How this is priced · Operating since 2002
There are no price tiers on this page. A number without an estate behind it is fiction, and the more useful thing — the thing people are actually searching for — is how this category gets priced at all.
So this sets out what each service is metered on, which vendor list prices are genuinely published, and which of your own decisions move a quote further than the choice of provider does. Send a device and user count and you get a real figure instead.
The meter
Why the unit matters more than the rate
One company, three billing meters, three different totals — before anybody negotiates anything.
Note the third bar is dashed and deliberately not scaled against the others. Log-volume pricing tracks the number of systems and the retention period rather than headcount, so a forty-person firm with heavy cloud logging can genuinely cost more to monitor than a four-hundred-person one that is mostly laptops. Comparing it to a per-seat rate is the most common budgeting error in this category.
Across the portfolio
What each service is metered on
Six services, six different units. Knowing which one you are being quoted on is most of understanding the number.
Scroll the table sideways →
| Service | Billing meter | What grows the bill | What to watch | Detail |
|---|---|---|---|---|
| Managed IT | Per user, or per device | Headcount and device count | A device meter grows every time someone gets a second machine. A user meter does not — which is why the two diverge as an estate matures, not on day one. | Managed IT services |
| Managed SOC / SIEM | Per log source, per GB ingested, or per asset | Number of systems, and retention period | Decoupled from headcount entirely. A 40-person firm with heavy cloud logging can cost more to monitor than a 400-person one that is mostly laptops. | Managed SOC services |
| MDR / EDR | Per endpoint, per month or per year | Endpoint count | The cleanest meter in the category, which is why it is the easiest to compare across vendors — and several publish list prices openly. | MDR, EDR and XDR |
| VAPT | Per scope, usually quoted in tester-days | Application count, IP ranges, and depth | Ask what a day buys. An automated scan with a cover page and a genuine manual test are both sold as “VAPT” and differ by an order of magnitude in both price and value. | VAPT |
| Firewalls | Hardware once, subscriptions annually | Throughput, and which subscription bundle | The appliance is the small number. The renewable security subscription over three to five years is usually the larger one, and it is where a cheap quote becomes expensive. | Firewall services |
| NOC / NMS | Per monitored device or interface | Estate size and polling depth | Watch the definition of “device”. A switch stack counted as one unit or as twelve is the difference between two very different bills. | NOC as a Service |
Published benchmarks
List prices vendors actually publish
Not our prices — third-party list prices, each with the vendor named, so you have a public reference point to compare any quote against. Tooling only; none of these includes analysts.
| Vendor | Product | Published list price |
|---|---|---|
| Huntress | Managed EDR | $8.99 per endpoint / month |
| Huntress | Managed SIEM | $4.00 per data source / month |
| Blumira | Detect / Respond / Automate | $12 / $16 / $21 per employee / month |
| CrowdStrike | Falcon Go / Pro / Enterprise | $59.99 / $99.99 / $184.99 per device / year |
| Wazuh Cloud | Small / Medium / Large | $571 / $923 / $1,467 per month (to 100 / 250 / 500 agents) |
| UnderDefense | MDR | $10–$30 per asset / month, annual contract |
These are the tooling floor, not the cost of a service. A platform licence with nobody watching it produces alerts rather than outcomes, and the people are the larger number — see the staffing arithmetic on our team page.
What you control
Six things that move a quote more than the provider does
Buyers spend most of their energy comparing rates between providers, when the larger movements are usually in decisions they own.
Relative, not absolute — the ratios follow from storage and index cost scaling with the period, which is why this is the lever to settle before comparing any two quotes.
Retention period
The single largest lever on any monitoring quote. Twelve months of hot, searchable logs against ninety days is not a small adjustment — storage and index cost scale directly with it. Decide what you actually need searchable versus merely retained, because the two have very different prices.
How many log sources you send
Every added source raises the bill and not every source earns its place. Firewall, identity and endpoint logs almost always do. Verbose application debug logs almost never do, and they are frequently the largest volume in the estate.
Whether the scope is written down
An unclear scope is priced with a risk margin, because the provider is guessing. A precise asset list, a defined out-of-hours expectation and a named escalation path all reduce a quote, and they cost you nothing but an afternoon.
What you count as a device
A switch stack, a virtual host, a pair of firewalls in HA — each can reasonably be counted as one unit or several. Settle the counting rule before comparing quotes, or you will compare two numbers that were never measuring the same thing.
