Friday SIEM post. This week: how many times has SIEM survived the "SIEM is dead" wave?
I saw a post this week about email being dead. Email is still here. Same with SIEM. Every few years a new category shows up to bury it, and every time SIEM is still standing.
The waves:
UEBA (2014 to 2016). Gartner coined the term. The pitch was that behavioral analytics and ML would make rules-based correlation obsolete. People forget this one, but it was the first real "SIEM is dead" push.
XDR (2018 to 2021). The loudest wave. Nir Zuk of Palo Alto Networks coined the term in 2018 at Ignite, and Cortex XDR shipped in early 2019. Palo Alto's line was literally that SIEM needs to be eliminated and replaced.
Security Data Lake / decoupled SIEM (2020 to 2023). The argument: SIEM is just an overpriced database. So decouple storage from analytics, bring your own lake, and put a detection engine on top.
And now Gartner has a name for the next one: ISOC, the integrated SOC. SIEM, SOAR and AI SOC in one platform, positioned as the next-gen SIEM.
Notice the difference. UEBA, XDR and the data lakes all claimed to kill SIEM. ISOC does not. The new term IS the SIEM.
SIEM does not die. It absorbs the challenger and takes its name.
So will ISOC be the SOC revolution everyone wants? My bet: no. Not because the tech is bad, but because the thing that kills a SIEM was never the category.
Like Rafał Kitab said in a recent post https://lnkd.in/dRQMFsZN your SIEM won't die because of a new term. Your processes and your people can kill it, through bad implementation.
Side note: on the SecOps Unpacked list I now track 36 vendors that pair SIEM with AI SOC. The category is not dying. It is eating its challengers.
Originally posted on LinkedIn on 29 May 2026.
Read the original post and the comments.


