Buyer fit
Good fit when
- ✓Norwegian and Nordic buyers that want MDR operated from Oslo and Gjovik
- ✓Microsoft-heavy teams using Microsoft 365, Sentinel, Defender or Log Analytics
- ✓Organizations that want MDR tied to threat hunting and incident-response escalation
Watch out when
- ×Buyers that need public MDR pricing or contractual SLA terms before sales
- ×Teams that require named autonomous endpoint or identity response actions in public docs
- ×Organizations that want a global follow-the-sun SOC footprint published on the provider site
Coverage
1 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote.
How pricing works+−
Defendable does not publish MDR package pricing.
Not published
Cost caveats
- –Public pages do not publish MDR pricing, contract minimums or service-credit language.
- –Response authority should be defined in writing because named autonomous endpoint and identity actions are not published.
- –Log storage can sit in the customer's Microsoft Log Analytics tenant or Defendable's platform, so retention and storage costs should be modeled early.
2 more+−
- –Incident-response retainer SLA is separate language and should not be assumed to be the MDR SLA.
- –Threat hunting is public, but hunt cadence and staffing are not published.
What costs extra (4)+−
- –Exact MDR pricing requires a Defendable quote
- –Microsoft Sentinel, Microsoft Defender, Microsoft Log Analytics and Microsoft 365 licensing can affect total cost
- –Defendable-hosted log management may affect storage cost
- –Incident Response Retainer, security advisory and security testing may be separate from MDR scope
Team and access
Certifications
Reputation
Defendable has limited MDR-specific public review volume in major English-language review communities. The public buyer case rests on Norwegian SOC delivery, a direct MDR page, Microsoft Sentinel support, proactive threat hunting, a customer portal and incident-response depth. Buyers should validate pricing, response authority, retention cost and contractual SLA terms directly.
No meaningful Reddit signal found for Defendable MDR specifically.
Questions to ask
- 1.
Which log sources, endpoints, users and Microsoft tenants are included in the MDR quote?
- 2.
Will our logs sit in Microsoft Log Analytics or Defendable's log management platform, and what retention period is included?
- 3.
Which response actions can Defendable take directly and which require our approval?
- 4.
What MDR SLA applies to high-severity triage, escalation and containment?
- 5.
How does the incident-response retainer interact with MDR during a severe incident?
- 6.
How often does proactive threat hunting run and how are findings reported?
- 7.
Which Sentinel workbooks and SOAR playbooks are standard versus customized for our environment?
- 8.
What tickets, reports, detection content and log data can we export if we leave?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response workflows are described, but exact standard containment actions are not public.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
