Build your sovereign SIEM for SMEs, compliant with GDPR/NIS2 without CLOUD Act
You're already forced by GDPR to detect a breach within 72 hours. NIS2 just widened the net by 30x. Build your SIEM now, it's security today and compliance amortised before it lands on you.
You don’t have a SIEM. You tell yourself it’s not for you, that your SME is too small or outside a regulated sector, so under the radar of the big cyber obligations. You’re wrong on two counts.
Now, GDPR. Since 2018, any company that processes personal data must notify the CNIL of a breach within 72 hours. That’s Article 33. Not a recommendation, an obligation. Notifying within 72 hours means you know something happened, that you can characterise it, that you have the logs to trace the chain back. Without a system that centralises your logs and raises alerts, this obligation is unenforceable. You’re in breach the first time a ransomware gets through.
Tomorrow, the widening. NIS2 has just multiplied by thirty the number of French entities subject to reinforced cyber obligations, from 500 to around 15,000. DORA has applied since January 2025 to the extended financial sector, subcontractors included. The Cyber Resilience Act applies fully from December 2027 to any product with a digital component sold in the EU. NIS3 isn’t voted on yet, the indicative timeline aims for the end of 2027. But the trajectory is legible, every two to three years the net widens. Betting your SME stays out of scope in 2028 or 2029 is betting against Brussels and against the GDPR case law that has done nothing but harden.
The word that keeps coming back in all these texts is SIEM, for Security Information and Event Management, centralised management of security events. They never name it, but they make it impossible to avoid. Detecting an incident, keeping exploitable logs, notifying the regulator within short deadlines, those are the functions of a SIEM.
And what is a SIEM, concretely? Picture the CCTV of your shop, but for your IT. Every server, every firewall, every workstation, every mailbox constantly produces a log of what happens on it. Who logged in, at what time, from where, which file was opened, which process started.
A SIEM is the system that brings all these logs to one place, keeps them for several months, and raises an alert when it detects suspicious behaviour.
An account that logs in at 3 in the morning from Pakistan, ten thousand files encrypted in two minutes, a burst of failed passwords on the director’s account, these are signals a human will never catch with the naked eye on a fleet of fifty machines.
The SIEM sees them, cross-references them, and warns you. Behind this consultant’s acronym hides a very concrete assembly, which we take apart further down in this article.
The problem is what’s being sold to you today under that name. Splunk, Microsoft Sentinel, CrowdStrike. At a modest SME’s entry ticket the prices look affordable, but the bill climbs with every gigabyte and every seat, and we do the full accounting at the end of the series. And the price isn’t even the worst of it. These products store your incident logs in a jurisdiction that isn’t yours, under the CLOUD Act. The real question is who holds your most sensitive data.
There’s a third path. The sovereign one. It’s the path of this series.
NIS2 in five minutes, and why it concerns you even outside the scope
NIS2 is the European directive on the security of networks and information systems, replacing NIS1. NIS1 covered around 500 French entities. NIS2 covers around 15,000, spread across eighteen sectors. Health, energy, transport, digital, financial services, agri-food, waste, manufacturing. If your company exceeds 50 employees or 10 million euros in revenue in one of these sectors, you’re directly concerned. Probably as an “important entity”, sometimes as an “essential entity” depending on your size and criticality.
If you’re smaller or outside a listed sector, you’re not off the hook for all that. Two mechanisms catch you. First the supply chain, Article 21 requires NIS2 entities to assess the cyber-resilience of their subcontractors. If you sell service or software to a 60-person SME in health or finance, it’s going to ask you for your proof. No SIEM, no contract. Then the regulatory trajectory itself, NIS3 is in preparation at the Commission, the scope always widens from one revision to the next.
The heart of the mechanism is Article 21. Ten categories of minimum measures, risk analysis, incident management, logging, continuity, training, encryption, access control, supply chain security. And the notification obligation, in three steps, early warning within 24 hours, structured notification within 72 hours, final report within 30 days.
The triptych holds for NIS2 as for GDPR, without a detection and logging foundation, the obligation is unenforceable.
Article 20 adds the detail that changes everything for the director. Liability falls on the natural person who runs the company. Not on the IT manager, nor on the provider. On you.
On the sanctions side, it’s calibrated to hurt. Essential entity, up to 10 million euros or 2% of worldwide revenue, whichever is higher. Important entity, up to 7 million euros or 1.4% of worldwide revenue. For an SME with 30 million in revenue, we’re talking a maximum sanction of several hundred thousand euros.
