Measured by users across key metrics
Five evaluators scored LogLM on false negatives, false positives, time to detect and time to adapt. Below, their results, their words, and a model that converts them into the return for your own SOC.
Across four key measurements
Thanks to the rise of AI powered attackers, the still important false positive rate is no longer sufficient to determine the effectiveness of a cybersecurity system. Today the ability of a system to detect all attacks, quickly, with a minimal amount of time and money required for ongoing operations has become equally important.
| Evaluator | False neg | False pos | MTTD | To adapt |
|---|---|---|---|---|
| BNYGlobal custodian bank | 0.9% | 2.1%from 52% | <3 min | 15 minfine tuning |
| Deutsche TelekomTelecommunications | 2.1%NGFW 72% | ~1.3% | <1 min | 0 to 5 minfine tuning |
| Top four bankGlobal bank | 0.7% | <1%from 73% | <1 min | 0 minzero shot |
| TAC for OTOperational technology | 0%NGFW saw none | 2% | 2 min | 0 minzero shot |
| On TAC's WS3 water-plant range, LogLM surfaced a rogue HMI with no signature, device rule, or fine tuning written for that endpoint. The TAC independently confirmed that endpoint as the source of the malicious behavior. | ||||
| Mega CDN vendorInternet infrastructure | 2.1% | 0.08% | 1 min | 0 minzero shot |
Scores reported at zero shot unless the time to adapt column shows fine tuning. False negatives measured against the labelled evaluation set for each environment. Next generation firewall comparison shown where the customer ran one in parallel.
DeepTempo is delivering a powerful analyst-assistant capability that adds true plant-operating-state semantic analysis, pairing its established IT analysis with meaningful, plant-aware OT analysis.
Steve Hutchinson, Director of Research, Technology Advancement Center
LogLM bested our in-house models before fine tuning, and once fine tuned it performed at well below a 1% false positive rate.
Analytics lead, cyber, top four bank
Vigil is simple to customize, and has allowed us to use our own AI models for reasoning, saving costs and increasing our confidence versus the black box AI SOCs we evaluated.
Threat investigation lead, North American carrier
Cost per event as volume climbs
A SOC metered by token spend can be attacked through its own bill. Bounded inference at the data layer and routed execution in Vigil close that path.
Your environment, against the evaluations
Defaults come from the sector nearest yours. Change any of them.
Triage at 20 minutes per alert, analyst capacity 1,800 hours, loaded rate $85. Residual false positives at the rate measured in your sector. SIEM and inference at $2,000 per TB per year. AI SOC investigation at $0.40 per alert. Detection engineering at 0.12 FTE per analyst. Breach cost and frequency scaled by site size. Conservative applies a 0.6 factor throughout.
Take the numbers with you
A one-page business case carrying your inputs, our assumptions and the arithmetic. Pricing is small, medium or large, and every license carries LogLM, Vigil and the management code.
The one-page business case for is heading to , carrying every input from the model above.
Request a Demo