- IBM covers the technology layer well: QRadar SIEM, QRadar SOAR (the product formerly sold as Resilient) and X-Force threat intelligence.
- IBM sold its QRadar SaaS business to Palo Alto Networks in 2024. On-premises QRadar continues, but get roadmap commitments in writing before you buy.
- Technology is roughly a third of the build. The 24x7 rota, log source onboarding and detection tuning decide whether the SOC catches anything.
- Assessors do not ask which SIEM you bought. They ask for coverage maps, retention evidence and proof that response has been exercised.
IBM can sell you most of a SOC's technology layer. It cannot sell you the part that decides whether the SOC catches anything: analysts on a sustainable rota, the right log sources onboarded and parsed, and a detection lifecycle that keeps rules current as the estate changes. Price all three from the start, or the project stalls at the technology stage, which is where most stalled UAE SOC builds are sitting.
What IBM actually supplies
The IBM SOC stack rests on three products. QRadar SIEM handles collection, correlation and alerting. QRadar SOAR, which IBM acquired as Resilient, adds case management and response playbooks. X-Force supplies threat intelligence, and IBM Consulting sells the surrounding services, from incident response retainers to fully managed operations.
QRadar's strengths are real. It is mature at on-premises scale, the regional talent pool knows its correlation engine, and its DSM library parses most enterprise log sources without custom work. For a UAE bank or government entity with a heavy on-premises estate and a data residency constraint, that profile still fits.
Licensing needs eyes open. QRadar is metered in events per second and flows per minute, so an unfiltered logging estate inflates the bill quickly. Size from your measured volumes, document the filtering assumptions, and treat any figure produced from a questionnaire as a guess.
The 2024 change nobody should skip
In 2024 IBM sold its QRadar SaaS assets to Palo Alto Networks, which offers those cloud customers a migration path to Cortex XSIAM. On-premises QRadar remains an IBM product with continued support, but the sale tells you where IBM judged the cloud SIEM market to be heading, and it was not towards QRadar.
For a UAE buyer this cuts two ways. If your constraint is data residency and your estate is on-premises, QRadar remains a defensible choice, and the installed base across the Gulf means experienced QRadar analysts are easier to hire than specialists in most rival platforms. If you are cloud-first, ask IBM to commit its on-premises roadmap to writing for your full contract term, and evaluate the alternatives honestly before standardising on a platform whose SaaS future now belongs to a competitor.
The two-thirds no vendor ships
A genuine 24x7 rota is the expensive part. Cover the shift patterns, annual leave and attrition and you need eight to twelve analysts before you add a SIEM engineer, a detection developer and someone senior enough to say no to the business. In the Gulf market those people are scarce and mobile: salary bands move quickly, and a trained QRadar analyst is a recruitment target for every MSSP in the region. Budgeting for retention, training and progression is not an HR nicety. It is the difference between a SOC and a room of vacancies.
Process is the other missing shipment. Log source onboarding is a project in its own right: custom applications need parsers built and maintained, network teams need persuading to forward the right telemetry, and every source needs an owner who notices when it goes quiet. Detection content needs a lifecycle of build, test, tune and retire, or the default rule set generates the alert fatigue that has analysts closing offences without reading them. Alert fatigue is not a staffing problem. It is engineering debt.
What NESA-aligned assessors actually ask for
Assessors have largely stopped asking which SIEM you bought. Across NESA-aligned reviews, CBUAE examinations and ISO 27001 audits, the requests converge on operational evidence:
- a coverage map showing which critical systems feed the SOC, which do not, and who owns each gap
- log retention demonstrated against your stated policy, not asserted in a slide
- incident response runbooks that have been exercised, with dates and findings recorded
- detection and response metrics reported to someone with the authority to act on them
Build the team, or buy the operation?
Most UAE mid-market organisations cannot fill the rota, and a SOC staffed for business hours fails quietly: the attacker who lands at 2am on a Friday gets the whole weekend. The realistic options are a fully managed service, or a hybrid model where you own the platform and the data and rent the overnight shifts. Hybrid is where most regulated UAE entities land, because it keeps data in-country while making the staffing problem someone else's. The full trade-off is worked through in the managed SOC versus in-house guide.
Budget honestly across both options. Whatever the software quote says, people dominate the running cost of an in-house SOC, and the commitment scales with coverage: every hour of the week you want watched is an hour someone must be paid to watch. If the IBM stack plus the headcount is beyond reach, a leaner platform run with discipline beats a flagship run badly. A FortiSIEM deployment with fifty tuned use cases and an owned onboarding backlog will out-detect an under-staffed QRadar every week of the year.
Where UAE SOC builds stall
The failure modes repeat across the region, and none of them are technology faults:
- Onboarding stops after the easy sources. Firewalls and Windows logs arrive in month one; the core banking platform and the custom applications that actually matter are still "in progress" a year later.
- The SIEM becomes a compliance logging appliance. It retains logs, satisfies an audit checkbox, and nobody investigates anything.
- Nobody owns tuning after go-live. The integrator leaves, default rules pile up offences, and analysts learn to bulk-close.
- SOAR arrives before there is a process to automate. Playbooks encode a workflow; if the workflow does not exist, you have automated nothing and licensed it anyway.
Five questions before you sign
- Will IBM commit the on-premises QRadar roadmap to writing for your full contract term?
- Was licensing sized from measured events per second and flows, with filtering assumptions documented?
- Who owns detection content after go-live, and how many engineering hours a week are budgeted for it?
- Can you genuinely fill a 24x7 rota, and if not, which managed or hybrid model covers the nights?
- For each control an assessor will probe, which report or dashboard produces the evidence?