The law of 30 April 2025 transposes NIS2 into French law. The implementing decrees and the exact scope of the entities concerned are being specified over the course of 2026. As long as it’s fuzzy you tell yourself you have time, but the directive already applies, the case law will be built on the first disputes. The question is when, not if.
We already saw in a previous article how NIS2 contradicts CSAR on encryption. Here, we look at the other obligation, the one that becomes concrete for your infrastructure, detect, log, notify.
You have three options, and two of them are bad
Option 1, US SaaS
Splunk, Microsoft Sentinel, CrowdStrike, Datadog, Elastic Cloud. They work. They’re mature. And at a modest SME’s entry price, they’re not out of reach. The trap is elsewhere.
Microsoft Sentinel charges around $4.30 per gigabyte ingested in the East US region, in the simplified billing model that combines Log Analytics ingestion and Sentinel analytics. CrowdStrike Falcon charges per endpoint, between $60 and $185 per seat per year depending on the tier, Go, Pro, Enterprise or Complete. Splunk is more opaque, the vendor doesn’t publish its prices, but serious secondary sources converge around $8,000 to $12,500 per year for an entry ticket of 5 gigabytes of logs per day, licence only, in Cloud or self-hosted Enterprise.
Take a 50-employee SME that generates five gigabytes of logs per day. On Microsoft Sentinel, around $7,800 per year. On CrowdStrike Falcon Pro for 50 endpoints, around $5,000 per year. On Splunk Cloud at entry, around $8,000 per year. Let’s be honest, $13,000 per year for Sentinel and CrowdStrike combined, on an SME with $10 million in revenue, is 0.13% of turnover. The entry cost isn’t the obstacle.
The obstacle is what you sign up for at the same time. Your logs go to the United States, or to a European subsidiary of an American company. The CLOUD Act, passed in 2018, lets US authorities requisition this data from the provider, even when it’s physically stored in Europe. Microsoft Ireland, Splunk Cloud, CrowdStrike, all are subject to it through their parent company.
And your incident logs aren’t just any data. They’re the complete fingerprints of your network, the usernames, the application flows, the internal behaviours, the vulnerabilities exposed at the moment of the attack. The most sensitive material your information system produces. Handing it to a provider requisitionable by a foreign jurisdiction is a real operational risk.
The Data Privacy Framework, the EU-US legal bridge, survived first instance before the EU General Court in September 2025. It’s on appeal before the CJEU since 31 October 2025. The CNIL, in its February 2025 decision on health hosting, is clear, the only recognised marker for materialising a sovereign cloud remains the SecNumCloud qualification. None of the three SaaS providers cited has it.
One last point. The reasonable entry cost is today. The billing mechanism gets worse as you grow. Every additional gigabyte ingested is charged, every additional endpoint too. At 50 gigabytes of logs per day, the Sentinel ticket climbs above $78,000 per year, Splunk rises in proportion depending on the licence mode. You sign a modest entry price, you also sign a tariff lock-in that closes in as your SIEM sees wider and deeper.
Conclusion, you pay a reasonable price for the plumbing today, by handing the most strategic data in your information system to a jurisdiction that isn’t yours, in an unfavourable legal framework, with a meter running against you at every extension of scope.
Option 2, do nothing
It’s tempting. It’s the most common strategy among SMEs, whether or not they’re in the NIS2 scope. Wait. See. Hope.
The calculation is wrong on three fronts. GDPR today, the CNIL has already sanctioned SMEs for failure to notify, the absence of any detection means is an aggravating factor. NIS2 tomorrow if you enter through the supply chain or through a revision, the maximum sanction for an essential entity exceeds GDPR’s, the director’s personal liability exists in black and white. Ransomware any time, encryption of production, ransom, loss of operations, that’s another order of magnitude than getting into compliance.
Doing nothing isn’t saving. It’s postponing, at the risk of worsening the final bill.
Option 3, sovereign self-hosted
You build your SIEM with mature open-source bricks, deployed on an infrastructure you control. Four bricks, four complementary roles.
- Wazuh, it’s the brain of the setup, the central platform that brings all the logs to one place, stores them, analyses them and raises the alerts. It’s your “home-made Splunk”.
- CrowdSec, it’s the bouncer at the door. A community network defence that automatically blocks the IP addresses already flagged as attackers by the other users of the network. When a bot scans a thousand sites before yours, it’s blacklisted before it reaches you.
