Emergency, call now

Blog

The Best SIEM and SOAR Systems for SMEs in 2026

Fabienne Aebi·8 October 2026

You've been asked to find something for your company that detects attacks and responds to them. Vendors talk about SIEM, SOAR, XDR, managed detection. Price lists run from open source to six figures a year. And nobody tells you plainly what a business with 50 or 500 devices and no security team actually needs.

This article sorts it out. First the basics, then 7 vendors side by side. Our own product is in the list, and we'll say openly where it wins and who is better served by something else.

What Is a SIEM and What Does It Do for You?

SIEM stands for Security Information and Event Management. In plain terms: one central place where the logs from all your systems come together. Laptops, servers, firewall, Microsoft 365, cloud consoles, VPN, email gateway. Each of these records what happens. The SIEM collects those records, stores them and searches them for patterns that point to an attack.

The value is in the combined view. One failed login is routine. A hundred failed logins on the same account, then a successful one from another country, then a new forwarding rule in the mailbox: that is an incident. No single system sees the whole chain. The SIEM does.

A SIEM gives you three things:

  • Visibility. You know what is happening in your environment instead of guessing.
  • Detection. Rules and correlation fire when events become suspicious in combination.
  • Traceability. After something happens, you can still reconstruct weeks later when it started and which systems were affected. Cyber insurers, ISO 27001 and increasingly supply-chain customers demand exactly that.

What a SIEM does not do on its own: respond. It alerts. Someone has to read the alert and act.

What Is a SOAR and When Do You Need One?

SOAR stands for Security Orchestration, Automation and Response. It answers the SIEM's weakness. A SOAR takes a detection and runs a predefined playbook: take the affected device off the network, lock the account, end the session, preserve evidence, notify the people responsible. Automatically or at the push of a button.

Why that matters: the time between detection and response is the time an attacker uses to spread. Ransomware groups today often need only hours from first access to encryption. An alert that gets read on Monday morning is too late if the attack started Friday evening.

Traditionally, SIEM and SOAR are two separate products operated by a Security Operations Center (SOC) with several people working shifts. For an SME that is neither affordable nor sensible. Hence the trend towards platforms that combine both, and towards offerings where the vendor takes over part of the work.

Comparison Table

Criterion Goldoak Spectacles Sentinel Splunk ES Elastic Wazuh QRadar Huntress
SIEM ✅ ✅ ✅ ✅ ✅ ✅ ✅
SOAR built in ✅ ⚠️ via Logic Apps ❌ separate product ⚠️ basic ⚠️ basic ⚠️ add-on module ⚠️ by Huntress SOC
Operable without own SOC ✅ ⚠️ needs Azure skills ❌ ⚠️ needs Elastic experience ❌ ❌ ✅
Setup time (typical) under 1 hour days weeks days to weeks days to weeks weeks hours to days
Log tuning included in price ✅ by Goldoak ❌ yourself or partner ❌ yourself or partner ❌ yourself or partner ❌ yourself ❌ yourself or partner ✅ part of managed service
24/7 incident response by vendor ✅ ❌ support ❌ support ❌ support ❌ community ❌ support ⚠️ alert triage
Hosting CH / DE / AT ✅ ✅ Azure region ⚠️ cloud region or self-hosted ⚠️ cloud region or self-hosted ⚠️ self-hosted ⚠️ cloud or self-hosted ❌ primarily US
On-premise possible ✅ ❌ ✅ ✅ ✅ ✅ ❌
Pricing model per system per data volume per data volume / compute per resources, free tier open source, optional support per event rate / licence per endpoint

✅ available, ⚠️ limited or extra effort, ❌ not available. State at publication; pricing models and regions change, so check the details with each vendor. The reasoning behind each rating is in the profiles below.

The 7 Vendors Compared

1. Goldoak Spectacles

Our own platform, so with due transparency: Spectacles is SIEM and SOAR in a single product, built for companies that have IT but no security team. A lightweight agent for Windows, macOS and Linux delivers endpoint telemetry; cloud environments need no agent at all. Detection rules come from real incidents handled by our incident response team and are continuously extended. Every incident is shown as a timeline: what happened first, which systems are affected, what has already been done. Responses such as isolate, lock account and preserve evidence run automatically or with one click.

