Security Information and Event Management (SIEM)

Analyse the security alerts generated by the components of its information system

Challenges

In the digital sphere, companies and institutions need to guard against numerous IT security events: attacks on IT systems, data breaches, the manipulation of information, to name just a few. If they are neither detected, nor analysed, they can not be resolved and have free rein to potentially compromise infrastructures, systems and data and lead to serious consequences: financial losses, damage to reputation, service outages, etc.

To avoid such disappointments, the integration of an IT security incident management system right at the heart of companies and institutions is a formidable weapon. That system - better known as Security Information and Event Management (SIEM) - collects, centralises, correlates and analyses logs from all components of the information system. Then, it translates the collected data into operational information in order to monitor, detect, alert, facilitate investigation, produce dashboards and reports and provide centralised visibility of logs.

Features

The SIEM is a sovereign solution developed, managed and controlled by the Restena Foundation, on its own servers and within its premises in Luxembourg. The data fed into the tool is transmitted to Restena in encrypted form only. At no time, they are transmitted outside Luxembourg, even not on a cloud. Beyond a thorough understanding and complete control of the its technical infrastructure, the SIEM has another distinctive feature : it is only based on open-source technologies, which, in particular, ensures greater flexibility and security.

Components of the SIEM
Dashboard – Center view of the SIEM

The SIEM was entirely built by the Restena Foundation’s teams, in close collaboration with several representatives from the research and education community in Luxembourg (higher-education establishments, research institutes, etc.) This participatory approach remains central to the continuous improvement of the service.

Benefits

IT security events fed by institutions from the research and education in Luxembourg

Detection and analysis of threats specific to the research and education

Compliance with European directives Critical Entities’ Resilience (CER) and Network information System Security 2 Act (NIS 2)

Low running costs

More details on the service

Who can benefit?

Higher, Secondary, and Primary Educational Establishments, Special Education, Vocational and Adult Training Centres, Research Institutes, Cultural Institutes, Museums, Ministries

Some useful information

  • The SIEM has been developed as part of the European research project ‘Enhancing Cybersecurity Services for the Luxembourgish Research and Education community’ (LuCySe4RE), led by Restena from 2023 to 2026.
  • For optimum protection of your IT system, it is advisable to combine the SIEM to the ‘DNS firewall’ service.

Assistance and support

Services

Other services that might be of interest to you

Help desk block