By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: AnomaliPublished November 5, 2025

TL;DR: Patchy, siloed SIEM data makes adversary behavior harder to correlate and creates risk for Agentic AI that acts on incomplete context, according to Anomali. The governance problem is no longer just visibility but whether your telemetry architecture can support both human analysts and machine-driven response safely.


At a glance

What this is: This is Anomali's analysis of why SIEM modernization starts with data assessment, unified telemetry, and an observable data lake before AI-driven detection and response can work reliably.

Why it matters: It matters because IAM, entitlement, and identity telemetry are part of the same evidence chain as endpoint and network data, and weak integration leaves both analysts and Agentic AI operating with blind spots.

👉 Read Anomali's guide to SIEM modernisation and AI-era data foundations


Context

SIEM modernization fails when organisations treat tooling as the main problem instead of the data foundation underneath it. In practice, fragmented telemetry, inconsistent identity data, and delayed correlation create blind spots that slow both investigation and response. For teams responsible for identity governance, this is not just a SOC issue because entitlement usage and IAM signals are part of the same operational picture.

The article frames data architecture as the first control decision for AI-ready detection and response. That is a useful lens for practitioners because Agentic AI is only as reliable as the context it can consume, and partial context increases the risk of misclassification or overconfident action. In identity-heavy environments, unified observability becomes a governance requirement, not an architecture preference.


Key questions

Q: How should teams modernise SIEM data foundations for AI-driven detection?

A: Start by mapping the telemetry sources that matter most for correlation, especially identity, entitlement, endpoint, network, and threat intelligence data. Then define which sources are mandatory for analysis, which are optional, and where latency or schema gaps weaken investigations. A modern SIEM should improve context, not just collect more logs.

Q: Why does fragmented telemetry create risk for AI-enabled SOC operations?

A: Fragmented telemetry weakens AI because models inherit the quality and consistency of their inputs. When schemas differ, context is missing, or lineage is unclear, AI produces less reliable recommendations and analysts spend more time validating outputs. Good automation depends on governed, observable data, not just more data.

Q: What breaks when a SIEM cannot normalize identity-change events?

A: Without normalisation, the SIEM cannot reliably show who changed access, which account was affected, or whether the change was expected. That breaks correlation, weakens audit evidence, and slows incident triage because analysts must manually reconcile inconsistent event formats across systems.

Q: How do security teams decide whether SIEM cost optimisation is hurting detection?

A: Measure whether pricing changes are reducing ingestion of the telemetry that most often closes investigation gaps, especially identity and cloud logs. If the budget decision causes more blind spots or longer triage times, the optimisation is undermining security outcomes. The right metric is correlation quality, not just storage savings.


Technical breakdown

Why siloed telemetry breaks SIEM correlation

A SIEM only works when it can correlate events across sources in time and context. When endpoint, network, identity, and threat intelligence data sit in separate systems, the analyst must reconstruct the sequence manually, which increases dwell time and hides weak signals. Siloed telemetry also breaks entity resolution, so the same user, workload, or token may appear as separate records. That is especially damaging in identity-led incidents because entitlement usage and authentication events are often the earliest indicators of compromise.

Practical implication: map your highest-value identity and security sources into a single correlation path before tuning detections.

What an observable data lake changes for agentic AI

An observable data lake is a unified layer that stores security telemetry in a form that both humans and automated systems can query consistently. For Agentic AI, the issue is not just access to data but access to sufficiently complete and well-governed context. If the model sees only partial logs, it may take action on an incomplete picture. Unified architecture reduces that risk by preserving relationships between identities, assets, and events so the AI can reason over the same evidence analysts use.

Practical implication: require provenance, retention, and access controls on the data layer before allowing AI-driven response to use it.

How SIEM cost models can create security blind spots

Consumption-based pricing can discourage teams from ingesting the telemetry they most need, especially high-volume sources such as identity, endpoint, and cloud logs. That creates a hidden control failure because the organisation is effectively paying to exclude evidence from detection workflows. In modern environments, cost pressure and visibility pressure are linked: if the data stream is too expensive to retain or query, threat hunting and incident triage both degrade. This is a governance issue as much as a budget issue.

Practical implication: validate whether licensing decisions are suppressing critical identity and entitlement telemetry before reducing ingestion volume.


Threat narrative

Attacker objective: The attacker objective is to remain hidden long enough to fragment detection, extend dwell time, and increase the chance of successful compromise or exfiltration.

  1. Entry begins with attackers hiding across multiple systems and exploiting the organisation's inability to connect related telemetry, which delays detection.
  2. Escalation follows when incomplete identity and event context prevents analysts and tools from seeing entitlement misuse, lateral movement, or obfuscated activity as one campaign.
  3. Impact is slower containment and poorer machine-assisted response because Agentic AI or SOC workflows act on partial evidence instead of a unified security picture.