Where Spectacles wins:

  • Built for the DACH market. Swiss Made Software, hosting in Switzerland, Germany or Austria, compliant with the Swiss DSG and the GDPR. On-premise on request.
  • Operational in under an hour. Configure the licence, roll out the agent, done. In the Akira case we onboarded 1,000 systems in five days.
  • Transparent pricing. CHF 8.50 per system per month, CHF 7.50 from 500 systems, no volume surprises. A dedicated instance per customer. Log tuning, meaning adjusting sources and rules to your environment, is included in the price.
  • People behind it. Rollout planned together, and when a serious incident hits, our incident response team takes over around the clock.

Where it doesn't fit: if you run your own SOC with analysts who write their own queries and rules every day, an open platform like Elastic or Splunk gives you more freedom. Spectacles is deliberately designed for operation without specialists.

2. Microsoft Sentinel

Microsoft's cloud-native SIEM, tightly integrated with Azure, Entra ID and Microsoft 365 Defender. If you are already deep in the Microsoft ecosystem, many data sources connect in a few clicks and automation can be built with Logic Apps. The detection content is extensive.

Fits if your environment is Microsoft-heavy and you have Azure skills in-house. Pricing is based on the data volume ingested into Azure, so costs are hard to estimate up front. Data residency follows your Azure region; Swiss regions are available.

3. Splunk Enterprise Security

The classic among SIEM products, now part of Cisco. A very powerful search language, a huge ecosystem of apps and integrations, SOAR as a separate product. The standard in large security teams.

Fits if you have analysts who want to work with data and an enterprise-level budget. Priced by data volume or compute. For an SME without specialists the entry is demanding; the strength only shows with people who master the tool.

4. Elastic Security

Built on the Elastic Stack that many IT teams already know for logs and monitoring. SIEM with endpoint protection, ready-made detection rules and an open data model. Available as a cloud service or self-hosted, with a free basic tier.

Fits if you already use Elastic or want an open platform you run and extend yourself. SOAR features exist but are less developed than in specialised products. Operating it takes experience with the stack.

5. Wazuh

Open source and free, with an agent for all common operating systems, file integrity monitoring, vulnerability detection and compliance checks. A large community and a vendor that sells cloud hosting and support.

Fits if budget is tight and you have the time and skills to build, maintain and tune the system yourself. The licence costs nothing; operating it does. Automated response exists in basic form; a full SOAR layer you have to add. Data residency: wherever you host it.

6. IBM QRadar

Long established in banks, insurers and government. Strong correlation, deep experience with regulated environments, SOAR as its own module. With parts of the portfolio moving to Palo Alto Networks, the product strategy is in transition.

Fits if you are in a heavily regulated sector, have a security team and value established enterprise processes. For SMEs, rollout and operation are usually oversized.

7. Huntress Managed SIEM

Huntress comes from managed detection for small businesses and MSPs and offers a SIEM where the Huntress SOC reviews the alerts. The approach: filter data deliberately, store only what matters, and have the vendor's people assess the alerts. Priced per endpoint rather than per data volume, easy to start.

Fits if you have a small environment, mainly Windows and Microsoft 365, and want someone else to triage the alerts. Huntress is a US vendor with a US focus, so check data residency and contractual assurances if the Swiss DSG or the GDPR apply to you. Custom queries and deep customisation are not the focus.

Conclusion

The question is not which SIEM is the most powerful. Splunk, Sentinel and QRadar are mature tools for teams that can operate them. Wazuh and Elastic pay off if you want to build it yourself. Huntress takes alert triage off your hands, with a US focus.

For an SME in the DACH region without its own security team, the deciding question is different: which system is live within a week, can be run on the side, keeps the data in Switzerland, Germany or Austria, and who stands behind it when it gets serious? That is exactly what we built Spectacles for, and that is where we see it ahead.

Best to see for yourself. In a demo we show you what an attack looks like in Spectacles and how the response works, no sales pitch. If you first want to clarify what your environment actually needs, we'll go through it together in a consulting session. All platform details are at Spectacles.

← All articles