SECAI Core · phase 13 of 15
Security information and event management
A solution that provides real-time or near-real-time analysis of security alerts generated by network hardware and applications.
The Explain card
- Plain English
- A SIEM collects security alerts and logs from network hardware and applications into one place and analyses them in real time or close to it, so analysts can detect and investigate incidents.
- Example
- An organisation feeds its LLM gateway logs, EDR alerts and cloud audit trails into the SIEM. A rule fires when one user triggers repeated prompt-injection blocks shortly after a suspicious login.
- Why it matters
- AI systems add new log sources, and attacks rarely show up in just one of them. The SIEM is where those signals meet, and where AI telemetry earns its place.
- Hook
- The control room where every camera feed lands on one wall.
Where it sits in the deck
Phase 13: Detection, Monitoring, and Threat Intelligence
Defences eventually fail — learn how to detect, correlate, and investigate anomalies in real time across both AI-specific and traditional security telemetry.