- Rspamd, it’s the filter in front of your mail server. It intercepts spam and phishing attempts before they reach your employees’ inboxes. Mail remains the number one intrusion vector for SMEs, that’s where prevention pays off most.
- Santa, it’s the execution controller on your Macs. It decides which applications are allowed to start on each machine, according to an allowlist you build. A ransomware downloaded by mistake can’t run, because it isn’t signed by a vendor you’ve approved. It’s the brick that turns an everyday Mac into a hardened workstation, without the user having to change their habits.
None of these bricks is experimental. Wazuh is used by Fortune 100 companies. CrowdSec, a French company founded in 2019, aggregates 10 million signals a day, shared by more than 70,000 users across 190 countries. Rspamd powers Mailcow, Zimbra, Mailu, which set the reference. Santa, originally developed at Google and now maintained by North Pole Security, runs in production at Figma.
The cost, it’s a correctly sized VPS, the installation time, and an internal competence you build. Not zero, but nowhere near the figures above.
What a SIEM really is, for someone who doesn’t do blue team
The word is scary. It smells of black screens, 24/7 teams and analysts speaking a dialect your IT manager doesn’t understand. Once demystified, it’s simpler.
A SIEM is plumbing. Not a product, an assembly. Four functions that chain together:
- Collect the logs from your equipment, servers, firewalls, workstations, applications, mailboxes. Everything that produces a log, you bring to one place.
- Centralise and keep these logs in an exploitable format, with a retention that lets you investigate an incident going back several months.
- Detect abnormal behaviours. An account logging in at 3 in the morning from an unusual country, a burst of failed authentications, a process that modifies 10,000 files in one minute.
- Alert and keep the trace, for your ANSSI notification within 24 hours, and for your final report within 30 days.
That’s it. No magic. A system that sees, that remembers, and that shouts when something’s wrong.
The hard work isn’t the technology, it’s the adjustment. Which rules you enable, which thresholds you calibrate, who you send the alert to, how you respond. It’s the same thing on Splunk or on Wazuh. And it’s that internal competence you’re going to build across this series.
In short
Building your SIEM in 2026 pays you on two horizons.
Short term, it’s operational security. A ransomware detected in hours instead of weeks, an exfiltration intercepted before the ransom, a GDPR breach you can characterise and notify within the deadlines. That ROI depends on no text that isn’t yet voted, it’s immediate.
Medium term, it’s amortised compliance. You build the infrastructure and the internal competence before the obligation lands on your head. Your competitors will build it under pressure, in a hurry, at three times the price of a flash-mission consultant. You’ll have taken a five-year lead on them for the price of a few weekends spread over a quarter.
US SaaS does the job and isn’t out of price on the entry ticket. It just delivers your most strategic data into an unfavourable jurisdiction, and locks you into a model where every extra gigabyte is charged. Self-hosting demands an initial time investment. In the end, you’re master of the data, of the marginal cost and of the compliance schedule. Real sovereignty against a little of your time, which we’ll make a point of optimising across our articles.
Seven episodes to build your plumbing
It’s the stack I use in production. Not a blogger’s fantasy, an infrastructure that runs day to day, that detects, that logs, that notifies. Seven episodes, seven bricks:
- Episode 1, the foundation. A hardened VPS, on a European host outside American reach. Choice of operator, base configuration, minimal attack surface, encrypted off-site backups.
- Episode 2, Wazuh all-in-one. Installing the manager, the indexer, the dashboard on a single node. Hardening, first dashboards. The functional equivalent of a Splunk for the price of a VPS.
- Episode 3, agents everywhere. Deploying Wazuh agents on your servers, Macs and Windows. Collecting system logs, security events, file activity. The moment your SIEM starts to see.
- Episode 4, CrowdSec on the front line. The community network defence that blocks known attackers before they reach your services. Wazuh integration, signal sharing.
- Episode 5, Rspamd for the mail. The anti-spam and anti-phishing filter that plugs in front of your mail server, or integrates with your existing solution. Phishing detection, logging into Wazuh.
- Episode 6, Santa on the Macs. Execution control on Apple machines. North Pole Security fork, the project actively maintained since Google handed it over in 2024. Progressive lockdown, Wazuh integration.
- Episode 7, alerting and total cost. Calibrated notifications, escalation, honest financial breakdown, episode-by-episode comparison with what the equivalent SaaS would have cost.
The links light up as the episodes publish, come back and plug into the new ones as they come out.
Each episode is standalone. You can stop at 3 and already have covered the essentials of NIS2. You can push to 7 and have a stack with nothing to envy in those of large companies.