NHI Mgmt Group analysis

Unified telemetry is now an identity governance control, not just a SOC design choice. The article is right to treat data architecture as the prerequisite for AI-era detection because identity, entitlement, and activity data now sit in the same decision chain. When those signals are fragmented, both human analysts and automated systems lose context. The practical conclusion is that SIEM modernisation must include identity telemetry governance, not only log engineering.

Agentic AI creates a new dependence on evidence quality. If an automated response system can act, then the organisation must control the evidence it acts on. Incomplete telemetry turns AI from an accelerator into a risk multiplier, especially where identity and access decisions are involved. The governance implication is that AI response should be constrained by observability maturity, with clear thresholds for when automation is permitted.

Cost-driven visibility loss is a hidden form of security debt. Consumption pricing can pressure teams to exclude high-volume identity and cloud logs precisely when adversaries benefit most from missing data. That creates a false economy in which reduced ingestion looks efficient while actually weakening detection coverage. Practitioners should treat telemetry coverage as a control objective, not a discretionary spend line.

Observable data lake: the named concept that matters here. The article points to a model where data is unified, queryable, and available to both analysts and machine-driven workflows. That concept matters because modern threat detection depends on reconstructing relationships across identity, infrastructure, and threat intelligence sources. The practitioner takeaway is simple: if the data layer cannot preserve those relationships, neither SIEM optimisation nor AI augmentation will hold up in production.

What this signals

Observable data lake: the practical signal for teams is whether identity and security telemetry can be queried as one evidence layer across human, workload, and machine activity. If the answer is no, SIEM modernisation will stall at the visualisation layer instead of improving containment. Teams should assess whether their correlation model can survive automated response before they let AI systems take action.

Modern SIEM programmes should now be judged on whether they preserve the relationships between identities, entitlements, and security events. That requirement aligns directly with governance disciplines such as access review, privileged access monitoring, and evidence retention. The next phase of modernisation is less about adding tools and more about making telemetry trustworthy enough for both analysts and automation.


For practitioners

  • Build a unified telemetry inventory Catalogue endpoint, network, identity and access management, entitlement usage, and threat intelligence sources, then identify where correlation breaks between systems. Prioritise the identity feeds that most often reveal misuse of accounts, tokens, or elevated access.
  • Set observability thresholds before enabling AI response Define the minimum telemetry completeness required before Agentic AI or automated response workflows can take action. Include provenance, retention, and access controls so the model operates on governed context rather than partial logs.
  • Review licensing for hidden ingestion trade-offs Test whether volume-based pricing is suppressing critical identity, cloud, or endpoint data, then compare that cost against the loss in detection fidelity. Make the business case in terms of missed correlation, not just storage spend.
  • Use identity signals as correlation anchors Anchor investigations on authentication events, entitlement changes, and privileged access usage so the SIEM can connect otherwise isolated alerts into one sequence. This is especially important where attackers try to hide inside normal administrative activity.

Key takeaways

  • Siloed telemetry is no longer just an analytics problem because it weakens the evidence base for both human investigation and machine-driven response.
  • AI-ready SIEM depends on governed, unified data, and incomplete context can turn automation into a security liability.
  • Practitioners should treat identity telemetry, entitlement usage, and correlation quality as first-order controls in SIEM modernisation programmes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-7Continuous monitoring depends on unified telemetry and correlation across sources.
NIST SP 800-53 Rev 5AU-6Audit review and analysis fit the article's focus on making logs actionable.
NIST AI RMFMANAGEAI response depends on governed data inputs and controlled operational use.
MITRE ATT&CKTA0005 , Defense Evasion; TA0006 , Credential AccessThe article discusses obfuscation and attack visibility gaps that support these tactics.

Prioritise monitoring coverage that preserves identity, endpoint, and cloud event relationships.


Key terms

  • Observable Data Lake: A central security data layer that preserves relationships between telemetry sources so both analysts and automated systems can query them consistently. In modern SIEM programmes, it is less about storage and more about keeping identity, event, and context data usable for detection and response.
  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Unified Data Management: Unified Data Management is a central 5G core function that manages subscriber-related data and supports network decisions. When used for steering and provisioning, it becomes part of the trusted control path, so access, integration and data minimisation need explicit governance.

What's in the full article

Anomali's full post covers the operational detail this post intentionally leaves for the source:

  • The specific data-source assessment checklist for SIEM modernisation and optimisation
  • The observable data lake rationale as presented in the source webinar context
  • The licensing and cost arguments tied to consumption-based SIEM pricing
  • The unified data architecture examples across endpoints, network, IAM, entitlement usage, and TIPs

👉 The full Anomali post covers the data-assessment steps and unified architecture details behind this SIEM modernisation approach.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, secrets management, and identity lifecycle control. It helps security practitioners connect identity discipline to the broader programmes they are responsible for.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org