SECAI Core · phase 13 of 15

Security information and event management

A solution that provides real-time or near-real-time analysis of security alerts generated by network hardware and applications.

The Explain card

Plain English
A SIEM collects security alerts and logs from network hardware and applications into one place and analyses them in real time or close to it, so analysts can detect and investigate incidents.
Example
An organisation feeds its LLM gateway logs, EDR alerts and cloud audit trails into the SIEM. A rule fires when one user triggers repeated prompt-injection blocks shortly after a suspicious login.
Why it matters
AI systems add new log sources, and attacks rarely show up in just one of them. The SIEM is where those signals meet, and where AI telemetry earns its place.
Hook
The control room where every camera feed lands on one wall.

Where it sits in the deck

Phase 13: Detection, Monitoring, and Threat Intelligence

Defences eventually fail — learn how to detect, correlate, and investigate anomalies in real time across both AI-specific and traditional security telemetry.