Kaseya MDR vs Thales (S21sec)
Kaseya MDR is a MSP-channel that works with your existing tools. Thales (S21sec) is a Services firm that works with your existing tools. Kaseya MDR targets SMB and Mid-market organizations; Thales (S21sec) serves Enterprise.
Buyer brief
Kaseya MDR is a MSP-channel that works with your existing tools. Thales (S21sec) is a Services firm that works with your existing tools. Kaseya MDR targets SMB and Mid-market organizations; Thales (S21sec) serves Enterprise.
Kaseya MDR (MSP-channel) and Thales (S21sec) (Services firm) serve different buyer profiles. Your decision depends on whether you prioritize Kaseya MDR's kaseya mdr is strongest for msps that want rocketcyber-style managed soc coverage tied into kasey... or Thales (S21sec)'s thales/s21sec is strongest for complex, regulated and critical-sector environments that value glo....
At a glance
| FIELD | ||
|---|---|---|
| Best fit | MSPs that want white-labeled MDR across endpoints, Microsoft 365, Entra ID and firewalls | Critical infrastructure and public-sector buyers that need Thales/S21sec regional cyber detection and response |
| Price | Custom quote | Custom quote |
| Response authority | 3/6 actions · Configurable | 2/6 actions · Configurable |
| Stack | Own agent required | Works with existing stack |
| Data access | Dashboards | Reports only |
| Warranty | None listed | None listed |
- Best fit
- MSPs that want white-labeled MDR across endpoints, Microsoft 365, Entra ID and firewalls
- Price
- Custom quote
- Response authority
- 3/6 actions · Configurable
- Stack
- Own agent required
- Data access
- Dashboards
- Warranty
- None listed
- Best fit
- Critical infrastructure and public-sector buyers that need Thales/S21sec regional cyber detection and response
- Price
- Custom quote
- Response authority
- 2/6 actions · Configurable
- Stack
- Works with existing stack
- Data access
- Reports only
- Warranty
- None listed
Detailed comparison
| FIELD | Kaseya MDRTECH-AGNOSTIC | Thales (S21sec)TECH-AGNOSTIC |
|---|---|---|
| Fit | ||
| Target size | SMB, Mid-market | Enterprise |
| Sentiment | Mixed | Mixed |
| Your stack | ||
| Approach | Works with your tools | Works with your tools |
| EDR integrations | Microsoft DefenderSentinelOneSophosBitdefenderWebrootBlackBerry CylanceDeep Instinct | Customer endpoint security tools |
| SIEM integrations | None listed | Customer SIEM platformsThales SOC tooling |
| Coverage | EPEndpoint: CoveredCloudCloud: Not coveredIDIdentity: LimitedSaaSSaaS: LimitedNetNetwork: CoveredOTOT/IoT: Not covered | EPEndpoint: LimitedCloudCloud: LimitedIDIdentity: LimitedSaaSSaaS: LimitedNetNetwork: CoveredOTOT/IoT: Covered |
| Response | ||
| Response type | Active Remediation | Active Remediation |
| Approval policy | Configurable | Configurable |
| Response actions | IsolateKill processCustom playbooks | ContainCustom playbooks |
| IR included | Separate | ✓ Included |
| Cost | ||
| Price range | Custom quote. No public per-endpoint price found. | Not published |
| Minimum seats | None | None |
| Breach warranty | – | – |
| More details | ||
| Requires own agent | Yes | No |
| Endpoints | ✓ Included | ~ Limited |
| Cloud workloads | Not offered | ~ Limited |
| Identity | ~ Limited | ~ Limited |
| SaaS apps | ~ Limited | ~ Limited |
| Network | ✓ Included | ✓ Included |
| OT/ICS | Not offered | ✓ Included |
| Threat hunting | ✓ Included | ✓ Included |
| Response SLA | Not disclosed | Not disclosed |
| 24/7 coverage | ✓ | ✓ |
| Pricing model | Custom quote. Kaseya publishes a pricing request page and says Kaseya MDR is available as a standalone offering and within Kaseya 365 Endpoint Pro. | Custom quote for Thales Cyber Detection and Response, Managed Security Services, SOC and MDR. Public prices are not published. |
| Hidden cost warnings | RocketCyber is transitioning into Kaseya MDR, so buyers should confirm which platform, retention terms and response capabilities are included in the quote.. Kaseya packaging can bundle MDR with endpoint management, EDR, backup and automation, which makes direct MDR-only comparison harder.. Community sentiment around Kaseya contract terms and support is mixed, even when some MSPs praise RocketCyber SOC responsiveness.. No public MDR-specific SLA or independent detection benchmark was found. | The current S21sec domain routes to Thales-branded services, so buyers wanting legacy S21sec-specific delivery should confirm contracting entity, SOC location and delivery team.. Public pages do not publish prices, minimum terms, service credits, MTTD/MTTR or formal MDR SLAs.. Thales offers a broad cybersecurity services portfolio; buyers should separate base MDR scope from CTI, DRPS, DFIR, CERT, ICS monitoring and advisory services.. Named endpoint, identity and cloud containment actions are not public and should be confirmed tool by tool.. Data retention, raw log access, offboarding and detection-content export rights are not described publicly. |
