Ireland and the United Kingdom enterprise technology-change research

PT-2026-113 · dossier edition · 26 July 2026

PlatformTrace

Enterprise platform change across Ireland and the United Kingdom.

SIEM platform migration · Migration completed and operational · High confidence

Nationwide replaces its previous SIEM with Microsoft Sentinel

Nationwide Building Society migrated from its previous SIEM to Microsoft Sentinel and the Sentinel data lake for security-data ingestion, retention, detection, investigation, automation and response.

Organisation
Nationwide Building Society
Predecessor
previous incumbent SIEM solution with limited innovation and fragmented security visibility
Destination
Microsoft Sentinel and Sentinel data lake
Workload
security-data ingestion, retention, detection, investigation, automation and response
Stage
Migration completed and operational
Retirement status
The previous SIEM was replaced for the named security-operations scope; the broader security-tool estate is not claimed retired.
Confidence
High
Next trigger
A dated cutover, formal retirement statement or material later implementation milestone.
Evidence boundary: The source supports replacement of the previous SIEM for the named security-operations scope. It does not name the predecessor vendor, disclose the exact cutover date or prove retirement of every security tool.

Programme context

Nationwide Building Society migrated from its previous SIEM to Microsoft Sentinel and the Sentinel data lake for security-data ingestion, retention, detection, investigation, automation and response.

Why this matters: This record identifies a named Irish or UK organisation, a bounded predecessor state, a destination platform, an affected workload and a source-stated operational stage.

Migration timeline

Date or stageMilestoneWhat changedEvidence status
Before migrationIncumbent SIEMNationwide operated a previous SIEM with limited innovation and fragmented visibility.Source-stated predecessor
Completed programmeSIEM migrationNationwide migrated the named security-operations workload to Microsoft Sentinel and the Sentinel data lake.Source-stated completion
3 Oct 2025Dated sourceMicrosoft published the customer story.Dated first-party evidence

Workload migration matrix

WorkloadPredecessorDestinationStatus by 26 Jul 2026
security-data ingestion, retention, detection, investigation, automation and responseprevious incumbent SIEM solution with limited innovation and fragmented security visibilityMicrosoft Sentinel and Sentinel data lakeMigration completed and operational

Implementation and architecture

  • Microsoft Sentinel provides SIEM detection, investigation, automation and response capabilities.
  • Sentinel data lake supports security-data ingestion and retention.
  • The publication claim is bounded to the named security-operations workload.

Known unknowns and contradictions

  • The predecessor SIEM vendor and product.
  • The exact production cutover date.
  • The complete residual security-tool inventory.

No missing fact is inferred to broaden the source-supported platform-change claim.

PlatformTrace analysis

The source supports replacement of the previous SIEM for the named security-operations scope. It does not name the predecessor vendor, disclose the exact cutover date or prove retirement of every security tool.

Performance, cost, uptime and operational outcomes remain attributed source claims unless independently stated otherwise.

Evidence ledger

  1. Nationwide Building Society — Microsoft customer story, 3 October 2025

    Dated Microsoft customer story explicitly describing Nationwide's decision and migration from its previous SIEM to Microsoft Sentinel and the Sentinel data lake.

Approval: Issue #47 standing publication authority and the completed 26 July 2026 five-lane central filter.

Corrections and updates

26 July 2026 — Initial long-form Verified dossier published from the completed five-lane Ireland/UK intake and corrected central filter. Later milestones will be appended rather than silently replacing this state.