TL;DR: Legacy SIEMs are struggling with the volume, speed, and complexity of AI-fueled attacks, with MIT Sloan research cited by Anomali saying 80% of ransomware attacks now use AI. The modernization question is no longer just tooling refresh, but whether SOC workflows can still keep pace with adversaries that move faster than manual search and siloed data models can support.
NHIMG editorial — based on content published by Anomali: Dispelling the Myths of SIEM Modernization
By the numbers:
- 80% of ransomware attacks are now powered by artificial intelligence.
Questions worth separating out
Q: How should security teams modernise SIEM without losing critical identity visibility?
A: Start with the identity events that matter most for detection: authentication, privilege changes, secret use, and non-human identity activity.
Q: Why do legacy SIEMs struggle against AI-fuelled attacks?
A: They were designed for slower investigations, smaller data volumes, and more predictable attacker behaviour.
Q: What do organisations get wrong about SIEM cost and modernisation?
A: Many teams assume modernisation only means buying more capability and paying more.
Practitioner guidance
- Prioritise identity-rich telemetry Keep authentication, privilege change, secret usage, and service-account activity in the highest-value logging tier so the SOC can see abuse patterns before they spread.
- Redesign detection around response time Test whether your current query, correlation, and triage workflow can detect and investigate a multi-stage intrusion before the attacker completes lateral movement.
- Separate retention strategy from raw log volume Classify telemetry by investigative value, not by source system alone, and keep the evidence needed for privileged access investigations longer than routine operational logs.
What's in the full article
Anomali's full article covers the operational detail this post intentionally leaves for the source:
- The migration mindset and sequencing questions teams face when moving off entrenched SIEM platforms.
- The four-step blueprint the vendor recommends for assessing, defining, implementing, and measuring modernization.
- The cost logic behind newer licensing models and how they change data retention decisions.
- The vendor's examples of KPIs that can be used to prove the value of a modernized SIEM.
👉 Read Anomali's analysis of SIEM modernization for the AI era →
SIEM modernization and AI-fueled threats: what are teams missing?
Explore further
SIEM modernization has become an identity governance issue, not just a detection issue. When logs do not surface authentication abuse, token misuse, or privileged service-account behaviour quickly enough, identity controls lose operational value. That is especially true for NHIs, where access can be machine-speed and short-lived. Practitioners should treat SIEM modernization as part of identity control enforcement, not a separate observability project.
A question worth separating out:
Q: How can SOC teams measure whether SIEM modernisation is working?
A: Use operational measures, not just deployment status. Track time to search, time to correlate, number of identity-relevant detections, and whether the platform can support investigations without workarounds. If analysts still export data into side tools to understand access abuse, modernisation has not yet delivered the intended value.
👉 Read our full editorial: SIEM modernization is now an operational resilience problem