Cybersecurity

Events, identities and relationships on one clock.

Security data is telemetry plus relationships: something happened, and the question is what it can reach.

A detection that carries its own reachability context.

The story

A detection that carries its own reachability context.

Where it starts

Security events

Authentication, network, endpoint and application events. It is the first of 4 workloads running in Cybersecurity.

The question it raises

Reachability in the answer

A detection is read against the relationships that decide what it can touch.

Why one question is hard

From Collect to Investigate

Cybersecurity data moves through 4 stages — Collect → Inventory → Correlate → Investigate. The shapes in play are Time series, Graph, SQL, Events, JSON / documents, and answering one question means reading across all of them.

What PLOMID contributes

Security questions are traversals with a time filter. These are the parts that keep them fast and local.

The environment

Telemetry, identity, asset relationships and the cases that follow.

Events arrive continuously from endpoints and networks, identities and assets are records, and the relationships between them decide exposure. PLOMID holds the events, the entities and the relationships in one layer, so a detection carries its own reachability context.

Workload architecture

The system reading itself.

Planning, execution and transactions first — then the workloads that use them and the shapes they name.

Cybersecurity · workload architecture
Workloads

What runs against this data.

  • Security events
  • Identities and assets
  • Relationships and privilege
  • Cases and findings
Data models

The shapes those workloads read and write.

  • Time series
  • Graph
  • SQL
  • Events
  • JSON / documents
The layer

One path from a request to the data it names.

  • Planning Predicates narrow the work before it runs
  • Execution Records, fields and windows answered together
  • Transactions Readers and writers do not block each other
Surfaces

How the work reaches the layer.

  • SQL surface The query language the layer is documented in
  • Applications Services and jobs writing and reading as they run
  • Analytics & AI clients The same layer, the same access path
One environment · many workloads

What runs against cybersecurity data.

4 workload families over one set of shapes. Choose one to see what it moves and where it lands.

Authentication, network, endpoint and application events.

  • Planned once against the layer, not once per store
  • Read beside the records it shares a key with
  • Persisted under one storage contract
The data journey

How cybersecurity data reaches one layer.

Walk the path the data takes, from the environment that produces it to the questions it answers. Select a station, or a shape, to read each step.

A detection that carries its own reachability context.

Environment

The estate

Endpoints, networks and identities generating events continuously.

Events · Time series

Data models in play

The shapes, in one layer.

5 shapes carry this domain. Choose a stage to read the operation, or a shape to see every stage that handles it.

PLOMID · Cybersecurity collect · inventory · correlate · investigate Select a stage
Stage

Collect

Endpoint, network and identity events

Events · Time series

Workload map Cybersecurity workload map. Every shape on it is a surface of the layer, and each stage names the part of the operation it carries.
  • Time series Measurements and events in time order
  • Graph Relationships and traversal
  • SQL Records, keys and joins
  • Events Operational events as they happen
  • JSON / documents Documents and nested objects
Where the data goes to work

Questions a fleet asks about itself.

Each one reads telemetry with the records that explain it, from the same layer rather than a sidecar store.

Reachability in the answer

A detection is read against the relationships that decide what it can touch.

  • Events
  • Time series

Event history that is queryable

Telemetry stays in the same layer as the inventory it concerns, so history is not a separate archive.

  • SQL
  • Graph

Case evidence

Notes, findings and the events they reference stay queryable together.

  • Graph

Control over placement

Where security telemetry may live is a governance decision, not an afterthought.

  • JSON / documents
  • SQL
Deployment & residency

Where this data is allowed to run.

Sensitive telemetry often has to stay inside a boundary, which makes placement part of the security design.

Deployment, residency and control
What you build next

Real-time Analytics

Windows and aggregates over data that is still being written.

If Reachability in the answer is your question, start here.