As petabyte-scale data overwhelms traditional security platforms, managed security services providers are looking into modern data fabrics.
For years, the SIEM has been the nerve center of enterprise security operations. It’s the platform where logs flow in, analysts hunt threats, and compliance boxes get checked. But something is shifting. While SIEMs have historically been indispensable, in today’s AI and agentic AI world, the traditional technology is struggling to meet modern data demands.
With AI, agentic AI, and dispersed applications, services, and systems, traditional SIEMs are having trouble keeping up with the massive amounts of data all that digital infrastructure produces. For example, a large enterprise today can generate 30 to 50 terabytes of security telemetry per day from firewalls, EDR agents, CDN infrastructure, API gateways, authentication systems, and cloud services. Then add logs pouring out of AI and agentic AI systems, and the amount of data continues to climb.
Some MSSPs tier storage – frozen, cold, warm, and hot – as a way to keep all data in the SIEM; however, it makes retrieval slow. When a security analyst needs to investigate an incident, they often need to look back months or years, which is when data is in cold or frozen tiers. Retrieving that data typically requires a rehydration process that includes manually selecting a time window, submitting a restore request, and waiting. The process can take hours or longer.
Matteo Rebeschini, Strategic Solutions Engineer at Hydrolix, works closely with enterprise security teams and MSSPs on exactly this problem. He says the limitations of traditional SIEMs are a fundamental structural barrier to modern security investigations.
“You have to pick and choose a time window to restore it before you can search it,” Rebeschini explained. “It’s not that you can search through all the data for specific logs matching a search criteria. You have to know the timeframe you’re searching before you can search. The whole process slows down investigations, which only widens the window for more damage. ”
Many common attacks such as credential stuffing, slow lateral movement, and advanced persistent threats require investigators to reconstruct months of attacker behavior. They become operationally expensive exercises where analysts must manage multiple sequential restore cycles, often while time is of the essence.
Storing petabyte-scale data in a traditional SIEM is also costly. One major European financial institution was recently quoted $2.5 million per year by its SIEM vendor for data retention, and the vendor still relied on a rehydration model, hampering the speed of data access and the institution’s bottom line.
The SIEM’s data problem is not just getting more expensive. It is colliding with the next generation of security operations at exactly the wrong moment. And that moment centers around agentic AI.
Security operations are rapidly moving toward automated systems that investigate anomalies, correlate telemetry across dozens of log sources, and surface threats without requiring an analyst to manually construct each query. Traditional SIEM vendors know this and are adding AI capabilities to their platforms. But those agents require millisecond data access and full fidelity data to understand patterns and connect historical context – two must-haves that many traditional SIEMs cannot provide.
“Since traditional SIEMs rely on tiered storage, AI agents may not be able to quickly access the data that they need to detect and respond to an incident,” said Daniele Ricci, Head of Strategic Consulting at RAD, an MSSP that specializes in cybersecurity and security analytics. “So even when using agentic AI with an MCP-type interface to do security investigations, if the platform behind the scenes hits slower storage for long retention in responding, it won’t work.”
The result is a compounding problem: traditional SIEMs are too expensive to retain high-volume data, too slow to serve the agentic AI workflows that are becoming the centerpiece of SOC operations, and too difficult to replace through traditional procurement cycles. So where does that leave enterprises that are locked into multi-year SIEM agreements?
This is where MSSPs can help save the day
MSSPs operate security infrastructure on behalf of hundreds or thousands of enterprises, monitoring environments around the clock, managing detection and response, and satisfying compliance requirements their clients cannot efficiently address in-house. They maintain full control over their technology stacks, and oftentimes their clients typically never see the underlying platform.
“MSSP customers typically are not aware of the SIEM their provider is using,” Rebeschini explained. “MSSPs deliver a user interface, which is often homegrown and custom to them, with their branding, that shows customers their tickets, alerts, and some metrics. That means it’s easy for MSSPs to change their technology stack without their clients finding out. And they can change it to both their benefits.”
That flexibility creates a powerful financial incentive. For example, an MSSP spending $5 million annually on SIEM licensing that replaces its data storage layer with a more cost-efficient platform improves its margins directly, without disrupting a single end-client workflow. Analysts continue using the interfaces they love. Alerts surface through the same channels. Costs are lower. Speed is faster. Both the MSSP and their customer reap the benefits of more affordable retention, and full fidelity data that’s always hot.
The emerging alternative to storing all data in a SIEM is what practitioners are calling the security data layer or fabric model. It’s a high-performance, cost-efficient storage and search layer that keeps all data immediately accessible without tiering, rehydration, or restoration windows.
Platforms built on this architecture ingest petabytes of security telemetry and apply aggressive compression to dramatically reduce storage costs while maintaining millisecond query performance across the entire dataset no matter the age of the data.
“All data is hot and readily available,” Rebeschini said. “That’s something that any large organization can use today. An analyst can search across months or years of telemetry in real time, without any delay. We’re talking seconds, not even minutes.”
For MSSPs, the practical architecture is straightforward. Data pipelines already in place, such as Cribl or Monad, normalize and route telemetry before it enters a SIEM. Those pipelines can be redirected to send high-volume log sources to a security data layer platform instead. Detection logic and automation workflows built in SOAR platforms remain untouched. Security analysts continue querying through familiar interfaces, in some cases directly from Splunk via federated search connectors.
The SIEM becomes an interface layer while storage and querying take place in the data layer platform.
For some MSSPs, specifically those in Europe, adopting this kind of architecture is becoming more urgent. The Digital Operational Resilience Act (DORA), which took effect in 2025, requires financial institutions operating in the European Union to retain security logs for five years and to ensure those logs remain searchable within a reasonable timeframe.
That searchability requirement is new. In the past, organizations satisfied DORA’s predecessor requirements simply by demonstrating that data was being retained in archives. Now they must also demonstrate they can find and retrieve specific records when regulators ask. That means that rehydration-dependent architectures will struggle to fulfill reliably. If the records regulators ask for are in a cold tier, it could take too long to retrieve them. Whereas if the data is always hot, it can be retrieved in seconds.
Industry analysts have long anticipated a restructuring of the SIEM market. What is becoming clearer is the shape of the security data layer architecture that will complement it.
“Agentic AI is replacing the need for manual labor in security operations. But it needs to have a very fast data layer for storing security events and millisecond querying due to continuous iterations between AI agents and the data layer. You cannot wait an hour for the answer to a question you asked. The platform has to be fast enough to respond to natural language queries at the speed of the investigation,” said Ricci.
For MSSPs, this architecture offers a compelling path forward: lower infrastructure costs, better margins, dramatically improved investigation capability, and a platform genuinely built for AI-native security operations.
The SIEM is not going away. But the direction it is headed in can’t be ignored. Data volumes are only increasing. And the MSSPs who operate security infrastructure for thousands of enterprises have both the incentive and the architectural flexibility to start moving now.

