The Business of Cyber Security

Security Operations and SIEM

Security operations (SecOps) is where every other security telemetry stream lands, and the category is being reshaped by two forces at once: hyperscaler bundling (Microsoft Sentinel, Google SecOps) and the agentic SOC. Cisco paid ~$28B for Splunk to own this layer, and it is not yet clear how durable ownership of the layer will prove.

What security operations and SIEM cover

Security operations is the discipline of detecting, investigating, and responding to threats. Its tooling stack — historically three separate products now collapsing into one — is:

SIEM is the aggregation layer of the SOC — the place all other tools' data flows to. That makes it the highest-leverage position in security operations and the natural control point for AI: the vendor that owns the data lake the detections run on owns the substrate the agentic SOC will automate. It also carries volume-based pricing that increases cost as customers log more data, which is a primary reason the architecture is being disrupted.

How the vendors make money and how they differ

Vendor Owner Posture Differentiation / economics
Splunk Cisco (CSCO) Incumbent / bundler Most widely deployed enterprise SIEM; per-GB ingestion economics; now Cisco's data/telemetry platform — networking-led SOC bundle
Microsoft Sentinel MSFT Bundler Cloud-native SIEM converging with Defender XDR; bundled pricing inside the Microsoft estate, able to price toward near-zero marginal cost
Google SecOps (Chronicle) GOOGL Bundler / hyperscaler Petabyte-scale, flat-rate-ish ingestion (priced by users/data, not pure GB); Mandiant intel baked in; furthest "vision" in Gartner MQ
Palo Alto (Cortex XSIAM) PANW Platform / disruptor AI-driven "autonomous SOC" rebuild of SIEM; fastest-growing new SecOps platform; the XDR-from-above attack on legacy SIEM
CrowdStrike (Next-Gen SIEM) CRWD Platform / disruptor Built on LogScale (Humio); endpoint-telemetry-led; attacks SIEM's ingestion tax with the Falcon data
Securonix Vista-backed Specialist analytics UEBA-led cloud SIEM; scaled independent; classic sponsor consolidation candidate
Exabeam + LogRhythm Private (merged 2024) Specialist consolidator Exabeam UEBA + LogRhythm SIEM merger — two sub-scale players combining to survive against the platforms
Devo, Gurucul, Sumo Logic various / PE Sub-scale specialists Cloud-native or analytics-led; Sumo Logic taken private by Francisco Partners (2023); roll-up/consolidation supply
Elastic (Elastic Security) ESTC Open-core challenger Search-engine-led, cost-efficient SIEM; competes on price/openness against per-GB incumbents
IBM QRadar IBM → PANW (SaaS) Legacy in transition IBM sold QRadar SaaS to Palo Alto and steers customers to XSIAM — a managed wind-down of a legacy SIEM franchise
Sophos Fusion Thoma Bravo (TB) Platform integrator AI-native bundled platform (endpoint + SIEM + identity + MDR); launched Jul 2026 with next-gen SIEM / XDR / MDR components GA on Aug 15, 2026; Taegis (from Secureworks, acquired Feb 2025) + Sophos endpoint + Counter Threat Unit analytics; TB's multi-platform consolidation play to attack legacy SIEM from the endpoint up

Three camps compete over one pool. The legacy SIEMs (Splunk/QRadar) own the install base and the compliance workflows but carry the per-GB pricing model; their value is the switching cost, not the architecture. The hyperscaler bundlers (Sentinel, Google SecOps) compete on price and data-gravity, and can offer good-enough SIEM at low cost to win the cloud estate. The platform disruptors (XSIAM, CrowdStrike NG-SIEM) reframe SIEM as a by-product of telemetry they already collect, removing the ingestion cost. The scaled specialists (Securonix, Exabeam/LogRhythm, Devo, Gurucul) sit in the middle: too small to out-invest the platforms on AI and too large to compete purely on price, which makes them the clearest consolidation supply in the domain.

Value migrating off legacy SIEM

Where SOC spend is migrating (directional, est.) Legacy Legacy SIEM (Splunk/QRadar) ↓ Bundle Hyperscaler (Sentinel/SecOps) ↑ Platform Disruptor (XSIAM/NG-SIEM) ↑↑
Directional view (illustrative, not to scale): SOC spend is migrating off legacy per-GB SIEM toward hyperscaler-bundled platforms and AI-native "autonomous SOC" disruptors. Modern SIEM TAM is projected to grow from ~$7.1B (2024) to ~$14B (2029), ~14% CAGR, even as the *legacy* share shrinks. Source: UnderDefense SIEM trends 2026; netguardia 2026 SIEM landscape.

Signature deals & events

The bear case

The SecOps bull case is that all telemetry must land somewhere, so the SIEM/SOC data layer is permanent and the winner compounds. The bear case is that the category is being commoditized from two directions at once. From above, the hyperscalers (Sentinel, Google SecOps) can bundle SIEM into the cloud contract at near-zero marginal price; from the side, the platform disruptors (XSIAM, CrowdStrike NG-SIEM) make the standalone SIEM redundant by deriving detections from telemetry they already own. The legacy SIEM's main durable asset is switching cost, and the agentic SOC, by automating the migration and re-tuning of detections, lowers that switching cost over time. A falsifiable test is Splunk's growth and renewal economics inside Cisco relative to XSIAM's and Microsoft Sentinel's net-new SIEM wins. If Splunk decelerates while XSIAM and Sentinel take the net-new SOC budget, the thesis that legacy SIEM is a durable franchise is breaking, and Cisco would have overpaid for a declining system of record.

Cross-references: Vendors, Endpoint, Network/SASE, AI Security, Earnings, Bear Case.

Adjacent market: the observability and telemetry-pipeline industry this page borders is mapped on Observability & Data Pipelines.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.