facebook
  • Home
  • News
  • The evolution of security: development and certification stages of NTechnology SIEM

The evolution of security: development and certification stages of NTechnology SIEM

12 August 2026

In the era of global digitalization and the complication of the cyber threat landscape, the development of the NTechnology SIEM information security event management system has become an important strategic project of the National Traffic Exchange Center (NTEC) republican unitary enterprise. The creation of a Security Information and Event Management class system from scratch transferred NTEC to the status of a vendor of high-load information security systems, demonstrated tremendous engineering potential and confirmed the technological maturity of the company.

Background: digital sovereignty

The adoption of Decree of the President of the Republic of Belarus No. 40 "On Cybersecurity" and Order of the Operational-Analytical Center under the President of the Republic of Belarus No. 130 established a systemic approach to building national cyber defense. Strict requirements were established for the creation of departmental and corporate cybersecurity centers (SOC), as well as for mandatory monitoring of incidents. The current regulatory framework obliges enterprises to provide centralized storage of security events throughout the year and deploy effective tools to quickly identify cyber attacks.

Thus, it became necessary to create a domestic SIEM system that meets both the requirements of the law and the request of users:

  • Technological independence: Traditional foreign SIEM systems carry the risks of excessive functionality, sanctions pressure and lack of adaptation to the national IT infrastructure.
  • Economic feasibility: Enterprises of the Republic of Belarus needed an affordable solution with local technical support and regular updating of knowledge bases for current threats.

NTEC laid these requirements as the basis for the terms of reference and quickly prepared NTechnology SIEM for certification tests.

NTechnology SIEM certification is not a formal receipt of a form, but a multi-stage process of code verification, its functionality and compliance with the requirements of technical regulations. Each stage of product modernization pursued specific goals and recorded a new development milestone.

v1.0.0 First recognition and verification of the underlying architecture

In less than a year of active development, NTechnology SIEM has gone from an idea to a full-fledged information protection tool. The Operational Analytical Center under the President of the Republic of Belarus issued a certificate of compliance with the requirements of TR 2013/027/BY for the first target batch on October 8, 2024.

Obtaining this document gave an important start for product development:

  1. Market access: Implementation of NTechnology SIEM has become possible in certified information security systems, where only certified software can be used.
  2. Proof of reliability: laboratory tests have proven the stability of the basic functions of the SIEM system, the absence of vulnerabilities in the code and the security of the selected architecture.

The successful debut of NTechnology SIEM in October 2024 proved the viability of NTEC's chosen engineering concept and laid a solid foundation for the subsequent rapid scaling of the product.

v1.2.3 Major league security and development

Soon NTechnology SIEM made a qualitative leap - on January 14, 2026, the software package was re-certified, which radically changed the status of the product:

  • Highest protection class: due to the accuracy of differentiation of user rights, an uncompromising level of security and control of the integrity of the source code, NTechnology SIEM is allowed to be introduced into information systems of the 1st protection class, where state secrets are processed.
  • Mass production: Instead of certifying limited batches, NTEC validated the quality of product development processes throughout the entire life cycle, including design, development, testing, deployment and support.
  • Upgrading the base platform: added the ability to end-to-end user authentication using the LDAP/LDAPs protocol, integrated a full-fledged report designer, introduced flexible visualization, and significantly redesigned asset and incident management modules.

This stage proved that NTechnology SIEM has outgrown the status of a young promising project and has transformed into a mature and replicable solution for protecting critical digital infrastructure of a national scale.

v2.0.0 Deep storage refactoring

Along with the popularity of the product, the volume of processed data also grew: the load on the system increased tenfold. The development team made an ambitious decision - to revise the storage architecture and transfer NTechnology SIEM to a high-performance ClickHouse DBMS. Modernization of this kind required re-certification, and on July 8, 2026, NTEC noted another important stage in the development of its own development.

The release of a new major version of NTechnology SIEM marked a qualitative technological leap and brought a number of fundamental changes:

  1. Multiple performance gains: the first version of the system could handle up to a thousand events per second, and now NTechnology SIEM can withstand ten times the load - up to 10,000 EPS.
  2. Storage optimization: thanks to the new NTechnology SIEM architecture, event storage has been reduced by 4 times compared to the previous version, and by 8 times compared to standard open-source solutions.
  3. Decentralized agentless collection: it is possible to install collectors in branches and closed circuits for unidirectional transmission of information security events from various sources, including databases, specialized network equipment, reading from Windows OS log files.
  4. Advanced functionality: adaptive web interface and interactive prompts, flexible dashboard and customizable tables, multiple groupings and sorts, background tasks and asset monitoring have significantly improved the user experience.

The modernization significantly reduced the requirements for equipment on the customer side, which significantly saved government and business funds. At the same time, the speed of performing complex search queries and the depth of retrospective analysis have increased, which allowed information security analysts to identify threats and respond to incidents almost instantly in the face of an avalanche-like growth of cyber threats.

NTEC synergy: a single contour of national cyber defence

The development of NTechnology SIEM takes place in close integration with other elements of the NTEC cybersecurity ecosystem:

  1. NTEC Cyber Security Center: The country's first certified SOC continuously monitors the network and analyzes incidents on critical customer infrastructure. Own practical experience and operational data from the National Cybersecurity Center are transformed into current normalization and correlation rules in NTechnology SIEM. As a result, customers receive a product adapted to the current landscape of cyber threats in Belarusian realities.
  2. Development team "NTechnology": local engineering team guarantees clients prompt technical support and expert advice. The status of a domestic developer allows you to flexibly modify the functionality of the system to individual technical requirements of a particular customer.
  3. NTEC "CyberRing" cyber polygon: the platform acts as the main testing ground for information security tools. In the course of practical cyber training, specialists practice their skills in detecting hacker attacks using NTechnology SIEM analytical tools in conditions as close as possible to real ones.
  4. International Education Center NTEC "ROZUM": practice-oriented training in the administration and operation of NTechnology SIEM, as well as general skills in quickly detecting anomalies and responding to computer attacks, solves the issue of the shortage of qualified information security specialists in the Belarusian labor market.

NTEC offers the market a complete protection cycle: from developing personnel competencies to instantly repelling complex targeted attacks. Belarusian enterprises receive not just certified software, but a reliable technological shield adapted to national standards and regulator requirements.

On the scale of the Republic of Belarus, the emergence and systematic evolution of the domestic NTechnology SIEM system is critical for strengthening the country's digital sovereignty. Regular confirmation of compliance with strict state standards records key milestones in the architectural growth of the system and a steady increase in the product quality bar.