With regulations such as PCI, Memo 22, Sarbanes-Oxley and ISO27001 increasingly demanding effective security monitoring of organisations’ IT infrastructures, security managers are finding that they simply do not have the time or resources to perform this to an acceptable level. The level of complexity involved and the sheer amount of time required to effectively react to security incidents, means