Year two
Threat hunting, extended retention and vulnerability management are frequently free in year one and line items afterwards. Ask for the renewal schedule up front. This is the most common cause of a relationship souring at the first anniversary.
How much you already own
If you hold current firewall subscriptions or endpoint licences, an honest provider operates them rather than replacing them. Where we do recommend a change we quote the cost to run it, not only to buy it — and those are very different numbers over three years.
Questions we get asked
Pricing, answered
Why are there no prices on this page?
Because a price without an estate behind it would be fiction, and this page used to carry exactly that — four invented tiers taken from a website template, one of which described incident response as “best for individual designers”. They have been removed. What is published instead is how each service is metered, which third-party list prices are genuinely public, and which of your own decisions move a quote most. Send us a device and user count and you get a real number.
What is the most common cybersecurity pricing model?
Per user or per device for managed IT; per log source, per GB ingested or per asset for monitoring; per endpoint for MDR; per scope in tester-days for VAPT. The important thing is that these are not interchangeable. For an estate of 200 staff and 350 devices, a per-device meter bills 1.75 times as many units as a per-user meter at the identical rate — which is the diagram at the top of this page.
Which is better, per user or per device?
Per user is more predictable and usually favours you as the estate matures, because device counts creep upward while headcount does not. Per device can be cheaper for an organisation with fewer machines than people, such as a shift-working operation with shared terminals. Neither is a trick; the mistake is comparing a per-user rate against a per-device rate as if they were the same number.
How much does a SOC cost?
The published benchmarks on this page are the honest public answer for tooling. The number worth comparing any quote against is what running it yourself costs, and that is dominated by people rather than software: covering one seat around the clock takes about five people once leave and attrition cover are counted, and six seats across three tiers and two functions is roughly thirty before a single specialist. That arithmetic is on our team page, and the fuller cost comparison is on SOC as a Service.
How much does VAPT cost in India?
It is quoted per scope, normally in tester-days, and the range is genuinely wide because the same three letters are sold for two very different things. An automated scan exported to a template is one price; a manual test where somebody actually attempts to chain findings together is several times that. Ask any provider how many days are manual, who performs them, and to see a redacted sample report before comparing prices — the sample tells you more than the quote.
Do you publish a FortiGate price list?
No, and be cautious of pages that do. Appliance list pricing moves, bundles differ by region and term, and a stale list is worse than none. What matters more than the appliance price is the renewable subscription attached to it over three to five years, which is usually the larger figure. We quote both together, because quoting only the first is how a cheap firewall becomes an expensive one.
Is a cheaper provider usually worse?
Not necessarily, but find out what has been removed. The usual candidates are out-of-hours cover that turns out to be an alert queue rather than an analyst, response authority that requires your approval before anything happens, retention shortened to ninety days, and specialist tiers that are subcontracted. Each is a legitimate way to reduce cost and each should be a decision you made rather than one you discovered.
Can we start small?
Yes, and we often suggest it. A controls review, a single site, or one function is a reasonable way to test the working relationship before committing to a multi-year agreement. It is also a much cheaper way to discover a mismatch.
Do you charge for the initial review?
The scoping conversation and the resulting proposal are not charged. A deeper assessment that produces a written report is a piece of work with a cost, and we say which one you are getting before it starts rather than after.
What do you need from us to quote?
For managed IT: user count and device count. For monitoring: which log sources, roughly what daily volume, and how long you need them searchable. For VAPT: how many applications or IP ranges, and whether you need manual depth. For firewalls: throughput, site count and which subscriptions you already hold. That is usually enough for a real number rather than a range.
Are prices in rupees or dollars?
Indian engagements are quoted in rupees. Where a client outside India needs a dollar figure we quote in dollars and contract through the Indian company. The published benchmarks on this page are in dollars because that is how those vendors publish them — they are third-party list prices, not ours.
Why do quotes for the same thing differ so much?
Most often because they are not the same thing. Different retention periods, different definitions of a monitored device, business hours versus genuine 24×7, and response authority included or excluded will each move a number substantially. Settle those four before comparing, and the quotes usually converge.
Next step
Send a device count and a user count
That is genuinely enough to start. For monitoring, add which log sources matter and how long you need them searchable. You will get a real figure with the build-it-yourself number beside it, so you can see what you are actually buying rather than only what you are paying.



