Pricing

Pricing based on coverage, complexity and response requirements.

MDR scope is shaped by endpoint count, servers, identities, log sources, retention, integrations, service hours and the response actions included.

Service options

Choose a starting point, then scope it properly

The packages below describe service levels, not a rigid product catalogue. Final pricing follows technical discovery because environments vary significantly in size and complexity.

Security Assessment

For organizations that need a clear current-state review and prioritized roadmap.

Custom
Fixed scope after discovery
  • Asset and control review
  • Monitoring coverage assessment
  • Incident readiness review
  • Prioritized recommendations
Request scope

Custom Managed Security

For larger, cloud-heavy or technically complex environments.

Custom
Annual or multi-year agreement
  • Additional endpoints and log sources
  • Cloud and application monitoring
  • Custom retention and dashboards
  • Expanded response procedures
  • Resilience and recovery workstreams
Discuss requirements

Reference package

Example cost structure

ItemDescriptionReference cost
Annual MDR serviceUp to 30 virtual machines, up to 1,000 client computers through agreed monitoring, Microsoft 365 access activity and firewall integrationCAD $66,000
ImplementationDeployment, configuration, integration, testing and trainingCAD $5,000
Implementation discountReference discount applied to implementationCAD -$5,000
Total reference costAnnual service plus discounted implementationCAD $66,000

This is a representative estimate based on the scope above, not a public warranty of final price. Pricing may change when requirements, products, licensing, retention, integrations or third-party costs change. A 10% discount may be available with a three-year commitment, subject to contract terms.

What affects price

The main scoping variables

We confirm these inputs before issuing a final statement of work and price.

  • Number and type of endpoints, servers and cloud workloads.
  • Microsoft 365 licensing and available audit data.
  • Firewalls, network appliances and additional log sources.
  • Data retention, ingestion volume and SIEM licensing.
  • Required response actions, access and customer approval model.
  • Implementation complexity, locations and change constraints.

Get a quote that matches your environment.

Provide approximate endpoint, server, Microsoft 365 and firewall counts. We will use them to prepare the discovery discussion.

Request a quote