Security & Continuity

24/7 Managed SOC & MDR

  • Multi-year savings
From $11,000.00 /mo per organization or $132,000/yr

Pay monthly or annually — the contract value is the same.

Save 5% with a 2-year term or 10% with a 3-year term.

Round-the-clock security monitoring, threat hunting and incident response across endpoints, identities, cloud and network.

About this service

  • 24/7/365 monitoring, triage and investigation by our SOC analysts
  • Managed detection and response on your existing EDR, with pre-approved containment actions
  • Managed SIEM with log ingestion included: endpoints, identity, email, cloud and firewalls
  • Proactive threat hunting and detection rules mapped to MITRE ATT&CK
  • Incident response hours included every year, with a written report for every confirmed incident

Plans at a glance

Compare all features

About 24/7 Managed SOC & MDR

24/7 Managed SOC & MDR gives your company a security operations center without hiring and retaining a round-the-clock team. Our analysts monitor alerts from your endpoints, identities, email, cloud platforms and network devices, investigate what matters and take pre-approved containment actions — such as isolating a device or disabling an account — when an attack is in progress.

We work with the security tools you already have, such as Microsoft Defender, CrowdStrike Falcon, SentinelOne or Symantec Endpoint Security, and collect logs into a managed SIEM with ingestion included in your tier. Detection rules are mapped to the MITRE ATT&CK framework, tuned to your environment and reviewed every month so analysts spend their time on real threats rather than noise.

Every confirmed incident comes with a written timeline, root cause and recommendations. Each tier includes incident response hours for deeper investigation and recovery support, and higher tiers add a named security lead who briefs your leadership on trends, risks and improvements.

Compare plans

All prices in USD, per organization at the 1-year rate. Pay monthly or annually — the contract value is the same. Swipe the table sideways to see every plan.

Plan comparison for 24/7 Managed SOC & MDR
Feature Business Professional Recommended Enterprise
Price $11,000.00 /mo per organization or $132,000.00/yr $66,000.00 /mo per organization or $792,000.00/yr
With a 3-year term $9,900.00/mo Save 10% or $118,800.00/yr $59,400.00/mo Save 10% or $712,800.00/yr
Best for For mid-size organizations that need 24/7 eyes on endpoints and identities. A full SOC extension with deep hunting, detection engineering and response.
What’s included
  • Up to 1,000 endpoints and their user identities
  • 24/7 monitoring, triage and pre-approved containment
  • Managed SIEM with 25 GB/day ingestion, 90 days searchable
  • 30-minute triage target for critical alerts
  • 40 incident response hours per year
  • Monthly security report and review call
  • Up to 7,500 endpoints and their user identities
  • Everything in Professional
  • Managed SIEM with 200 GB/day ingestion and 1 year searchable
  • 10-minute triage target for critical alerts
  • Weekly threat hunting and custom detection engineering
  • 250 incident response hours per year and an annual tabletop exercise
  • Dedicated analyst pod that knows your environment
Order

Billed monthly · 1-year term

Customize billing, term & quantity (Plan: Business)

Billed monthly · 1-year term

Customize billing, term & quantity (Plan: Enterprise)

Specifications

Specifications for 24/7 Managed SOC & MDR
SKUTS-SEC-505
CategorySecurity & Continuity
PricingPer organization, per year; payable monthly or annually
ContractAnnual commitment; 1-, 2- or 3-year term
BillingMonthly or annual invoicing; same contract value
Endpoints coveredUp to 1,000 / 3,000 / 7,500 depending on tier
Log ingestion25 / 75 / 200 GB per day into the managed SIEM
Critical alert triage30 / 15 / 10-minute target, 24/7
Incident response40 / 100 / 250 hours per year included
TeamTier 1–3 analysts, threat hunters, detection engineers and incident responders
Not includedEDR licenses (see Symantec Endpoint Security Complete Licensing) and litigation-grade forensics
Lead timeMonitoring live within 30 days (phased onboarding)

Frequently asked questions

Do we need to replace our security tools?

No. We work with leading EDR platforms, including Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne and Symantec Endpoint Security, plus common firewalls and identity providers. EDR licenses are not included; if you have none, we can supply Symantec Endpoint Security Complete or recommend an alternative.

What actions will your analysts take without asking?

Only the containment actions you approve during onboarding, such as isolating an endpoint, disabling a compromised account or blocking a malicious indicator. Everything else is discussed with your on-call contact first, and every action is logged and reported.

What if we exceed our endpoint band or log volume?

We review volumes every month. If you grow beyond your tier, you can move up a tier at any time, prorated to your renewal date. We never stop ingesting logs without telling you first.

Can we pay monthly, and how do we leave?

Yes. Monthly invoices spread the same annual commitment over 12 payments and do not shorten it. To end the service, give written notice at least 30 days before renewal; we export your logs, detection rules and documentation and hold a handover call with your new provider.

Have another question? Ask a solutions architect