What Is Co-Managed SIEM?

Also called: Co-managed security information and event management

Related problems: We bought a SIEM but don't have the staff to run it; Our security team can't watch alerts around the clock; Want outside help without giving up control of our security data; SIEM detection rules and integrations falling out of date

Co-managed SIEM is an arrangement in which an outside security provider and an organization’s own team share the work of running a security information and event management (SIEM) system. The internal team keeps access to the platform and its data, while the provider takes on agreed tasks such as platform upkeep, data source onboarding, detection rule tuning and out-of-hours alert monitoring. The exact division of labor is what defines each service, and it varies widely between providers.

At a glance

  • Co-managed SIEM splits SIEM work between your team and a provider; the split is set by contract.
  • Your team keeps hands-on access to the SIEM and its data, which is the main difference from fully managed services.
  • Providers commonly handle platform health, log source onboarding and detection content; many also provide after-hours or 24/7 monitoring.
  • It can run on a SIEM you already license or one the provider supplies, depending on the service.
  • It suits organizations with some security staff who need more capacity or skills, not none at all.

What problem it solves

A SIEM collects logs from across the organization and turns them into alerts, but it is demanding to operate. Log sources need connecting and maintaining, detection rules need constant tuning to stay relevant and avoid alert fatigue, the platform itself needs upkeep, and someone has to watch alerts at all hours. Many mid-sized organizations buy a SIEM and then find their small security team spends its time keeping the tool running rather than finding threats.

Fully outsourcing is one answer, but it can mean losing visibility and control, and some organizations need their own team to stay involved for compliance, internal investigations or knowledge of the business. Co-managed SIEM fills the gap: the provider adds staff, skills and coverage hours, while the organization keeps its data, its platform access and a say in how detection works. It works much like co-managed IT, applied to security monitoring.

How it works

Responsibility matrix. The service starts with an agreed split of tasks. A common pattern: the provider maintains the platform, onboards log sources and writes detection rules; both sides triage alerts, with the provider covering nights and weekends; your team handles investigations needing business context and decides on responses.

Platform and data. The SIEM may be one you already license, in your cloud or data center, or one the provider hosts. Your team and the provider’s analysts both have access, with roles and permissions defining who can change what.

Detection and tuning. The provider brings detection content, often drawn from what it sees across customers, and tunes it to your environment to reduce false positives.

Monitoring and escalation. Alerts are triaged according to the agreed coverage hours and severity levels. Confirmed issues are escalated to your team with findings and recommended actions. Some providers can take agreed response actions, often through security orchestration, automation and response (SOAR) playbooks.

Reporting. Regular reports cover alerts handled, detection changes, log source health and compliance evidence, typically with periodic service reviews.

When it matters for buyers

  • When your SIEM is underused. If the platform is collecting logs but nobody has time to tune it, co-management can recover the investment.
  • When you need 24/7 coverage but have a daytime team. A provider can cover the hours your staff can’t. See our security operations center overview.
  • When compliance requires log monitoring and retention. Many frameworks expect logs to be collected, reviewed and kept; co-management can help meet that with evidence.
  • When choosing between SIEM, MDR and a managed SOC. Decide how much control and how much internal staff you want.
  • When migrating SIEM platforms. Some providers help move to a new SIEM as part of the service.

Questions to ask vendors

  • Can you provide a written responsibility matrix showing who does what, by task and by hour?
  • Do you work with our current SIEM, or do we need to move to yours?
  • Who owns the data and detection content, and what happens to both if we leave?
  • What coverage hours are included, and what are your response times by severity?
  • Which response actions can you take, and which need our approval?
  • How are log volume growth and new data sources priced?
  • Who are the analysts, and will we have a named contact who knows our environment?

How it differs from MDR

Managed detection and response (MDR) is a service focused on the outcome of detecting and responding to threats, often using the provider’s own tools, with the customer receiving alerts and reports rather than running the platform. Co-managed SIEM centers on a SIEM your own team also uses, with responsibilities shared. MDR usually suits organizations with little security staff; co-managed SIEM suits those with some staff who want to stay hands-on. A fully managed SIEM from a managed security services (MSS) provider sits between the two: the provider runs the SIEM and monitoring with limited customer involvement. Many providers sell several of these, so compare contract scope rather than labels.

Frequently Asked Questions

What is the difference between co-managed and fully managed SIEM?
With fully managed SIEM, the provider runs the platform and the monitoring, and your team mainly receives escalations and reports. With co-managed SIEM, your team keeps hands-on access and does part of the work, such as investigations, rule tuning or business-hours monitoring, while the provider covers the rest. The exact split is set in the contract.
Who owns the SIEM in a co-managed arrangement?
It varies. Many co-managed services run on a SIEM the customer already licenses; others supply the platform as part of the service. Ownership affects who controls the data, what happens when the contract ends, and how hard it is to switch providers, so settle it before signing.
Is co-managed SIEM the same as MDR?
Not exactly. Managed detection and response (MDR) is an outcome-focused service that detects and responds to threats, often using the provider's own tools and with limited customer access to the platform. Co-managed SIEM centers on a SIEM your team also uses and shares responsibility for. Some providers offer both, and the line between them has blurred.
Do we need our own security staff for co-managed SIEM?
Usually yes, at least one person who can work with the provider, act on escalations and use the SIEM. If you have no internal security staff, a fully managed service or MDR is often a better fit.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.