Buyer fit
Good fit when
- ✓Large enterprises that want to keep existing EDR and SIEM tools such as CrowdStrike, Cortex XSIAM, or Microsoft and layer a global managed SOC on top, with a migration path onto Deloitte's MXDR platform
- ✓Industrials and critical-infrastructure operators needing endpoint through OT and identity coverage plus incident response under one services relationship
- ✓Organizations already inside a Deloitte relationship, or Australian buyers wanting sovereign SOC delivery through ParaFlare
Watch out when
- ×SMBs and cost-sensitive buyers, since indicative AWS pricing starts around 2,000 endpoints at roughly $806,000/yr
- ×Teams that rely on published MTTD/MTTR or MITRE managed-service results to compare vendors, since Deloitte publishes neither
- ×Buyers who want transparent self-service per-endpoint pricing and a large body of independent MDR reviews before signing
Coverage
2 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom private-offer quote scoped by endpoint count, region, module mix, and data volume.
Checked Aug 2026
US-based customers, 12-month term. Three published endpoint tiers: 2,000 endpoints…
How pricing works+−
Deloitte's AWS Marketplace listing publishes indicative US tiers, but all pricing routes to a private offer after scoping.
Indicative US AWS Marketplace tiers (12-month, private offer after scoping): 2,000 endpoints about $806,000/yr, 10,000 endpoints about $1,682,000/yr, 50,000 endpoints about $5,987,000/yr. Roughly $10 to $34 per endpoint per month depending on scale.
Cost caveats
- –Indicative AWS pricing starts near 2,000 endpoints at about $806,000/yr, so smaller environments fall outside the published tiers.
- –The service is modular, so OT, identity, cloud, SaaS, and insider-threat coverage are separately scoped modules rather than automatically bundled into a base price.
- –You still license the underlying detection platform (CrowdStrike, Cortex XSIAM, Microsoft, Exabeam), which sits on top of the MXDR fee.
3 more+−
- –Quote-only via private offer after scoping. AWS tiers are US-only indicative prices that vary by region, module mix, and data volume.
- –No public MTTD, MTTR, or contractual response SLA, so response commitments must be negotiated during scoping.
- –Data retention, export rights, and detection-content portability are not published.
What costs extra (6)+−
- –Underlying detection platform licensing (CrowdStrike Falcon, Cortex XSIAM, Microsoft, Exabeam, Splunk), which the client provides or Deloitte procures
- –Additional MXDR modules beyond base scope (OT PDR, Identity PDR, Insider Threat, Attack Surface and Vulnerability Management, SaaS PDR, Cloud Security PDR)
- –Incident response as a selectable module, plus full digital forensics engagements scoped as their own workstream through Deloitte's Cyber practice
- –Cyber advisory and SOC transformation work
- –Higher-volume data ingestion and log source onboarding
- –Offensive testing (red and purple team) through the broader Deloitte Cyber practice
Warranty conditions+−
No public breach warranty found for MXDR by Deloitte.
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Reputation
Deloitte was named a Leader in the inaugural IDC MarketScape for Worldwide MDR Services 2024 and a Leader in the inaugural 2026 IDC MarketScape for Worldwide OT Security Services, and Gartner ranked it No. 1 in security services by revenue. Independent buyer reviews for the MDR product itself are scarce: Gartner Peer Insights lists Deloitte Managed Security Services Worldwide with only a handful of reviews and no MDR-specific product page, PeerSpot has no MXDR reviews, and no substantive Reddit discussion was found. Analyst and market-share recognition is strong, but practitioner-side validation is thin.
Common complaints
- ×Almost no independent MDR-specific practitioner reviews exist to validate the service
No substantive Reddit discussion of MXDR by Deloitte was found. Deloitte's cyber work surfaces in enterprise procurement and analyst contexts rather than practitioner forums like r/msp or r/cybersecurity.
Questions to ask
- 1.
Which of the 11 MXDR modules are in our base scope, and which surfaces (OT, identity, cloud, SaaS, insider threat) are priced as separate modules?
- 2.
Which detection platform will you deploy or operate on (CrowdStrike Falcon, Cortex XSIAM, Microsoft), and who licenses it, us or Deloitte?
- 3.
Which response actions will your analysts take autonomously versus requiring our approval, and how are those playbooks agreed per platform?
- 4.
What is bundled in the Incident Response module, and at what point does a forensic engagement become a separate DFIR workstream and fee?
- 5.
The AWS tiers start at 2,000 endpoints. What does pricing look like at our size and region, and what drives movement between tiers?
- 6.
What contractual response-time commitments will you make, given no MTTD or MTTR is published?
- 7.
Which delivery center handles our account, and for Australian scope, is delivery through ParaFlare with sovereign data handling?
- 8.
What data retention, raw-data export rights, and detection-content portability apply if we leave?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
