Skip to content
Article 32(1)(d)Article 33

SIEM Setup (Security Information & Event Management)

Deploy and configure a SIEM (Wazuh + OpenSearch or Elastic SIEM) to correlate security events, detect breach indicators, and enable 72-hour Article 33 breach notification compliance.

€2,700–€4,500
EUR
60100
hours
3050
business days
Fixed scopeEU-nativeNDA pre-signed
💡Quick Answer

Deploy Wazuh or Elastic SIEM, ingest security events from infrastructure (Linux syslog, CloudTrail, Kubernetes audit logs, application logs), configure correlation rules for GDPR-relevant threats, and set up PagerDuty alerting. Achieves Article 33 72-hour detection capability. Fixed price €2,700–4,500.

📋Why this service exists

Article 33(1) requires notifying the supervisory authority within 72 hours of becoming 'aware' of a breach. The key is 'aware' — you are legally expected to have systems that detect breaches quickly. A SIEM is the standard technical measure that enables this awareness.

Article 32(1)(d)Article 33

What you get

  • SIEM deployed (Wazuh + OpenSearch recommended)
  • Log ingestion from: Linux servers, CloudTrail, K8s audit logs, application events
  • GDPR-relevant detection rules configured (brute force, data exfiltration, unusual bulk downloads)
  • PII access anomaly detection rules
  • PagerDuty / email alerting for critical events
  • Incident response workflow documentation
  • Security operations runbook

How we deliver

  1. Day 0
    You request quote → reply in 4 business hours
  2. Day 1–2
    Discovery call & scope clarification
  3. Day 3–5
    Contract signed, kickoff scheduled
  4. Day 5–7
    Implementation begins
  5. Day N
    Final deliverables + walkthrough call
  6. +30 days
    Free post-delivery support

Tools & technologies

WazuhOpenSearchElastic SIEMGrafanaPagerDutyAlertmanager

Prerequisites

  • Log sources accessible (SSH or agent-based)
  • Infrastructure inventory
  • PagerDuty or similar alerting system (or we set up email alerts)

Pricing

Base scope€2,700–€4,500
Estimated hours60100h
Hourly rate€45/h
Delivery time3050 business days

Within scope:

  • Up to 20 log sources
  • Standard GDPR correlation rules
  • AWS or GCP environment

Outside scope (additional quote required):

  • More than 20 log sources (additional quote)
  • Custom ML-based detection (covered in UBA service)
  • 24/7 SOC monitoring (covered in managed operations retainer)

📋Final price confirmed in proposal within 4 hours of your request.

Realistic timeline — what to expect

  1. T+0hSubmit request
  2. T+4hInitial proposal (business hours)
  3. T+1–3dDiscovery call
  4. T+2–3dFinal invoice
  5. T+3–5dContract signed
  6. T+4–6dPayment received
  7. T+5–7dService kickoff
  8. T+5–7d+NService complete
This timeline reflects EU B2B best practices. We protect both parties from misunderstandings.

Frequently asked questions

Wazuh vs. Elastic SIEM — which should I choose?
Wazuh is open-source, includes a built-in agent, and has GDPR/PCI compliance rules out of the box. Elastic SIEM is more powerful for custom analytics but requires more configuration. We recommend Wazuh for most mid-size organizations and Elastic for those already using the ELK stack.
Does a SIEM guarantee we'll detect breaches in 72 hours?
No tool guarantees breach detection — attackers evolve. But a properly configured SIEM with GDPR-specific rules is the industry-standard technical measure that demonstrates reasonable diligence to regulators.

Related services

Request a quote

You're requesting a quote for:

SIEM Setup (Security Information & Event Management)

Estimated: €2,700–4,500 · 30–50 business days

Initial proposal within 4 business hours, contract within 3 business days.

Where we'll send your proposal and invoice.

If you prefer to discuss by call.

🔒 Your data is encrypted in transit and at rest. Never shared with third parties.

Initial proposal within 4 business hours (EU hours, Mon–Fri 9:00–18:00 EET).

💼 Mutual NDA available on request before any sensitive discussion.