. Beyond the obligation, the useful question is how far back you would need to look to reconstruct an incident, which is typically longer than teams expect because intrusions are often found weeks after they start.
Can we run a SIEM without hiring anyone?
Only if somebody else operates it. A SIEM produces alerts, and alerts nobody reads are worse than no alerts because they create the appearance of coverage. That is the actual argument for buying it as a managed service rather than as software: you are buying the reading of it, not the storing.