RSMM · Realistic SIEM Maturity Model

Most SIEMs are not mature. They are loud, bloated and expensive.

Three instruments for working out where your SIEM actually stands. No buzzwords, no vendor slides, no unrealistic promises. Built on the Realistic SIEM Maturity Model.

Most SIEMs fail not because of tech, but because of expectations. These tools are designed to tell you something uncomfortable and specific, rather than something reassuring and vague.
01

SIEM Sanity Checklist

79 questions
Is this a security tool or expensive log storage?
Seventy-nine questions across thirteen areas, answered yes, partly or no. Produces a sanity score, a profile of where the damage is, and one of three verdicts ending in Alert Cannibalism.
Start the checklist →
02

Maturity assessment

45 criteria · staged
Which of the five SIEMs are you running?
Forty-five criteria across the five RSMM levels. Staged rather than averaged, so doing Level 4 things while Level 1 is unfinished does not make you Level 4.
Find your level →
03

Metrics calculator

38 metrics
Can you prove any of it?
Thirty-eight metrics with explicit formulas across the RSMM dimensions, including the cost and portability numbers most SIEM programmes never calculate until renewal.
Open the calculator →

The five levels

LEVEL 0
Blame Collector
Ingesting logs so somebody can say logs are ingested. No use cases, no detections. Often bought for compliance.
LEVEL 1
Alert Factory
Out-of-the-box rules, tons of alerts, few useful. No tuning, no feedback loop. The platform produces work rather than answers.
LEVEL 2
Use Case Island
Humans design some use cases and correlation exists. Still mostly reactive, but alerts begin to be worth reading.
LEVEL 3
Detection Pipeline
Detection-as-code, threat-informed, ATT&CK mapped. Data quality is reviewed rather than assumed. False positives fall.
LEVEL 4
Outcome-Driven SIEM
Aligned with business risk, integrated with TI, SOAR and deception, driven by threat profiles. You actually detect real attackers.

About the model

RSMM was written to give teams an honest way to evaluate a SIEM without drowning in buzzwords or vendor slides. It scores five levels grounded in real outcomes rather than aspiration, across dimensions covering data utility, detection content, alert quality, threat intelligence, engineering process and measurable outcomes.

These tools extend it with three areas the original article touched only lightly: cost and data economics, search and investigation experience, and portability and lock-in. Sections marked Extended in the checklist are those additions.

Everything runs in your browser. There is no backend, no database and no analytics, and nothing you enter is transmitted or stored.

Created by Reza Adineh. Inspired by the work of Anton Chuvakin, Christopher Crowley and Rob van Os, and by SOC-CMM.

See also the Unified Threat-Informed Operations Model, which covers the wider security operation that a SIEM sits inside.