CyberTRIZPEDIA

Security Logging vs System Performance

Route high-value OT security events to an off-device SIEM to meet NIS2 and IEC 62443 logging obligations without degrading legacy system performance.

CyberTRIZ analysis · Seveso contradiction CY011 · one of 8,235 worked contradictions published by CyberTRIZ.AI

Regulations

Business Context

Comprehensive security logs provide valuable information for incident

investigation, regulatory compliance, and threat detection. Extensive

logging, however, consumes storage, processing capacity, and network

bandwidth.

The Contradiction

More security logging improves forensic capability.

Higher system performance improves operational reliability.

Why It Exists

Large volumes of security events can overload legacy OT systems that

were not originally designed for extensive cybersecurity monitoring.

Direction

Collect and prioritize high-value security events while centralizing log

analysis through dedicated Security Information and Event Management

(SIEM) platforms.

TRIZ principles applied

P25 Self-ServiceP06 UniversalityP05 MergingP06 UniversalityP01 SegmentationP13 The Other Way Around