Northwave vs Tesorion
Northwave and Tesorion are both Services firms that work with your existing tools. Northwave targets Mid-market and Enterprise organizations, while Tesorion serves Mid-market and Enterprise. Northwave includes 2 attack surfaces in base pricing (Endpoint, Network), compared to 4 for Tesorion (Endpoint, Cloud, Identity, Network).
Buyer brief
Northwave and Tesorion are both Services firms that work with your existing tools. Northwave targets Mid-market and Enterprise organizations, while Tesorion serves Mid-market and Enterprise. Northwave includes 2 attack surfaces in base pricing (Endpoint, Network), compared to 4 for Tesorion (Endpoint, Cloud, Identity, Network).
Tesorion offers broader coverage (4 surfaces vs. 2). Northwave may suit teams that need depth over breadth.
At a glance
| FIELD | ||
|---|---|---|
| Best fit | Benelux, DACH and Nordic buyers that want European MDR with a Utrecht SOC | Dutch organisations that want MDR from a Netherlands-based cybersecurity services firm |
| Price | Custom quote | Custom quote |
| Response authority | 1/6 actions · Configurable | 1/6 actions · Configurable |
| Stack | Works with existing stack | Works with existing stack |
| Data access | Dashboards | Reports only |
| Warranty | None listed | None listed |
- Best fit
- Benelux, DACH and Nordic buyers that want European MDR with a Utrecht SOC
- Price
- Custom quote
- Response authority
- 1/6 actions · Configurable
- Stack
- Works with existing stack
- Data access
- Dashboards
- Warranty
- None listed
- Best fit
- Dutch organisations that want MDR from a Netherlands-based cybersecurity services firm
- Price
- Custom quote
- Response authority
- 1/6 actions · Configurable
- Stack
- Works with existing stack
- Data access
- Reports only
- Warranty
- None listed
›› Detailed comparison
| FIELD | NorthwaveTECH-AGNOSTIC | TesorionTECH-AGNOSTIC |
|---|---|---|
| ›› Fit | ||
| Target size | Mid-market, Enterprise | Mid-market, Enterprise |
| Sentiment | Mixed | Mixed |
| ›› Your stack | ||
| Approach | Works with your tools | Works with your tools |
| EDR integrations | Customer endpoint telemetry | SentinelOne Customer endpoint telemetry |
| SIEM integrations | Customer log sources | None listed |
| Coverage | EPEndpoint: CoveredCloudCloud: LimitedIDIdentity: LimitedSaaSSaaS: Not coveredNetNetwork: CoveredOTOT/IoT: Optional add-on | EPEndpoint: CoveredCloudCloud: CoveredIDIdentity: CoveredSaaSSaaS: LimitedNetNetwork: CoveredOTOT/IoT: Optional add-on |
| ›› Response | ||
| Response type | Active Remediation | Active Remediation |
| Approval policy | Configurable | Configurable |
| Response actions | Custom playbooks | Custom playbooks |
| IR included | Separate | Separate |
| ›› Cost | ||
| Price range | Not published | Not published |
| Minimum seats | None | None |
| Breach warranty | – | – |
| ›› More details | ||
| Requires own agent | No | No |
| Endpoints | ✓ Included | ✓ Included |
| Cloud workloads | ~ Limited | ✓ Included |
| Identity | ~ Limited | ✓ Included |
| SaaS apps | Not offered | ~ Limited |
| Network | ✓ Included | ✓ Included |
| OT/ICS | + Optional | + Optional |
| Threat hunting | ✓ Included | ✓ Included |
| Response SLA | Not disclosed | Not disclosed |
| 24/7 coverage | ✓ | ✓ |
| Pricing model | Custom quote. Northwave does not publish MDR package pricing. | Custom quote. Tesorion does not publish MDR package pricing. |
| Hidden cost warnings | Public pages do not publish response SLAs or named default response actions.. Rapid Response is a separate related service, so buyers should confirm what incident-response support is included in base MDR.. Cloud, SaaS and identity coverage are not named as clearly as endpoint, log and network telemetry.. Detection tuning depends on onboarding log sources and threat-based use cases, which may affect deployment effort. | Public pages do not publish response SLAs or named default response actions.. The public MDR page says mitigation is immediate where possible, but does not specify what Tesorion can do without customer approval.. T-CERT incident response is prominent, but buyers should confirm whether IR hours are included in MDR or sold separately.. Tesorion lists broad coverage across domains, so buyers should confirm which monitored sources are included in base MDR. |
