Buyer fit
Good fit when
- ✓Nordic and European mid-market and enterprise buyers that want a regional intelligence-led MDR provider
- ✓Microsoft Sentinel or Defender XDR shops, and Darktrace users, that want a SOC to run their existing stack
- ✓Banking, financial services and critical-infrastructure teams that value CSIS e-crime and threat-intelligence heritage across IT and OT
Watch out when
- ×Buyers that need public per-endpoint pricing and a contractual response-time SLA before engaging
- ×Organizations running EDR outside the Microsoft and Darktrace ecosystem that CSIS supports
- ×North American buyers wanting a local SOC, or buyers that rely on independent peer reviews to evaluate a vendor
Coverage
3 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Quote-only across all 3 tiers (Base, Pro, Elite).
Checked Aug 2026
How pricing works+−
CSIS does not publish per-endpoint, per-user or package pricing, and no marketplace or reseller price was found.
Cost caveats
- –No public price floor or tier table, every engagement requires sales contact
- –Detection runs on Microsoft or Darktrace, so buyers without those platforms may face separate tooling costs
- –Incident-response cost coverage applies only to the Elite tier, not Base or Pro
1 more+−
- –No published response-time SLA or service-credit terms, so response expectations must be negotiated
What costs extra (5)+−
- –Microsoft Sentinel, Microsoft Defender XDR or Darktrace licensing where the customer does not already own it
- –Threat hunting, only included from the Pro tier upward
- –Compromise, cloud and Active Directory assessments, included in Elite
- –Emergency incident response beyond the Elite guarantee, sold as consulting or retainer
- –OT coverage and Digital Risk Protection as separate CSIS services
Warranty conditions+−
The Elite tier states CSIS covers incident-response costs if it misses an incident on a monitored environment. This is included IR-cost coverage, not a financial breach-warranty payout, and CSIS publishes no coverage cap or qualifying conditions.
Team and access
Certifications
Reputation
Effectively unrateable on independent buyer platforms. CSIS MDR has zero reviews on PeerSpot, no Gartner Peer Insights profile, no G2 presence and no Reddit signal. It carries a strong Danish reputation in e-crime research, banking anti-fraud and incident response, but that reputation rests on vendor and press material rather than peer reviews.
Common complaints
- ×Zero public buyer reviews on any major platform, so service claims cannot be independently validated
- ×No published MTTD/MTTR metrics, response-time SLA or MITRE evaluation participation
- ×Glassdoor: some employee reviews describe thin management structure and owners and partners pulling in different directions, a stability signal worth probing
Questions to ask
- 1.
Which response actions can CSIS take without separate approval, and does automated remediation on Base cover isolation or only alert handling?
- 2.
Does the service require Microsoft Sentinel, Defender XDR or Darktrace, or can CSIS operate on our current EDR and SIEM?
- 3.
What contractual response-time and escalation terms apply to critical incidents, given no SLA is published?
- 4.
How does the Elite incident-response guarantee work in practice, what qualifies as a missed incident and are there cost limits?
- 5.
Is threat hunting genuinely included at our tier, or does it require Pro or Elite?
- 6.
What OT and Darktrace /OT coverage is included in MDR versus your separate OT cybersecurity service?
- 7.
Can CSIS provide MDR customer references in our country and industry, given the lack of public reviews?
- 8.
How has the Allurity ownership and the SecAlliance acquisition changed SOC staffing and threat-intelligence delivery?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
