TelcoNews US - Telecommunications news for ICT decision-makers
United States
ReliaQuest launches SIEM-less threat detection tool

ReliaQuest launches SIEM-less threat detection tool

Wed, 29th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

ReliaQuest has launched GreyMatter SIEM-Less, aimed at security teams that want to detect threats without relying on a traditional security information and event management platform.

The new offering lets teams run detections on data in motion rather than waiting for information to be indexed, parsed and stored. It also allows customers to decide where telemetry is held while keeping search, reporting, investigation and response functions within the GreyMatter environment.

The launch reflects a wider debate in the cybersecurity market over the role of SIEM platforms as data volumes rise and attacks move faster. Many organisations still use SIEM tools as the centre of their security operations, but vendors and customers have increasingly questioned the cost and delay of centralising large volumes of telemetry before analysis can begin.

ReliaQuest argues that the growth of distributed data and faster-moving attacks has made that model harder to defend on both speed and cost. Its view is that security teams now want to detect threats closer to the source, decide which data to keep, and query information across different storage locations without moving everything into one system first.

GreyMatter SIEM-Less sits within the broader GreyMatter platform, which ReliaQuest describes as its main environment for detection, investigation, hunting and response across enterprise technology estates. The new product extends that platform by changing how security telemetry is processed from collection through detection to later analysis.

According to ReliaQuest, users can query stored telemetry directly from GreyMatter in natural language. Teams can run and save searches, build reports, investigate incidents and conduct threat hunts, while also carrying out response actions such as blocking an IP address, banning a file hash and executing containment measures from the same console.

Shift in architecture

ReliaQuest framed the launch as part of a broader redesign of cybersecurity operations. The shift centres on reducing dependence on a single central repository for telemetry and allowing detections to occur before data is committed to storage.

In practice, that means normalising data across different tools and environments, running detections while data is moving, and giving customers more control over retention and storage choices. ReliaQuest says this approach is intended to preserve the outcomes security teams expect from established systems, including investigations, long-term storage and reporting, while changing the underlying architecture.

"We are in the middle of the great re-architecture of cybersecurity," said Brian Murphy, founder and chief executive officer of ReliaQuest.

"The most advanced security teams are rethinking how they store data, how they detect threats, and how quickly they can take action to stay ahead of agentic attacks. GreyMatter SIEM-Less provides the optionality and modularity they need to build the fastest, most accurate and cost-efficient architecture possible," Murphy said.

Market pressure

The launch comes as cybersecurity suppliers respond to the growing use of artificial intelligence by attackers and defenders alike. Vendors have been trying to show that their products can cut investigation times, reduce operating costs and help analysts work across fragmented infrastructure without adding complexity.

ReliaQuest argues that traditional SIEM deployments can create friction because data must be transported, transformed and stored before detections are applied. In environments where telemetry is spread across cloud platforms, on-premise systems and third-party services, that sequence can introduce delays and add storage and processing costs.

By contrast, GreyMatter SIEM-Less lets organisations detect threats at source, in transit or in storage, depending on how they design their environment, according to ReliaQuest. Customers can also drop unnecessary data before retention rather than sending all telemetry through a centralised process by default.

This approach may appeal to large enterprises under pressure to control cybersecurity budgets while maintaining visibility across diverse systems. It also fits a broader move towards modular security operations, in which companies mix analytics, data storage and response tools rather than relying on one platform to handle every stage.

ReliaQuest has built its recent market position around that message of integration across existing tools. It says GreyMatter uses a "Universal Translator" to normalise telemetry from different vendors without requiring centralised data storage, alongside detection methods that can operate before indexing or storage takes place.

That model attempts to address one of the persistent complaints about legacy SIEM projects: they can be expensive to scale as logging volumes increase. For large organisations collecting data from endpoints, networks, cloud workloads, identities and software services, the cost of ingesting and retaining everything in one place has become a recurring issue.

ReliaQuest says security teams still want the established functions associated with SIEM platforms, including saved searches, reports, investigations and long-term record-keeping. Its new product is designed to keep those functions available while changing where data resides and when detections run.

Founded in 2007, the company has focused on managed detection, response and security operations technology. With GreyMatter SIEM-Less, it is making a direct case that the next phase of security operations will depend less on centralised SIEM architecture and more on flexible telemetry handling tied to faster detection.

Security teams can also interface with stored telemetry directly from GreyMatter in natural language to run and save searches, build reports, and conduct investigations and hunts, while preserving response actions from the same console.