| Data portability | Partial | Partial |
| Contract terms | Custom | Custom |
| Channels | PortalEmailPhone | EmailPhone |
| Data access | Dashboards | Reports only |
| Dedicated analyst | – | – |
| SOC regions | Europe | Europe |
| Onboarding | Northwave says implementation starts with a plan covering service elements, phases, planning and threat-based use cases, then onboarding log sources and processes. No standard public onboarding duration was found. | Tesorion says MDR use cases are tailored per organisation and linked to mitigating measures. No standard public onboarding duration was found. |
| Industry focus | Financial ServicesHealthcareManufacturingLogisticsTechnologyPublic SectorCritical Infrastructure | Financial ServicesHealthcarePublic SectorManufacturingCritical InfrastructureTechnologyProfessional Services |
| MTTD | Not published | Not published |
| MTTR | Not published | Not published |
| Community view | Northwave has limited MDR-specific public review volume. The public buyer case rests on European delivery, Utrecht SOC operations and the connection between MDR, CERT, red team and threat research. Buyers should validate response authority, cloud and identity coverage, pricing and escalation rules before signing. | Tesorion has limited MDR-specific public review volume. The public buyer case rests on Dutch delivery, T-SOC operations, XDR and SOAR correlation, threat intelligence and nearby T-CERT incident response. Buyers should validate pricing, response authority, included source scope and whether T-CERT support is included before signing. |
| Compliance | NIS2ISO 27001GDPRTISAX | ISO 27001NEN 7510NIS2DORABIO |
| Certifications | – | ISO 27001NEN 7510 |
| Founded | 2006 | 2018 |
| Data retention | Not published as a standard MDR retention period. | Not published as a standard MDR retention period. |
| API available | – | – |
| Website | Visit → | Visit → |
›› FAQ
What is the main difference between Northwave and Tesorion?
Northwave is a Services firm that is technology-agnostic (works with your existing tools). Tesorion is a Services firm that is technology-agnostic (works with your existing tools). Northwave covers 2 attack surfaces in base pricing vs. 4 for Tesorion.
How do Northwave and Tesorion differ in response capabilities?
Northwave supports 1 autonomous actions (custom playbooks) and approval is configurable. Tesorion supports 1 autonomous actions (custom playbooks) and approval is configurable.
How does Northwave pricing compare to Tesorion?
Northwave pricing: Not published. Tesorion pricing: Not published. Watch for with Northwave: Public pages do not publish response SLAs or named default response actions.; Rapid Response is a separate related service, so buyers should confirm what incident-response support is included in base MDR.. Watch for with Tesorion: Public pages do not publish response SLAs or named default response actions.; The public MDR page says mitigation is immediate where possible, but does not specify what Tesorion can do without customer approval..
Should I choose Northwave or Tesorion?
Choose Northwave if: benelux, DACH and Nordic buyers that want European MDR with a Utrecht SOC. Choose Tesorion if: dutch organisations that want MDR from a Netherlands-based cybersecurity services firm. Northwave is not ideal for buyers that need public MDR pricing or response SLAs before engaging sales. Tesorion is not ideal for buyers that need public MDR pricing or contractual response SLAs before sales engagement.
Daylight Security
AI-native MDR for buyers comparing active remediation across endpoint, cloud, identity, and SaaS. Daylight works with existing EDR/SIEM stacks and uses ChatOps-native collaboration, so it can be a useful third reference point in this comparison.