SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
Story image

Expel boosts SIEM capabilities with expanded compliance focus

Fri, 14th Feb 2025

Expel has announced its expanded security information and event management (SIEM) coverage, enhancing its managed detection and response capabilities with a focus on better-supporting compliance and data storage requirements.

The company has introduced a low-cost data lake offering to help customers manage compliance and storage needs more effectively while bolstering security. Expel has also extended its integration and support for industry-leading SIEM and extended detection and response (XDR) products, including Sumo Logic Cloud SIEM and CrowdStrike Falcon LogScale environments.

Yonni Shelmerdine, Chief Product Officer of Expel, commented on the current cybersecurity landscape: "Organisations are navigating an increasingly complex landscape when it comes to the balance between cybersecurity risk, spend, and return on investment. With tighter budgets and a cyber talent shortage contending with the rising number of security products (driving up data and costs), organisations need more efficiencies from their tech stack for measurable security outcomes that prove ROI. Expel MDR's expanded SIEM capabilities deliver flexibility in managing security data while reducing costs and aligning with regulatory needs, perfectly timed to meet these evolving market demands."

Expel's new and expanded SIEM coverage includes the option for customers to provide a low-cost data lake and a comprehensive cloud SIEM product. This move allows for greater flexibility in tuning detections within Sumo Logic Cloud SIEM and CrowdStrike Falcon LogScale environments.

Expel has broadened its integration capabilities by adding support for Google Security Operations and Palo Alto XSIAM. Advanced features are expected to be launched early in 2025.

The expanded alliance with Sumo Logic allows Expel to offer a wider range of data analytics solutions, providing cost-effective long-term data storage and advanced security analytics tailored to customer needs. These services aid in compliance with standards such as the Payment Card Industry Data Security Standard (PCI DSS), General Data Protection Regulation (GDPR), and HITRUST Common Security Framework (CSF).

Seth Williams, Field CTO of Sumo Logic, said, "With the rise of AI evolving the next generation of SIEM solutions, Sumo Logic continues to drive cloud security innovations to modernise SOCs and offer predictive insights, automated responses, and seamless integration with DevSecOps. Our partnership with Expel delivers a joint offering that expertly manages detection and response strategies while providing a best-of-breed Cloud SIEM technology to help customers speed up incident investigations by automatically triaging alerts and correlating threats through log analytics."

Craig B. Robinson, Research Vice President, Security Services at IDC, emphasised the importance of these developments amidst a cybersecurity skills shortage: "The growing disparity between a marked cybersecurity skills shortage and advancing threats are compelling more organisations to turn towards security services to bridge the gap; nearly 41% of cybersecurity budget dollars are going towards security services, according to a recent IDC survey. IDC research has also uncovered how most CISOs report to either CEOs or COOs, making the cybersecurity business case even more important.

"Expel's expanded offerings enable businesses to find cost-effective solutions that don't compromise on security efficacy, while also addressing data storage demands and compliance requirements. The new enhanced SIEM options announcement reflects a critical market shift towards flexible and affordable data management, empowering companies to meet regulatory standards while optimising their existing security investments."

The enhancements in Expel's SIEM solutions are intended to provide data storage and compliance flexibility while combining advanced detection capabilities with broad integration support for popular SIEM tools. These developments aim to equip security leaders with the necessary tools to achieve measurable security outcomes, reduce costs, and optimise their security investments.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X