Security Data Works

Service Offering 3 · The design track

The architecture work that ends in Performant.

Offerings 1 and 2 make the data trustworthy and well-connected. Offering 3 is the design track: the vendor-neutral architecture decision for greenfield or post-Splunk environments, validated against your workload rather than the brochure. Two paid entry points scoped to where you actually are. This page is the working detail behind that decision: the principles, the detection-strategy call, the economics, and the build sequence.

How to engage

Two entry points, scoped to risk tolerance.

The intro call confirms which shape fits. The Migration Assessment is the right shape for a Splunk-anchored exit; the Architecture Assessment is the right shape for the wider input space. A "no-go" finding is a successful engagement. Under-scoping a deployment that drops the team into operational debt is the failure mode the framework is designed to avoid.

What MOAR is

A modular open architecture, not a product.

MOAR (Modular Open Architecture) un-bundles the monolithic SIEM into composable layers connected by open standards. The canonical deployment is the same seven components the capability matrix scores. Each component is a deliberate choice from open formats and purpose-fit tools, and each can be swapped without re-platforming the others. I keep the full breakdown (what goes in each component, the candidate tools, where lock-in actually sits) on the MOAR thesis page rather than repeating it here. This section of the site is the engagement detail: the methodology the assessment applies, not the argument for the architecture.

The design track is where that architecture becomes a defensible decision artifact for your specific environment. The four pages below are the working detail behind it, the same analysis the assessment runs, published openly so you can evaluate the depth before you buy the work.

The working detail

The methodology, in the open.

The architecture, as a decision you can defend.

The intro call confirms which entry point fits: the Migration Assessment for a Splunk-anchored exit, the Architecture Assessment for the wider input space.