Security Data Works

Engagements

Three principles, productized.

Security Data Works is a services company. The public MOAR Reference Stack shows the architecture working end to end before you spend anything; the services below implement it in your environment, incrementally; and the Capability Matrix — weighted scoring, claim-versus-shipped deltas, workload bundles — is the premium instrument bundled into every engagement above the $25K floor. Every engagement starts from the same insight: your platform problem is data-engineering debt, and the fix is repairing the broken pieces one at a time, never a bet-the-SOC migration.

Engagements above $25K include a 6-month matrix subscription plus 2 quarterly reports. Fixed price over hourly. Each engagement quotes a fixed fee scoped to deliverables. No body-shop hours, no surprise invoices.

Most engagements start here

Modernization Discovery · $20K · 2 weeks

A paid two-week wedge that sizes the larger assessment before you sign it: a Capability Matrix shortlist scoped to your workload, a half-day reference-architecture workshop, and a Splunk billing-and-license audit. The full $20K credits toward the Migration Assessment if you sign within 90 days, so the first step de-risks the engagement rather than committing you to it.

See the Modernization Discovery wedge →

Operational tracks
Design track
Service Offering 3

MOAR Architecture Design

→ Performant·Architecture

MOAR (Modular Open Architecture) is the design track for greenfield or post-Splunk environments. There are two entry points, plus a paid pre-track wedge that feeds them. Modernization Discovery is the wedge: a paid two-week shortlist plus reference-architecture workshop plus Splunk billing audit, and it sizes the assessment before you sign it. The Splunk-to-MOAR Migration Assessment is the flagship migration analysis. The evidence under the assessment is two-regime, and I report both halves: a schema-on-read index wins the simple indexed lookups, and the lakehouse engines win the hunting-shaped aggregations by 5–62× — 46.8× native / 10.1× Iceberg on the five-query average (Tier B, single host, 10M events, CV-gated, identical answers verified). Among compliant engines the join spread is compressed at SOC scale (every engine under 1.5 s), so the engine recommendation leads with manageability. The Architecture Assessment is the full vendor-neutral review against the matrix, covering storage, engine, 3-year TCO, and a phased roadmap. Validated on your workload, not the brochure.

The design track in full — principles, detection strategy, economics, roadmap →

The Architecture Assessment review runs against the matrix; you can see how that scoring works on the worked scorecard.

Reference implementation
Service Offering 6

Reference Implementation Deployment

3–6 weeks·pricing TBD

Stand up the open MOAR Reference Stack in your environment: the kit deployed against 2–5 of your own log sources, landing OCSF on Iceberg; the data-health gate running on your telemetry (the first broken-piece fix, live); a working multi-engine query path over the landed data, engine choice per the Matrix bundle; and a runbook with a keep-or-teardown decision at the end. The deployment is reversible by design. This is not a production SOC migration, not a managed service, and not a paid unlock of gated Matrix features.

Run the Reference Stack yourself first →

Continuity
+

Implementation Support · Advisory Retainer

Ongoing·$5K–$40K/mo

Embedded (1–2 days/wk during active migration), advisory (monthly strategy plus async review), or workshop (1–3 days). Continues across whichever of the three offerings are active.

Read the engagement detail →

Partner delivery

Delivery partners run the MOAR Reference Stack under their own SLA; Security Data Works verifies the architecture. That's the two-throats model made customer-visible: your integrator is the operational throat you can call at 2 a.m., and SDW is the assurance throat — Matrix-backed validation with the independence test intact, because a partner has to be able to accept a "stay and optimize" recommendation against their own implementation margin. No reseller margins, no kickbacks; that independence is what the partner is buying too.

No delivery partner is named here yet; until one is, I'll say it plainly — Security Data Works is a single-practitioner practice today, and every engagement is scoped so the deliverables stand on their own without me.

What customers are seeing

Measured outcomes from production deployments.

These are publicly attributable numbers from teams running the patterns the matrix recommends. Each is sourced; none are SDW marketing. Full pipeline detail and trade-offs live on references; the engagement narratives behind comparable numbers — anonymized — live on case studies.

$70K → $5K/mo

Huntress migrating off Elasticsearch onto ClickHouse Cloud. A reported >90% cost reduction at the analytics tier; throughput grew to 200K records/sec.

ClickHouse · published

46.8× faster

SDW Zeek benchmark (single host, Tier B, 10M events), CV-gated, identical answers verified. Two-regime: the lakehouse engines win the hunting-shaped aggregations by 5–62× over a schema-on-read SIEM foil (46.8× native / 10.1× Iceberg on the five-query average), and the index wins the simple lookups. Compression on the same corpus: 8.5× Iceberg Parquet vs raw JSONL, 9.0× ClickHouse blanket ZSTD-22.

ClickHouse · reproducible

9 mo → 5 days

Ziggiz.ai Cyber Lakehouse-as-a-Service. Tenant onboarding compressed. 30-50% cost reduction vs. three leading SIEMs (Ziggiz-published).

Databricks · published

80% faster TTD

Standard Chartered replaced a traditional SIEM with a self-managed Databricks lakehouse — 80% faster time-to-detect, 92% faster investigation, ~35% cost reduction (bank-reported, DAIS 2025).

Databricks · published

40% volume cut

Yale New Haven Health across 30K endpoints migrating to Microsoft Sentinel via Cribl Search query-in-place. Fortune 1000 deployment hit 99.99% on the same pattern.

Cribl Search · published

<100ms

Palo Alto Networks (Cortex XSIAM) event-to-rule firing on streaming SQL. Production-validated; eliminates the batch-index five-minute vulnerability window.

RisingWave · published

64% TCO at 1 TB/day

SDW TCO model for the route-reshape-reduce pattern at exchange-scale workload. 35% savings at 100 GB/day for smaller shops.

Cribl pipeline · modeled

Headline numbers travel; the methodology and caveats travel with them. Each outcome is either published by the deploying team, reproducible via the SDW benchmark methodology, or documented in the research surface, with evidence tier and confidence stated.

Pricing philosophy

Fixed price over hourly. Each engagement quotes a fixed fee scoped to deliverables. No body-shop hours, no surprise invoices.