Betsoftware’s security team was operating under conditions most modern security operations know well: their SIEM costs kept climbing based on how much data they ingested, not how useful that data actually was. Every new data source they wanted to monitor meant increased licensing spend, which made it harder to justify expanding coverage even when the business needed broader visibility.
The bottom line was that the team’s security capabilities were being shaped by infrastructure limitations rather than security priorities. Improving coverage, speeding up investigations, or even evaluating alternative SIEM platforms would have meant either significant new spending or a disruptive rip-and-replace.
Betsoftware deployed Abstract between its data sources and its existing SIEM, giving the team control over what data reached the SIEM and how much of it. The rollout was incremental and non-disruptive: existing SIEM operations continued without interruption while Abstract was connected and the team started getting visibility into their data flows, volumes, and quality.
Abstract's no-code pipeline interface allowed the security team to identify and act on reduction opportunities without needing dedicated data engineering support. Out-of-the-box rules filtered out low-value data such as debug logs, redundant telemetry, and benign events before they hit the SIEM billing meter. Enrichment was applied at the pipeline level as well, adding identity, asset, vulnerability, and threat intelligence context to events before routing, so that what did reach the SIEM was higher fidelity and more immediately useful.
Long term storage was addressed through Abstract's tiered data architecture, which allows data to be routed to appropriate storage destinations based on value and urgency rather than defaulting everything to high-cost hot storage. Data retained for compliance became searchable and queryable for historical investigation without requiring expensive reingestion or rehydration into the SIEM.
For time-sensitive data sources, streaming analytics run directly in the pipeline, enabling real-time correlation, behavioural anomaly detection, and threat intelligence matching at the point of ingestion. This moves detection earlier in the process, reducing dwell time and getting investigations started (and finished) sooner.
Before Abstract, Betsoftware’s security architecture was primarily guided by its SIEM vendor. Key decisions about data collection, retention, and routing were shaped by ingestion-based pricing models. While this structure provided stability, expanding coverage inevitably increased costs, and transitioning to a new vendor would have meant a major architectural overhaul. The security team's flexibility was boxed in by the commercial model as much as by any technical limitation.
Abstract changed that by putting a security data pipeline at the core of the architecture. Betsoftware now manages its data strategy independently of any single vendor, and the SIEM is now just one of several optional destinations instead of the default destination for everything.
New vendors can now be evaluated with live data running in parallel, making migration a deliberate business decision with a clear timeline rather than an open-ended risk. The security team has real commercial leverage, and the infrastructure can evolve with the threat landscape and vendor market without requiring a full overhaul every time something needs to change.