| Data portability | Partial | Partial |
| Contract terms | Custom | Custom cyber detection and response engagement, Managed Security Services, SOC and MDR, Critical-infrastructure cybersecurity services |
| Channels | PortalEmailPhone | EmailPhonePortal |
| Data access | Dashboards | Reports only |
| Dedicated analyst | – | – |
| SOC regions | North AmericaEurope | EuropeMEAAPAC |
| Onboarding | Kaseya describes cloud-based deployment with no on-site hardware and says protection can start in minutes. A public standard onboarding timeline for MDR customers was not found. | Not published. Thales describes customer-centric service roadmaps and selecting/deploying detection and response technologies, but no standard MDR onboarding timeline. |
| Industry focus | Managed Service ProvidersSMBFinancial ServicesProfessional ServicesHealthcare | Critical InfrastructureGovernmentDefenseEnergyManufacturingAviationSpaceFinancial ServicesTelecommunicationsHealthcareTransportationAutomotiveUtilitiesMaritime |
| MTTD | Not published | Not published |
| MTTR | Not published | Not published |
| Community view | MSP community signal is split. Several practitioners praise RocketCyber SOC responsiveness and value inside Kaseya bundles, while others distrust Kaseya ownership, contracts, support or the Datto/Kaseya stack around it. Treat RocketCyber service quality and Kaseya commercial fit as separate diligence tracks. | The current public evidence is strong for Thales-branded global SOC, MDR, CTI, DFIR and critical-infrastructure detection and response, but weak for S21sec as a standalone public MDR brand. Buyers should validate current delivery model, SOC location, response authority, pricing and whether the contract is with Thales/S21sec in the relevant country. |
| Compliance | SOC 2HIPAA | DORATIBER-EUPCI DSSEASA Part-ISEASAICAOUNECE |
| Certifications | SOC 2 | 8 threat intelligence and AI-driven SOCs around the worldSOCs in France, Morocco, the Netherlands, Belgium and Luxembourg, Portugal and Spain, and New Zealand and Australia |
| Founded | 2000 | – |
| Data retention | Kaseya's current MDR page says Kaseya MDR includes 400-day log retention. Older RocketCyber documentation and legal pages should be checked during quote review to confirm which retention terms apply to the deployed platform. | Not published. Public pages do not describe default log retention, raw log access, storage tiers or export terms for Thales SOC and MDR. |
| API available | – | – |
| Website | Visit → | Visit → |
FAQ
What is the main difference between Kaseya MDR and Thales (S21sec)?
Kaseya MDR is a MSP-channel that is technology-agnostic (works with your existing tools). Thales (S21sec) is a Services firm that is technology-agnostic (works with your existing tools).
How do Kaseya MDR and Thales (S21sec) differ in response capabilities?
Kaseya MDR supports 3 autonomous actions (custom playbooks, endpoint isolation, process termination) and approval is configurable. Thales (S21sec) supports 2 autonomous actions (custom playbooks, network containment) and approval is configurable. Incident response is not included with Kaseya MDR and included with Thales (S21sec).
How does Kaseya MDR pricing compare to Thales (S21sec)?
Kaseya MDR pricing: Custom quote. No public per-endpoint price found.. Thales (S21sec) pricing: Not published. Watch for with Kaseya MDR: RocketCyber is transitioning into Kaseya MDR, so buyers should confirm which platform, retention terms and response capabilities are included in the quote.; Kaseya packaging can bundle MDR with endpoint management, EDR, backup and automation, which makes direct MDR-only comparison harder.. Watch for with Thales (S21sec): The current S21sec domain routes to Thales-branded services, so buyers wanting legacy S21sec-specific delivery should confirm contracting entity, SOC location and delivery team.; Public pages do not publish prices, minimum terms, service credits, MTTD/MTTR or formal MDR SLAs..
Should I choose Kaseya MDR or Thales (S21sec)?
Choose Kaseya MDR if: mSPs that want white-labeled MDR across endpoints, Microsoft 365, Entra ID and firewalls. Choose Thales (S21sec) if: critical infrastructure and public-sector buyers that need Thales/S21sec regional cyber detection and response. Kaseya MDR is not ideal for buyers avoiding Kaseya contracts or vendor consolidation. Thales (S21sec) is not ideal for buyers that need a standalone legacy S21sec-branded MDR package.
Daylight Security
AI-native MDR for buyers comparing active remediation across endpoint, cloud, identity, and SaaS. Daylight works with existing EDR/SIEM stacks and uses ChatOps-native collaboration, so it can be a useful third reference point in this comparison.