Buyer fit
Good fit when
- ✓Swiss, German and Austrian buyers that want MDR from DACH-based SOCs
- ✓Regulated organizations that need Swiss data-residency options and incident-response depth
- ✓Teams that want Managed SOC or Co-Managed SOC on top of an open XDR architecture
Watch out when
- ×Buyers that need public MDR pricing before sales
- ×Teams that require named autonomous endpoint or identity actions in public docs
- ×Organizations that want a published global follow-the-sun SOC footprint outside DACH
Coverage
4 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote.
How pricing works+−
InfoGuard does not publish MDR package pricing.
Not published
Cost caveats
- –Public pages do not publish MDR pricing, contract minimums or service-credit language.
- –Named autonomous response actions are not published, so response authority should be written into the contract.
- –InfoGuard offers both Managed SOC and Co-Managed SOC, so buyer-side staffing and responsibility can vary by model.
2 more+−
- –Data can stay at the customer premises or in Swiss data centres, which may change architecture and retention cost.
- –Incident Response Retainer exists as a separate offer, so buyers should confirm exactly what incident-response work is included in MDR.
What costs extra (4)+−
- –Exact MDR pricing requires an InfoGuard quote
- –Managed SOC, Co-Managed SOC and Incident Response Retainer scope should be priced separately
- –Sensor, SIEM, XDR, SOAR and data-retention scope can affect total cost
- –Penetration testing, red teaming, cloud security and managed network services may be separate from MDR
Team and access
Certifications
Reputation
No meaningful MDR-specific buyer-review signal was found in major English-language review communities during this pass. The public buyer case rests on InfoGuard's Swiss and German SOC delivery, 90+ SOC and CSIRT experts, open XDR platform, data-residency options and incident-response credentials. Buyers should validate pricing, response authority, named integrations and exact co-managed responsibilities directly.
No meaningful Reddit signal found for InfoGuard MDR specifically.
Questions to ask
- 1.
Are we buying Managed SOC, Co-Managed SOC or a narrower MDR scope?
- 2.
Which response actions can InfoGuard take directly and which require our approval?
- 3.
What incident-response work is included in MDR and what requires an Incident Response Retainer?
- 4.
Which endpoint, network, cloud, identity, IoT and OT sources are required for go-live?
- 5.
Will our data stay on our premises or in InfoGuard's Swiss data centres, and what retention period is included?
- 6.
Which SIEM, XDR, EDR and ticketing integrations are standard versus custom?
- 7.
What contractual SLA applies to high-severity triage, escalation and containment?
- 8.
What detection content, cases, reports and log data can we export if we leave?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response workflows are described, but exact standard containment actions are not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
