Skip to content
SIEMWazuhOpen SourceSMEDetection

Wazuh Instead of a Commercial SIEM: What Open Source Really Costs an SME

1 August 2026|7 min read

Wazuh as an open-source SIEM for Swiss SMEs: what the platform does, what running it actually costs, and how the nDSG and the ISG come into it. And why the licence never decides the outcome. The operations do.

An attacker typically moves through a network for days before anyone notices. A SIEM cuts that time drastically. Provided it is running, properly configured and someone is actually watching. Those are exactly the three points where SIEM projects fail in SMEs. Not the software.

What a SIEM Does and Why the Invoice Scares People Off

A SIEM (Security Information and Event Management) collects the logs from your endpoints, servers, firewalls and cloud services in one place, correlates them against detection rules and raises the alarm when something is off: a brute-force attempt on the VPN, a new admin account at three in the morning, a tampered system file.

Commercial vendors usually charge per gigabyte of ingested log data. That sounds harmless, but it scales against you: the better your visibility, the higher the bill. An SME with a few dozen employees, some servers and Microsoft 365 logs quickly ends up with a four-figure monthly invoice. And with a perverse incentive: to log less in order to save money. Log less, see less. On top of that, with many cloud SIEMs your logs sit on infrastructure outside Switzerland, and with them sensitive personal data and internal business details.

What Wazuh Is

Wazuh is an open-source SIEM and XDR platform under a GPL licence. A lightweight agent runs on Windows, Linux and macOS; firewalls and network devices deliver their logs agentlessly via syslog. The Wazuh server correlates events against detection rules, an OpenSearch-based indexer stores them, and a dashboard makes them searchable.

Out of the box, the platform includes what requires paid add-on modules elsewhere: real-time log analysis, file integrity monitoring, vulnerability detection on endpoints, configuration checks against CIS benchmarks, mapping of findings to MITRE ATT&CK, and active response, meaning automated reactions such as blocking an IP.

No licence key, no forced vendor cloud, no lock-in. If you want to take over operations yourself, you can do so at any time.

The Honest Maths

The licence costs CHF 0. Operations do not.

Wazuh needs infrastructure, above all storage, if you want or need to retain logs for months. It needs updates. And it needs tuning: out of the box, Wazuh is loud. Thousands of events per day, many of them false positives. Without tailored rules, your team will be ignoring the alerts within two weeks, and at that point the SIEM is no longer a security tool but an expensive dashboard.

Still, the maths work out for most SMEs: a well-run Wazuh on your own or on Swiss infrastructure has predictable costs, regardless of how many gigabytes your systems produce. Compared with volume-based cloud SIEMs, you typically end up significantly cheaper, with full rather than throttled visibility.

Why This Counts Double in Switzerland

Logs contain personal data, so the nDSG (Swiss Data Protection Act) applies to your log management too. If you fall under the reporting obligation of the ISG (Information Security Act), you must report cyberattacks to BACS within 24 hours, but you can only report what you actually detect. The Swiss federal ICT minimum standard lists "Detect" as one of its core functions. And if you supply into the EU, your own customers are increasingly asking about your detection capabilities, because NIS2 reaches you through the supply chain.

With Wazuh on Swiss infrastructure, you answer all four points with the same sentence: our logs stay in the country, and we can see what is happening on our systems.

The Catch Is Called Operations

The technology is half the battle. The other half: someone has to maintain the rules, triage the alerts daily and escalate when it matters. A full-time security analyst is not realistic for most SMEs, and that is exactly the gap where SIEM projects quietly die.

How We Run Wazuh

We have made our choice here: Wazuh is the SIEM we run ourselves, for our own infrastructure and for our clients. Wazuh ships with more than 4,500 detection rules, and our own come on top, configured and tuned by MilesGuard. Depending on your starting point, in three tiers.

Setup and consulting: we build Wazuh in your environment, adapt the rules to your systems and hand over to your team. You operate it; we are there when needed.

Managed SIEM: we host and operate your Wazuh on Swiss infrastructure. Updates, rule maintenance and storage included. Your logs, your data, cancellable at any time.

SOC as a Service: the same engineers who run our penetration tests triage your alerts and escalate what matters. We call it what it is: best effort. Not a 24/7 SOC with guaranteed response times, but real day-to-day triage with clear escalation paths, at a fraction of the cost. For most SMEs, this is the realistic middle ground between "nobody is watching" and a six-figure SOC contract.

And if you need the strategic layer on top, meaning policies, incident response processes and board reporting, our CISO-as-a-Service model covers it from two days per month.

Conclusion

Wazuh makes detection affordable and sovereign for SMEs: no licence costs, no volume trap, logs in Switzerland. What decides the outcome is not the software but the operations. Every company has to settle that question. Not every company has to answer it alone.

If you want to know what a Wazuh setup would look like in your environment, let's talk.

Sources

Share:LinkedIn

More Posts

Related Services