Buyer fit
Good fit when
- ✓Mid-market organizations without a dedicated SOC that want a named security team, not just a monitoring service
- ✓IT teams managing multiple security tools that want a single pane of glass without replacing their existing stack
- ✓Organizations that value the industry's largest breach warranty ($3M) and compliance-aligned security reviews
Watch out when
- ×Security teams that want direct access to raw telemetry, custom detection engineering, or SIEM query capabilities
- ×Organizations that need the MDR provider to perform hands-on remediation, not just guide your team through it
- ×Budget-conscious SMBs: MDR Basic starts around $44K/year at the AWS Marketplace entry tier, an effective floor rather than a published minimum, and full-stack costs escalate quickly with add-ons
Coverage
3 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Per-user and per-server subscription priced by license type and concierge tier.
Checked Jul 2026
Sourced figures
MDR Basic, monitor up to 100 users, 12-month contract (listed 'save up to 6%')…
AWS Marketplace · checked Jul 2026
Core (MDR-only) bundle per user or per server per year: Silver $192, Gold $218…
AW-MDR-USER standalone MDR user license $200/user/year; limited user $20/year; SaaS…
All 6 sourced figures+−
Aggregated buyer transactions. Vendr page: median $79,740/yr, range…
Vendr / UnderDefense · observed 2026-07-18; UnderDefense guide updated 2026-02
Reseller/partner estimate: 'a 100-person shop might cost 40,000 a year.' Aligns…
PeerSpot · checked Jul 2026
Negotiated per-endpoint effective rate: $12-18/mo at 100-500 endpoints, $10-15/mo…
mdrcost.com / UnderDefense · 2026
How pricing works+−
Per-user and per-server subscription billed monthly under an annual or multi-year contract, priced by license type and concierge tier (Silver, Gold, Platinum), plus a per-organization platform base fee. Endpoints, cloud, SaaS apps, and network sensors are separate lines.
Government list price (Texas DIR, Feb 2025): Core MDR $192/$218/$257 per user or server per year for Silver/Gold/Platinum; standalone MDR user license $200/user/year; Aurora Managed Endpoint Defense $80/device/year for MDR customers ($110 standalone); Aurora Platform base $15,000/year per organization. Not a flat or purely per-endpoint model.
Cost caveats
- –60-day renewal-cancellation notice reported by a G2 reviewer, longer than the typical 30 days; miss it and all services auto-renew.
- –Annual escalation clauses of 3 to 7% are standard and compound over multi-year terms; lock expansion pricing at signature or mid-contract seat adds default to then-current list.
- –The $3M warranty requires Aurora Managed Endpoint Defense plus a Security Operations Bundle on a 3-year term, creating platform dependency; lesser bundles carry much lower ceilings.
3 more+−
- –List prices are quoted per unit per year; get the billing period of any quote confirmed in writing before comparing figures across vendors.
- –Non-return fees of $850 to $5,575 per sensor apply if appliances are not returned at exit.
- –Remediation is guided, not performed for you; hands-on incident response needs a separate retainer.
What costs extra (8)+−
- –Managed Risk vulnerability and posture management ($100/user/year list, or Plus/Total bundle uplift)
- –Aurora Managed Endpoint Defense ($80/device/year for MDR customers, $110 standalone), required for the $3M warranty ceiling
- –Incident response beyond guided remediation: IR JumpStart Retainer ($5,000/org/year list) or the larger Incident360 retainer
- –Cloud Detection and Response for IaaS/SaaS (separate product)
- –SaaS app monitoring (O365, Google Workspace, Salesforce, Box) at about $22.50/user each
- –Extended log retention beyond 90 days, per asset per year up to 10 years ($14.40 to $46.80/asset/year list)
- –Network sensor hardware, $1,250 to $22,000 per location by model
- –Managed Security Awareness training ($30 to $42/user/year list)
Warranty conditions+−
Up to $3M requires a Security Operations Bundle plus Aurora Managed Endpoint Defense on a 3-year term; lesser configurations carry lower ceilings (a Core 3-year Bundle floor is reported around $100k). Doubled from $1.5M on 2025-04-28. Covers ransomware, BEC, compliance/legal assessment, cyber legal liability, and lost business income. The warranty terms (2025.05) route claims through a third-party administrator, Cysurance, which decides qualification in its sole discretion: 1 qualifying event per enrollment term, damages must plausibly exceed $5,000, a deductible applies, the event must be reported within 48 hours of Arctic Wolf's incident-response referral, and requested documentation supplied within 15 days. Eligibility requires patching within 60 days of release, MFA on email and critical systems, current antivirus, and working backups; systemic attacks and zero-day exploits causing widespread harm are excluded. It is a warranty, not insurance.
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Certifications
Reputation
Polarizing along predictable lines. Gartner Peer Insights rates 4.8/5 (451+ reviews) and G2 4.7/5 (~276 reviews), with mid-market customers praising the Concierge model. Reddit and practitioner forums are more critical, with recurring complaints about false positive rates, limited data transparency, and guided-not-hands-on remediation. PeerSpot mindshare dropped ~48% year-over-year.
What customers praise
- ✓Named Concierge Security Team acts as extension of internal staff with scheduled proactive security reviews
- ✓Technology-agnostic design works with existing tools (200+ integrations) without forcing rip-and-replace
- ✓$3M breach warranty, the largest in the industry, included with qualifying bundles
Common complaints
- ×71% false alarm rate (vendor's own 2025 data) and recurring user complaints about alert noise and fatigue
- ×Limited data transparency: customers cannot query raw data or view active threat feeds directly
- ×Guided response means they advise but your team executes. No published MTTD/MTTR and no MITRE participation.
Polarizing. Some mid-market teams praise the concierge model and all-inclusive pricing. Others report slow detection (one user documented a week-long delay vs. 3 minutes with Rapid7), limited UI quality, and dissatisfaction after internal pentests exposed gaps. MSPs tend to be more critical than direct customers. Mindshare declining as competitors like Huntress gain ground.
Questions to ask
- 1.
What specific actions does the Concierge Security Team take directly vs. what requires our team to execute on guidance?
- 2.
How do we access our normalized data and raw telemetry? Can we query it ourselves, or only request reports?
- 3.
What is the false positive rate in environments similar to ours, and how does your team handle tuning over time?
- 4.
What exactly does the $3M warranty cover, and what products must we deploy to qualify?
- 5.
Which of our existing tools will you ingest telemetry from, and which require the Arctic Wolf Agent or Sensor?
- 6.
What does incident response cost beyond the MDR subscription? What is included in the Incident360 retainer vs. standard MDR?
- 7.
What happens to our data and detection history if we transition away from Arctic Wolf?
- 8.
How many customers does our assigned Concierge Security Team support, and which concierge tier (Silver, Gold, Platinum) are we getting?
Evidence
Sources reviewed
Main public source used for the provider profile.
2025 security operations report revealing threat landscape insights from 330 trillion observations
2025 press release detailing Aurora Platform enhancements with new endpoint, cloud, and identity integrations
2025 partnership announcement for advancing R&D in next-generation autonomous SOC capabilities
Official demonstration of Arctic Wolf's MDR platform showing real-time threat detection and response capabilities
Public-data caveats
- –SLA caveat: 1-hour SLA is published for the Incident360 IR retainer. UK government listing shows 30-minute emergency and 2-hour non-emergency outbound response for MDR. Standard commercial MDR SLA terms are not broadly published.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
