DTS Solution vs NCC Group
DTS Solution and NCC Group are both Services firms that work with your existing tools. DTS Solution targets SMB, Mid-market, and Enterprise organizations, while NCC Group serves Mid-market and Enterprise. DTS Solution includes 3 attack surfaces in base pricing (Endpoint, Cloud, Network), compared to 4 for NCC Group (Endpoint, Cloud, SaaS, Network).
Buyer brief
DTS Solution and NCC Group are both Services firms that work with your existing tools. DTS Solution targets SMB, Mid-market, and Enterprise organizations, while NCC Group serves Mid-market and Enterprise. DTS Solution includes 3 attack surfaces in base pricing (Endpoint, Cloud, Network), compared to 4 for NCC Group (Endpoint, Cloud, SaaS, Network).
NCC Group offers broader coverage (4 surfaces vs. 3). DTS Solution may suit teams that need depth over breadth.
At a glance
| FIELD | ||
|---|---|---|
| Best fit | Middle East and EMEA buyers that want a UAE-based managed CSOC and XDR provider | European enterprise and government organizations running Microsoft Sentinel or Splunk as their SIEM |
| Price | Custom quote | Custom quote |
| Response authority | 3/6 actions · Configurable | 5/6 actions · Configurable |
| Stack | Works with existing stack | Works with existing stack |
| Data access | Dashboards | Dashboards |
| Warranty | None listed | None listed |
- Best fit
- Middle East and EMEA buyers that want a UAE-based managed CSOC and XDR provider
- Price
- Custom quote
- Response authority
- 3/6 actions · Configurable
- Stack
- Works with existing stack
- Data access
- Dashboards
- Warranty
- None listed
- Best fit
- European enterprise and government organizations running Microsoft Sentinel or Splunk as their SIEM
- Price
- Custom quote
- Response authority
- 5/6 actions · Configurable
- Stack
- Works with existing stack
- Data access
- Dashboards
- Warranty
- None listed
Detailed comparison
| FIELD | DTS SolutionTECH-AGNOSTIC | NCC GroupTECH-AGNOSTIC |
|---|---|---|
| Fit | ||
| Target size | SMB, Mid-market, Enterprise | Mid-market, Enterprise |
| Sentiment | Mixed | Mixed |
| Your stack | ||
| Approach | Works with your tools | Works with your tools |
| EDR integrations | Microsoft endpoint securityHawkEye XDR AgentCustomer endpoint security tools CrowdStrike | Microsoft Defender CrowdStrike |
| SIEM integrations | HawkEye NG-SIEMHawkEye Open XDRCustomer-owned SIEM | Microsoft SentinelSplunk |
| Coverage | EPEndpoint: CoveredCloudCloud: CoveredIDIdentity: LimitedSaaSSaaS: LimitedNetNetwork: CoveredOTOT/IoT: Optional add-on | EPEndpoint: CoveredCloudCloud: CoveredIDIdentity: LimitedSaaSSaaS: CoveredNetNetwork: CoveredOTOT/IoT: Not covered |
| Response | ||
| Response type | Active Remediation | Active Remediation |
| Approval policy | Configurable | Configurable |
| Response actions | IsolateContainCustom playbooks | IsolateKill processContainQuarantineCustom playbooks |
| IR included | Separate | ✓ Included |
| Cost | ||
| Price range | Not published | Not published. Custom quotes only. |
| Minimum seats | None | None |
| Breach warranty | – | – |
| More details | ||
| Requires own agent | No | No |
| Endpoints | ✓ Included | ✓ Included |
| Cloud workloads | ✓ Included | ✓ Included |
| Identity | ~ Limited | ~ Limited |
| SaaS apps | ~ Limited | ✓ Included |
| Network | ✓ Included | ✓ Included |
| OT/ICS | + Optional | Not offered |
| Threat hunting | ✓ Included | ✓ Included |
| Response SLA | Not disclosed | Not disclosed |
| 24/7 coverage | ✓ | ✓ |
| Pricing model | Tiered subscription packages by log-source count and EPS, with custom-tailored packages for additional log sources, EPS and retention. Public prices are not published. | Not published. Custom quotes. Evidence of large-scale enterprise pricing: EUR 25M+ contract for Netherlands university consortium (23+ universities, 5-year term). |
| Hidden cost warnings | Package limits are defined by log sources and events per second, so high-volume environments should model ingestion growth before contract.. Public pages do not publish prices, minimum terms, contractual SLAs, service credits or MTTD/MTTR metrics.. DFIR is included only in Premium Platinum in the package table; lower tiers list it as an add-on.. Managed SOAR and many adjacent managed services are add-ons rather than guaranteed base MDR scope.. The public AI SOC page says response actions are analyst-approved, so buyers should document which containment actions DTS can execute and whose approval is required. | MXDR for Microsoft and MXDR for Splunk are separate offerings. Customers using both Sentinel and Splunk may face separate engagements.. Only Microsoft Defender and CrowdStrike EDR integrations are confirmed. Other EDR platforms may not be supported.. Post-breach advisory limited to 2 hours included. Full IR engagement is a separate NCC Group consulting purchase.. SIEM licensing (Microsoft Sentinel or Splunk) is the customer's cost, not included in MXDR pricing |
