DEV Community

Cover image for How to Meet NIS2 Without Splunk Scale SIEM Bills: A Sovereign Security Operations Studio
Micky Irons
Micky Irons

Posted on • Originally published at mickai.co.uk

How to Meet NIS2 Without Splunk Scale SIEM Bills: A Sovereign Security Operations Studio

You can meet NIS2 on hardware you own and stop paying a per gigabyte SIEM bill at the same time. Phylax, our Security Operations Studio, runs the whole security operations centre (SOC) on premise, correlates your telemetry into explained detections with no data volume charge, and seals a regulator ready incident timeline to a signed audit record, so the NIS2 compliance cost moves out of a rising subscription meter and into one system you own outright.

NIS2 compliance cost has turned into enforcement cost

NIS2 moved from readiness to live enforcement in 2026. Enforcement trackers report that the first fines have already landed in Belgium, Italy and Hungary, and on 8 July 2026 the European Commission referred four member states to the Court of Justice of the EU for failing to transpose the directive. For essential and important entities across energy, health, manufacturing, transport and digital infrastructure, the statutory maximum reaches up to 2 percent of worldwide annual turnover for essential entities, and senior management can be held personally accountable.

The obligation is no longer to hold a plan. It is to detect an incident, report it inside tight windows and produce a defensible timeline on demand. The usual way entities meet that is to buy more SIEM and EDR capacity and add an outsourced monitoring retainer on top, all of it metered, so the exact logging the directive pushes you to increase is the same thing that inflates the bill.

What a per ingest SOC costs you today

The incumbent stack bills on the volume you feed it. Splunk and IBM QRadar charge on data ingested and on events per second, Microsoft Sentinel on gigabytes ingested plus cloud egress, and CrowdStrike per endpoint and per module. A managed detection and response retainer usually sits over the lot. Every additional log source you turn on to satisfy NIS2 raises the meter, and the telemetry you are trying to protect leaves your building to be processed elsewhere.

Two costs compound: the licence that scales with the exact logging the regulation asks you to expand, and the egress and retainer fees that recur every year with nothing owned at the end of them. That is the shape of the problem a sovereign SOC removes.

How Phylax runs your SOC on hardware you own

Phylax is our Security Operations Studio, a ready made application for running a security operations centre inside one owned system. It correlates host, network and identity telemetry into detections that carry their own reasoning, triages and enriches each alert, drives the SOAR playbook and the incident, and does all of it fully offline and air gapped on the customer's own hardware. It is detection and advisory only: any containment action is operator gated, so a person authorises anything irreversible.

Because it runs on device, there is no per gigabyte ingest meter, no events per second tier and no egress charge. The Assistant reasons over your own security brain, built on your own data, rather than a shared cloud model, so scaling up detection coverage does not scale up an invoice.

What you replace, and what you save

| What you run today | What it costs you | With Mickai |

| --- | --- | --- |

| Splunk Enterprise Security | Per ingested gigabyte licence that rises with log volume | Correlated detections on owned hardware, no data volume meter |

| Microsoft Sentinel | Per gigabyte ingested plus cloud egress fees | The same telemetry correlated on premise, no ingest or egress bill |

| CrowdStrike Falcon | Per endpoint subscription plus per module add ons | Host telemetry folded into one owned system, no per endpoint line |

| IBM QRadar | Events per second (EPS) licence tiers | Uncapped correlation on hardware you own, no EPS tier |

| Outsourced MDR retainer | Monthly retainer plus per incident fees | Your own SOC drives the playbook and the incident, retainer stops |

From detection to a sealed, regulator ready timeline

NIS2 asks you to prove the incident, not only to stop it. Phylax turns raw telemetry into that evidence in a fixed sequence:

  • Ingest host, network and identity telemetry locally, with no per gigabyte meter and no egress to a vendor cloud.
  • Correlate the signals into an explained detection, so each alert carries the reasons behind its score rather than a bare number.
  • Triage and enrich the alert and drive the SOAR playbook, with any containment action operator gated.
  • Seal the correlated detection and the incident timeline to the Open Audit Record under post quantum cryptography.
  • Hand the incident authority a signed, tamper evident timeline that reconstructs who did what and when.

Every AI action in that chain is sealed into the Open Audit Record, a signed and tamper evident log held on your own hardware. The system does not hold a NIS2 certificate on your behalf, and no product can. What it does is produce the incident timeline and the audit record that a regulator's examination expects, generated on your infrastructure rather than reconstructed after the fact.

What actually leaves your budget

When Phylax takes over the security operations centre, the per ingest and per endpoint licences lapse, the managed detection retainer ends and the cloud egress line disappears. The spend converts from recurring operating expense into a one off owned capability on hardware that is yours. We do not quote you a savings percentage we made up. The saving is the specific set of meters that stop turning: the gigabyte, the event per second, the endpoint and the monthly retainer.

Frequently asked questions

Does an on premise SOC actually satisfy NIS2?

NIS2 does not require a cloud service. It requires risk management, detection, incident handling and reporting backed by evidence. Running the security operations centre on your own hardware meets those duties and keeps the data you are protecting inside your own control, which tends to be easier to defend to a regulator, not harder.

What does Phylax replace?

It stands in for the per ingest SIEM and EDR stack, including Splunk, Microsoft Sentinel, CrowdStrike, Palo Alto Cortex XSIAM and IBM QRadar, and for the outsourced managed detection and response retainer. Correlation, triage, the SOAR playbook and the regulator ready incident timeline all fold into one owned system.

How does it lower NIS2 compliance cost?

By removing the meters. There is no data volume charge, no events per second tier and no egress fee, so the extra logging NIS2 pushes you to enable no longer inflates the bill, and the annual retainer stops. The cost becomes a known number on hardware you own rather than a subscription that grows with your log volume.

Is anything sent to the cloud?

No. Phylax is fully offline and air gapped. Telemetry is correlated on device and the incident timeline is sealed locally to the Open Audit Record, so nothing you are trying to protect leaves the building.

Top comments (0)