The Challenge
Betsoftware’s security team was operating under conditions most modern security operations know well: their SIEM costs kept climbing based on how much data they ingested, not how useful that data actually was. Every new data source they wanted to monitor meant increased licensing spend, which made it harder to justify expanding coverage even when the business needed broader visibility.
BETSOFTWARE'S CHALLENGE
Rising costs without rising value
The team was paying premium rates to store and process large volumes of low-fidelity data that contributed little to detection or investigation outcomes.
Cold storage they couldn’t use
Data retained for compliance sat in storage but was not practically searchable. When analysts needed to investigate historical data for investigations or forensic work, it was slow, expensive, and operationally painful.
New data sources were too costly to add
Sources that would have materially improved threat visibility stayed out of scope because the cost model made onboarding them unworkable.
The bottom line was that the team’s security capabilities were being shaped by infrastructure limitations rather than security priorities. Improving coverage, speeding up investigations, or even evaluating alternative SIEM platforms would have meant either significant new spending or a disruptive rip-and-replace.
The Solution
Betsoftware deployed Abstract between its data sources and its existing SIEM, giving the team control over what data reached the SIEM and how much of it. The rollout was incremental and non-disruptive: existing SIEM operations continued without interruption while Abstract was connected and the team started getting visibility into their data flows, volumes, and quality.
Abstract's no-code pipeline interface allowed the security team to identify and act on reduction opportunities without needing dedicated data engineering support. Out-of-the-box rules filtered out low-value data such as debug logs, redundant telemetry, and benign events before they hit the SIEM billing meter. Enrichment was applied at the pipeline level as well, adding identity, asset, vulnerability, and threat intelligence context to events before routing, so that what did reach the SIEM was higher fidelity and more immediately useful.
Long term storage was addressed through Abstract's tiered data architecture, which allows data to be routed to appropriate storage destinations based on value and urgency rather than defaulting everything to high-cost hot storage. Data retained for compliance became searchable and queryable for historical investigation without requiring expensive reingestion or rehydration into the SIEM.
For time-sensitive data sources, streaming analytics run directly in the pipeline, enabling real-time correlation, behavioural anomaly detection, and threat intelligence matching at the point of ingestion. This moves detection earlier in the process, reducing dwell time and getting investigations started (and finished) sooner.
The Outcomes
Directly cutting licensing costs at scale and immediately improving the team’s commercial position.
Analysts can now run historical threat investigations and forensic work without paying to reingest data or deal with heavy operational overhead.
That were previously too expensive to send to the SIEM are now onboarded, materially expanding threat coverage without expanding cost.
Time-sensitive data sources are now analyzed in real time at the pipeline level, reducing dwell time and getting threats caught before they'd even have reached the SIEM under the old model.
Abstract's decoupled architecture lets Betsoftware route data to multiple destinations simultaneously, evaluate alternative platforms with live data, and make technology decisions based on merit rather than migration cost.
Driven by reduced SIEM licensing spend, improved analyst efficiency, and the removal of hidden costs around cold storage and new source onboarding.
The Strategic Shift
Before Abstract, Betsoftware’s security architecture was primarily guided by its SIEM vendor. Key decisions about data collection, retention, and routing were shaped by ingestion-based pricing models. While this structure provided stability, expanding coverage inevitably increased costs, and transitioning to a new vendor would have meant a major architectural overhaul. The security team's flexibility was boxed in by the commercial model as much as by any technical limitation.
Abstract changed that by putting a security data pipeline at the core of the architecture. Betsoftware now manages its data strategy independently of any single vendor, and the SIEM is now just one of several optional destinations instead of the default destination for everything.
New vendors can now be evaluated with live data running in parallel, making migration a deliberate business decision with a clear timeline rather than an open-ended risk. The security team has real commercial leverage, and the infrastructure can evolve with the threat landscape and vendor market without requiring a full overhaul every time something needs to change.
Results at a Glance
73%
Data Volume Reduction
Restored
Cold Storage Searchability
Onboarded
New Data Sources
Active
Streaming Threat Analytics
Eliminated
SIEM Vendor Lock-in
About Betsoftware
Betsoftware is a technology and gaming platform business operating within the Hollywood Bets Group, one of South Africa's largest sports betting and gaming operators. Founded in 2000, the group has grown from a single retail branch in Durban to a multi-channel operator with over 6,000 employees, a national retail network, and an presence spanning the UK, Ireland, and Mozambique. Betsoftware operates as a high-volume, data-intensive business unit where the scale of customer activity across online and retail channels generates substantial security telemetry, making always-on visibility, compliance, and real-time operational integrity critical requirements.
About Abstract
Abstract is the pioneer of AI-Gen Composable Security Operations, a streaming-first, AI-native security operations platform founded by leaders from ArcSight, Bank of America, Mandiant, and Palo Alto Networks. Abstract sits between an organisation's data sources and its downstream destinations, giving security teams control over how data is ingested, enriched, routed, and acted upon — detecting threats at the point of ingestion and eliminating the vendor lock-in that makes traditional SIEM migration prohibitively expensive. The company has raised nearly $50 million in funding and recorded 380% ARR growth in 2025.
Role of IGNISOVA
IGNISNOVA worked with Betsoftware's security team from the outset, sourcing Abstract Security as the right fit for the data volume and cost challenges the team was facing. Rather than a transactional introduction, IGNISNOVA remained embedded throughout the proof of concept, working alongside the security team to validate that Abstract's pipeline architecture could deliver the reduction and searchability outcomes the business needed before any commercial commitment was made. Once the technical case was proven, IGNISNOVA led the commercial negotiations, structuring terms that reflected the value Abstract had demonstrated during the POC rather than list pricing.
This ensured Betsoftware secured a deal that made sense on both fronts: technically validated and commercially sound. The result, a 73% reduction in data volume and restored cold storage searchability, reflects not just the technology but the rigour applied in getting the deployment and the deal right from day one.