Buyer fit
Good fit when
- ✓Large enterprises and mid-market organizations standardizing on Microsoft Sentinel and Defender or Google SecOps that want a co-managed SOC without a proprietary agent
- ✓Teams migrating to cloud-native SIEM that want help cutting Sentinel ingestion costs alongside detection and response
- ✓Buyers who want detection rules, playbooks, and data to stay in their own SIEM instance under a co-managed model
Watch out when
- ×SMBs and buyers wanting turnkey, self-service pricing, since engagements are custom-scoped and enterprise-oriented
- ×Organizations that need incident response and DFIR bundled into base MDR rather than as a separate engagement
- ×Teams that require a published response-time SLA or independent MITRE-validated detection metrics before signing
Coverage
3 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Quote-only, co-managed subscription.
Checked Aug 2026
How pricing works+−
Sold direct and via a private/contact offer on Microsoft Azure Marketplace. Pricing scales with environment size, data volume in the customer's SIEM, and which service level (Managed Detection and Notification versus Managed Detection and Response) is chosen. No list price is published.
Not published. Contact for a custom quote.
Cost caveats
- –The lower service level, Managed Detection and Notification, only notifies you of validated threats. Full response requires the Managed Detection and Response level
- –You still pay Microsoft or Google for the underlying SIEM and its data ingestion. CyberProof pitches ADX and its Log Collector to reduce that bill, which is itself a project rather than a switch
- –Incident response and DFIR are separate engagements, not included in base MDR
1 more+−
- –No published response-time SLA. Get response commitments in writing before signing
What costs extra (5)+−
- –DFIR and incident response engagements (separate from base MDR)
- –GRC and compliance consulting
- –Agentic MXDR AI-agent layer (positioned as an added service on top of managed detection)
- –Data-cost optimization work using Azure Data Explorer and the CyberProof Log Collector
- –Exposure and vulnerability management
Team and access
Certifications
Reputation
Gartner Peer Insights rates UST (CyberProof) 4.3 of 5 across only 5 reviews. PeerSpot lists the product with no collected reviews and about 0.8% category mindshare, there are no G2 reviews, and no meaningful Reddit discussion. The small review base makes independent validation difficult.
What customers praise
- ✓Gartner reviewers describe a strong ongoing partnership from onboarding through monitoring and incident response
- ✓L2 and L3 analysts called knowledgeable and proactive at identifying threats
Common complaints
- ×Gartner reviewers report L1 analysts overreacting on some vulnerability alerts and calling teams after-hours
- ×Some staff described as under-trained on the products they support despite being positioned as subject-matter experts
- ×Reviewers wanted a more proactive continuous-improvement roadmap, and 1 reviewer noted initial SIEM integration took longer than expected
No meaningful Reddit discussion found on r/msp, r/cybersecurity, or r/sysadmin. Low grassroots visibility compared to peers like Arctic Wolf or Huntress.
Questions to ask
- 1.
Which service level are we buying, Managed Detection and Notification or Managed Detection and Response, and exactly what response actions does the SOC take at each?
- 2.
In Agentic MXDR, which investigation steps do AI agents perform autonomously and which require L2 or L3 analyst validation? Where is that threshold configured?
- 3.
You do not publish a response-time SLA. What written response-time commitment will you put in the contract?
- 4.
Are incident response and DFIR included, or are they a separate engagement and retainer?
- 5.
How much of our delivery team is based in India versus other centers, and who covers our timezone overnight?
- 6.
The two-thirds-autonomous and 62.5% MTTR figures come from early case studies. Can you provide references in our industry and size, and show how those were measured?
- 7.
How do the ADX and Log Collector cost-optimization options change our total bill, including the Microsoft or Google SIEM charges we still pay directly?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
