Cybersecurity Pricing Models — How Managed Security and NOC Services Are Actually Priced

  • Home
  • Cybersecurity Pricing Models — How Managed Security and NOC Services Are Actually Priced
Cybersecurity Pricing Models — How Managed Security and NOC Services Are Actually Priced
Cybersecurity Pricing Models — How Managed Security and NOC Services Are Actually Priced
Cybersecurity Pricing Models — How Managed Security and NOC Services Are Actually Priced
Cybersecurity Pricing Models — How Managed Security and NOC Services Are Actually Priced

How this is priced · Operating since 2002

PricingHow cybersecurity services are actually metered, and what moves a quote

There are no price tiers on this page. A number without an estate behind it is fiction, and the more useful thing — the thing people are actually searching for — is how this category gets priced at all.

So this sets out what each service is metered on, which vendor list prices are genuinely published, and which of your own decisions move a quote further than the choice of provider does. Send a device and user count and you get a real figure instead.

The first question in any comparison. Establish the unit before you compare a single rate. For an estate of 200 staff and 350 devices, per-device billing charges 1.75× as many units as per-user billing at the identical rate — and neither provider has done anything dishonest.
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — NOC and SOC in scope

The meter

Why the unit matters more than the rate

One company, three billing meters, three different totals — before anybody negotiates anything.

The meter moves the number more than the rate doesOne company, three billing units, three different totals.Worked on a stated estate: 200 staff, 350 managed devices.Per user200 billable units1.00×Per device350 billable units1.75×Per log volumetracks systems, not peoplenot comparableSame company. Same provider. Same quality of service. Establish the unit before you compare any rate.The third bar is dashed because it is not on this scale at all — log volume follows systems and retention, not headcount.

Note the third bar is dashed and deliberately not scaled against the others. Log-volume pricing tracks the number of systems and the retention period rather than headcount, so a forty-person firm with heavy cloud logging can genuinely cost more to monitor than a four-hundred-person one that is mostly laptops. Comparing it to a per-seat rate is the most common budgeting error in this category.

Across the portfolio

What each service is metered on

Six services, six different units. Knowing which one you are being quoted on is most of understanding the number.

Scroll the table sideways →

Service Billing meter What grows the bill What to watch Detail
Managed IT Per user, or per device Headcount and device count A device meter grows every time someone gets a second machine. A user meter does not — which is why the two diverge as an estate matures, not on day one. Managed IT services
Managed SOC / SIEM Per log source, per GB ingested, or per asset Number of systems, and retention period Decoupled from headcount entirely. A 40-person firm with heavy cloud logging can cost more to monitor than a 400-person one that is mostly laptops. Managed SOC services
MDR / EDR Per endpoint, per month or per year Endpoint count The cleanest meter in the category, which is why it is the easiest to compare across vendors — and several publish list prices openly. MDR, EDR and XDR
VAPT Per scope, usually quoted in tester-days Application count, IP ranges, and depth Ask what a day buys. An automated scan with a cover page and a genuine manual test are both sold as “VAPT” and differ by an order of magnitude in both price and value. VAPT
Firewalls Hardware once, subscriptions annually Throughput, and which subscription bundle The appliance is the small number. The renewable security subscription over three to five years is usually the larger one, and it is where a cheap quote becomes expensive. Firewall services
NOC / NMS Per monitored device or interface Estate size and polling depth Watch the definition of “device”. A switch stack counted as one unit or as twelve is the difference between two very different bills. NOC as a Service

Published benchmarks

List prices vendors actually publish

Not our prices — third-party list prices, each with the vendor named, so you have a public reference point to compare any quote against. Tooling only; none of these includes analysts.

Vendor Product Published list price
Huntress Managed EDR $8.99 per endpoint / month
Huntress Managed SIEM $4.00 per data source / month
Blumira Detect / Respond / Automate $12 / $16 / $21 per employee / month
CrowdStrike Falcon Go / Pro / Enterprise $59.99 / $99.99 / $184.99 per device / year
Wazuh Cloud Small / Medium / Large $571 / $923 / $1,467 per month (to 100 / 250 / 500 agents)
UnderDefense MDR $10–$30 per asset / month, annual contract

These are the tooling floor, not the cost of a service. A platform licence with nobody watching it produces alerts rather than outcomes, and the people are the larger number — see the staffing arithmetic on our team page.

What you control

Six things that move a quote more than the provider does

Buyers spend most of their energy comparing rates between providers, when the larger movements are usually in decisions they own.

Retention is the largest lever on a monitoring quoteRelative to a 12-month baseline. Same estate, same sources, same provider.30 days0.30×90 days0.52×6 months0.70×12 months1.00×24 months1.62×Ask what must be searchable, and what merely has to be kept.Cold archive is a fraction of hot index, and most of what you retain is never queried.

Relative, not absolute — the ratios follow from storage and index cost scaling with the period, which is why this is the lever to settle before comparing any two quotes.

Lever

Retention period

The single largest lever on any monitoring quote. Twelve months of hot, searchable logs against ninety days is not a small adjustment — storage and index cost scale directly with it. Decide what you actually need searchable versus merely retained, because the two have very different prices.

