38,000 alerts a day, most of them the same incident
The CERT (an anonymized, fictional national CERT in this demo) coordinates incident response for public administrations and operators of essential services. Its 34 analysts work a 24/7 rotation and receive signals from fourteen feeds: two SIEM platforms, endpoint detection from constituent organizations, an Elasticsearch log archive, threat-intelligence feeds, public code repositories and monitored open channels where stolen credentials are traded.
Each feed raised its own alerts. A single phishing campaign could appear as hundreds of SIEM events, dozens of EDR detections and a handful of open-source mentions, each in a different console. On a typical day 38,400 alerts reached the analyst queues. The median time to acknowledge a genuinely new incident was over four hours, simply because it was buried.
Analyst fatigue was the real cost. Turnover in the night shift was high, and post-incident reviews kept finding that the first signal had been there hours earlier, unread.
> We did not need more alerts. We needed fewer, better incidents. That is exactly what changed.
National CERT · EU
How the national CERT set up Kimo
Kimo Defense Intelligence runs on the CERT’s sovereign private cloud, with no dependency on external services. Each feed is connected through native connectors or the existing Kafka pipeline, and every signal is normalized into a common schema: entity (host, account, domain, IP), technique, source, constituent and time.
A correlation model clusters signals that share entities within time windows, deduplicates repeats and attaches open-source context such as leaked credentials or exploit code published for the relevant vulnerability. Clusters are scored by severity, constituent criticality and novelty. Only clusters above threshold become incidents in the queue; the rest remain searchable, never deleted.
Analysts see one incident with its full timeline instead of hundreds of alerts. Ask Kimo answers questions like “Which constituents saw this domain in the last 72 hours?” in seconds, against data that never leaves the CERT’s infrastructure. Suppression rules are versioned and reviewed weekly, so noise reduction never becomes a blind spot.
- Week 101/03Fourteen feeds normalized
SIEM, EDR, Elasticsearch, threat intel and open sources in one schema.
- Week 302/03Correlation & scoring
Entity clustering, deduplication and OSINT enrichment tuned on past incidents.
- Week 603/03One incident queue
Analysts switch from feed consoles to correlated incidents, 24/7.

