Comment by everdrive
8 hours ago
No, and it's not strictly impossible to correctly build out a SOC / SIEM and ingest all the logs you want and pay for the right engineers to make sure it all works correctly. But damned if anyone manages to do a great job in this area. It's too complex and too expensive, so almost everyone settles for "best effort."
A lot of problems are easy conceptually, but we can't manage to tackle them.
No comments yet
Contribute on Hacker News ↗