Lever

How many log sources you send

Every added source raises the bill and not every source earns its place. Firewall, identity and endpoint logs almost always do. Verbose application debug logs almost never do, and they are frequently the largest volume in the estate.

Lever

Whether the scope is written down

An unclear scope is priced with a risk margin, because the provider is guessing. A precise asset list, a defined out-of-hours expectation and a named escalation path all reduce a quote, and they cost you nothing but an afternoon.

Lever

What you count as a device

A switch stack, a virtual host, a pair of firewalls in HA — each can reasonably be counted as one unit or several. Settle the counting rule before comparing quotes, or you will compare two numbers that were never measuring the same thing.

Lever

Year two

Threat hunting, extended retention and vulnerability management are frequently free in year one and line items afterwards. Ask for the renewal schedule up front. This is the most common cause of a relationship souring at the first anniversary.

Lever

How much you already own

If you hold current firewall subscriptions or endpoint licences, an honest provider operates them rather than replacing them. Where we do recommend a change we quote the cost to run it, not only to buy it — and those are very different numbers over three years.

Questions we get asked

Pricing, answered

Why are there no prices on this page?

Because a price without an estate behind it would be fiction, and this page used to carry exactly that — four invented tiers taken from a website template, one of which described incident response as “best for individual designers”. They have been removed. What is published instead is how each service is metered, which third-party list prices are genuinely public, and which of your own decisions move a quote most. Send us a device and user count and you get a real number.

What is the most common cybersecurity pricing model?

Per user or per device for managed IT; per log source, per GB ingested or per asset for monitoring; per endpoint for MDR; per scope in tester-days for VAPT. The important thing is that these are not interchangeable. For an estate of 200 staff and 350 devices, a per-device meter bills 1.75 times as many units as a per-user meter at the identical rate — which is the diagram at the top of this page.

Which is better, per user or per device?

Per user is more predictable and usually favours you as the estate matures, because device counts creep upward while headcount does not. Per device can be cheaper for an organisation with fewer machines than people, such as a shift-working operation with shared terminals. Neither is a trick; the mistake is comparing a per-user rate against a per-device rate as if they were the same number.

How much does a SOC cost?

The published benchmarks on this page are the honest public answer for tooling. The number worth comparing any quote against is what running it yourself costs, and that is dominated by people rather than software: covering one seat around the clock takes about five people once leave and attrition cover are counted, and six seats across three tiers and two functions is roughly thirty before a single specialist. That arithmetic is on our team page, and the fuller cost comparison is on SOC as a Service.

How much does VAPT cost in India?

It is quoted per scope, normally in tester-days, and the range is genuinely wide because the same three letters are sold for two very different things. An automated scan exported to a template is one price; a manual test where somebody actually attempts to chain findings together is several times that. Ask any provider how many days are manual, who performs them, and to see a redacted sample report before comparing prices — the sample tells you more than the quote.

Do you publish a FortiGate price list?

No, and be cautious of pages that do. Appliance list pricing moves, bundles differ by region and term, and a stale list is worse than none. What matters more than the appliance price is the renewable subscription attached to it over three to five years, which is usually the larger figure. We quote both together, because quoting only the first is how a cheap firewall becomes an expensive one.

Is a cheaper provider usually worse?

Not necessarily, but find out what has been removed. The usual candidates are out-of-hours cover that turns out to be an alert queue rather than an analyst, response authority that requires your approval before anything happens, retention shortened to ninety days, and specialist tiers that are subcontracted. Each is a legitimate way to reduce cost and each should be a decision you made rather than one you discovered.

Can we start small?

Yes, and we often suggest it. A controls review, a single site, or one function is a reasonable way to test the working relationship before committing to a multi-year agreement. It is also a much cheaper way to discover a mismatch.

Do you charge for the initial review?

The scoping conversation and the resulting proposal are not charged. A deeper assessment that produces a written report is a piece of work with a cost, and we say which one you are getting before it starts rather than after.

What do you need from us to quote?

For managed IT: user count and device count. For monitoring: which log sources, roughly what daily volume, and how long you need them searchable. For VAPT: how many applications or IP ranges, and whether you need manual depth. For firewalls: throughput, site count and which subscriptions you already hold. That is usually enough for a real number rather than a range.

Are prices in rupees or dollars?

Indian engagements are quoted in rupees. Where a client outside India needs a dollar figure we quote in dollars and contract through the Indian company. The published benchmarks on this page are in dollars because that is how those vendors publish them — they are third-party list prices, not ours.

Why do quotes for the same thing differ so much?

Most often because they are not the same thing. Different retention periods, different definitions of a monitored device, business hours versus genuine 24×7, and response authority included or excluded will each move a number substantially. Settle those four before comparing, and the quotes usually converge.

Next step

Send a device count and a user count

That is genuinely enough to start. For monitoring, add which log sources matter and how long you need them searchable. You will get a real figure with the build-it-yourself number beside it, so you can see what you are actually buying rather than only what you are paying.

sanjay@pjnetworks.com