| Data portability | Partial | Partial |
| Contract terms | Lite Bronze, Baseline Silver, Advanced Gold, Premium Platinum, Custom-tailored package | Annual, Multi-year |
| Channels | PortalEmailPhone | EmailPortalPhone |
| Data access | Dashboards | Dashboards |
| Dedicated analyst | – | – |
| SOC regions | MEA | Europe |
| Onboarding | HawkEye describes an onsite discovery workshop, package selection, secure onboarding, service delivery and secure offboarding. No standard calendar timeline was found. | Weeks, not months (vendor claim). Uses infrastructure-as-code deployment. Exact timeline not published. |
| Industry focus | Critical InfrastructureEnergyUtilitiesManufacturingGovernmentFinancial ServicesHealthcareRetailTechnologyTelecommunicationsSmart CitiesTransportation | GovernmentHigher EducationFinancial ServicesManufacturingEnergyTelecommunications |
| MTTD | Not published | Not published |
| MTTR | Not published | 25 minutes average time to close (vendor-published). 95% of threats resolved within 2 hours. |
| Community view | HawkEye has strong vendor-controlled detail for package tiers, dashboard access, retention, CSOC/XDR capabilities and regional SOC positioning, but little independent MDR-specific review signal in public English-language communities. Buyers should validate analyst quality, response authority and pricing through references. | Strong analyst recognition: Forrester Wave MDR Europe Q3 2025 Strong Performer, IDC MarketScape European MDR 2024 Leader. Virtually no practitioner reviews on G2 (not MDR-specific), PeerSpot (0 reviews, ranked 43rd in MDR), or Reddit. Analyst praise for threat hunting and consultative approach, but buyers cannot reference peer experiences. |
| Compliance | ISO 27001ISO 9001ISO 45001SOC 2 Type IMITRE ATT&CK | ISO 27001:2022ISO 9001:2015PCI QSAPCI ASV |
| Certifications | ISO 27001ISO 9001ISO 45001SOC 2 Type I logo shown on DTS siteSOC-CMM risk-driven certification logo shown on DTS siteSWIFT CSP logo shown on DTS site | ISO 27001:2022ISO 9001:2015PCI Qualified Security Assessor (QSA)PCI Approved Scan Vendor (ASV)FedRAMP 3PAO (Third-Party Assessment Organization) |
| Founded | 2011 | 1999 |
| Data retention | HawkEye package pages publish 3 months hot storage, 6 months warm storage and 12 months cold storage across service tiers, with longer retention available through a custom-tailored package. Advanced and Premium tier pages also describe standard collected-log retention; buyers should reconcile final retention language in the contract. | Not published. |
| API available | – | ✓ |
| Website | Visit → | Visit → |
FAQ
What is the main difference between DTS Solution and NCC Group?
DTS Solution is a Services firm that is technology-agnostic (works with your existing tools). NCC Group is a Services firm that is technology-agnostic (works with your existing tools). DTS Solution covers 3 attack surfaces in base pricing vs. 4 for NCC Group.
How do DTS Solution and NCC Group differ in response capabilities?
DTS Solution supports 3 autonomous actions (custom playbooks, endpoint isolation, network containment) and approval is configurable. NCC Group supports 5 autonomous actions (custom playbooks, endpoint isolation, file quarantine, network containment, process termination) and approval is configurable. Incident response is not included with DTS Solution and included with NCC Group.
How does DTS Solution pricing compare to NCC Group?
DTS Solution pricing: Not published. NCC Group pricing: Not published. Custom quotes only.. Watch for with DTS Solution: Package limits are defined by log sources and events per second, so high-volume environments should model ingestion growth before contract.; Public pages do not publish prices, minimum terms, contractual SLAs, service credits or MTTD/MTTR metrics.. Watch for with NCC Group: MXDR for Microsoft and MXDR for Splunk are separate offerings. Customers using both Sentinel and Splunk may face separate engagements.; Only Microsoft Defender and CrowdStrike EDR integrations are confirmed. Other EDR platforms may not be supported..
Should I choose DTS Solution or NCC Group?
Choose DTS Solution if: middle East and EMEA buyers that want a UAE-based managed CSOC and XDR provider. Choose NCC Group if: european enterprise and government organizations running Microsoft Sentinel or Splunk as their SIEM. DTS Solution is not ideal for buyers that need public MDR pricing or contractual MTTD/MTTR before sales. NCC Group is not ideal for organizations running a SIEM other than Microsoft Sentinel or Splunk (only two supported).
Daylight Security
AI-native MDR for buyers comparing active remediation across endpoint, cloud, identity, and SaaS. Daylight works with existing EDR/SIEM stacks and uses ChatOps-native collaboration, so it can be a useful third reference point in this comparison.