TopMDR SIEM Dedicated

SIEM SOLUTION FOR BUSINESSES: YOUR SCALABLE SECURITY ARCHITECTURE WITH DATA SOVEREIGNTY IN AUSTRIA

Cyberattacks are among the greatest risks faced by businesses today. Attackers are becoming increasingly professional, automated and often remain undetected for long periods of time. Traditional security solutions frequently operate in isolation and are unable to identify complex attack patterns early on.

That’s where a SIEM solution comes into play: it consolidates security-relevant data from multiple IT systems, correlates and analyses it in real time and detects even hidden or multi-stage threats. By evaluating log data and security events centrally, it provides a comprehensive view of your company’s security situation. This is a crucial prerequisite for identifying attacks at an early stage and responding to them effectively.

With TopMDR SIEM dedicated you receive a managed Security Information and Event Management (SIEM) platform for your company that is operated within conova’s data centers. The SIEM solution combines real-time endpoint monitoring with a structured incident response platform. Detected anomalies are centrally aggregated, documented and can then be forwarded to a Security Operations Center (SOC) such as TopMDR SOC. At the same time, the data is made available in a structured format for reporting, audits and certification purposes.

Zitat-Symbol
BENEFITS
  • Data sovereignty: Storage and processing exclusively within Austria
  • Real-time endpoint monitoring via log analysis and CVE scanning
  • Identification of infrastructure vulnerabilities based on CIS Benchmarks
  • Provision of a SIEM solution for use by TopMDR SOC or your company’s own Security Operations Center (SOC)
  • Optional: Joint tuning and optimization phase using best practices to achieve an optimal SIEM setup
  • Optional: Deployment on-premises or within a public cloud environment available upon request

SIEM SOLUTION: CENTRALIZED ANALYSIS, CORRELATION AND MONITORING OF YOUR ENTIRE IT ENVIRONMENT

TopMDR SIEM dedicated monitors endpoints such as servers, clients and network infrastructure components (e.g., switches and firewalls). These systems may be operated on-premises, within the conova data centers (unmanaged and managed services), or in public cloud environments (e.g., Microsoft Azure/M365, AWS or GCP). The data that is collected is transmitted to the SIEM platform, where it is correlated and analyzed. On the client side, the platform supports Windows, Linux and macOS operating systems. Alerts that are generated by the platform can optionally be forwarded to a Security Operations Center (SOC).

The SIEM architecture consists of the following components:

  • Agent: Runs on endpoints (servers, clients and cloud instances), collects log data and performs system checks.
  • Server (Manager): Analyzes events and correlates them based on predefined rules.
  • Indexer: Stores and indexes collected data.
  • Dashboard: Provides visualization, alerting and analysis of security events.

THERE ARE THREE DEPLOYMENT OPTIONS AVAILABLE FOR THE SIEM PLATFORM

SMALL: In this scenario, all components required to operate the platform are hosted on a single virtual machine.
MEDIUM: In this configuration, the Server and Indexer components are deployed separately.
LARGE: The Large deployment uses multiple servers and multiple Indexers operating as a clustered environment.

TopMDR SIEM dedicated does not include SOC services. Instead, it provides a technical platform to be used by a Security Operations Center (SOC), such as TopMDR SOC, under the customer’s own responsibility.

TopMDR SIEM dedicated 1)SML
DeploymentSingle-NodeDual-NodeMulti-Node+Cluster
Asset Monitoring (recommendation)up to 100 Assetsup to 1.000 Assetsfrom 1.000 Assets
Log storage included100 GB150 GB1.500 GB
Price per monthupon requestupon requestupon request
Set-up costs (one-time expense)upon requestupon requestupon request
TopMDR SIEM – extensions (excerpt)
Increase in storage quota per 100 GBupon requestupon requestupon request

1) SLA Economy included, SLA Business and First Class (24/7) optional. Further information about SLA on request.

Notes:
• Log data is stored for up to three months by default. Alternative retention periods can be agreed upon individually.
• For customers who are not currently using a conova Managed Service, access to the dashboard requires either a VPN connection or whitelisting of the customer’s static IP address.
• Joint onboarding, alert tuning and validation, ticketing system integrations and SOC operational optimizations can be booked via the service hours account.

Contract details:
• Minimum contract period 36 months.
• Errors and changes reserved.

FREQUENTLY ASKED QUESTIONS REGARDING SIEM

What is a SIEM solution?
A SIEM (Security Information and Event Management) solution such as conova’s TopMDR SIEM centrally collects and analyzes security-relevant data from various IT systems. By correlating log data, it identifies suspicious activities and helps companies detect and respond to cyberattacks at an early stage.

Why is a SIEM solution important for businesses?
Cyberattacks are becoming increasingly sophisticated and often remain undetected for long periods of time. A SIEM solution provides visibility across the entire IT environment, detects even multi-stage attacks and also enables a rapid response to security incidents.

What is the difference between a SIEM and a SOC?
A SIEM solution is the technical platform used to collect and analyze security data. A SOC (Security Operations Center) is a team of security specialists that monitors, evaluates and actively responds to security incidents based on the information provided by the SIEM platform.

What are the benefits of having a SIEM solution hosted in Austria?
Operating a SIEM solution in Austrian data centers such as the ones provided by conova, offers advantages ranging from data protection, data sovereignty and legal certainty. Companies benefit from clear regulatory frameworks and short response times.

Last update: 15.06.2026