Buyer fit
Good fit when
- ✓SMB and lower mid-market organizations that want a SOC layer over their existing endpoint stack
- ✓Teams that want guidance and threat hunting but prefer to execute response themselves
- ✓Existing OpenText or Webroot customers consolidating onto one vendor for endpoint and MDR
Watch out when
- ×Buyers who need analysts to isolate endpoints or kill processes without customer approval
- ×Teams that need a published response-time SLA with financial backing
- ×Organizations with OT or ICS environments needing dedicated industrial coverage
Coverage
4 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote, not published.
How pricing works+−
Sold direct and through OpenText partner channel.
Not published
Cost caveats
- –Co-managed model means the customer's team still does the actual containment work
- –No published SLA, contractual response commitments must be negotiated
- –Headline detection metrics come from a 2021 launch announcement and have not been independently verified
What costs extra (3)+−
- –Webroot endpoint protection if the customer needs it bundled
- –OpenText security awareness training
- –Incident response retainer
Team and access
Certifications
Reputation
Public review coverage of OpenText Core MDR is thin. Capterra lists the product with zero reviews, and there is no Gartner Peer Insights MDR profile or G2 page with a meaningful review base. Practitioner discussion mostly references the broader OpenText Cybersecurity portfolio and the Webroot heritage rather than the MDR service itself.
What customers praise
- ✓BrightCloud threat intelligence is well regarded inside OpenText's broader product line
- ✓Co-managed model appeals to teams that want a SOC layer without giving up control
- ✓Backed by a large public software vendor with long enterprise track record
Common complaints
- ×Very limited public review base for the MDR service specifically
- ×Headline detection metrics are vendor-published and date back to the 2021 launch
- ×Co-managed positioning means the customer still owns response execution
Limited Reddit discussion of OpenText Core MDR specifically. r/msp threads tend to surface Webroot MDR powered by Blackpoint, which is a separate product.
Questions to ask
- 1.
What response actions does your SOC take on our behalf, and what actions do we have to execute ourselves under the co-managed model?
- 2.
Are the 30-minute MTTD and 99 percent detection figures from the 2021 launch still reflected in current contracts, and what response SLAs will you commit to in writing?
- 3.
How does OpenText Core MDR differ from Webroot MDR powered by Blackpoint, and which one fits our environment?
- 4.
Which third-party EDR and SIEM products do your analysts actively support, and which are best-effort log ingestion only?
- 5.
What does the SOC do at 3am if our team is unreachable? Do they wait, escalate, or take any pre-approved actions?
- 6.
What happens to our detection content, custom rules and alert history if we move off the platform?
- 7.
Is there an option to add Webroot endpoint protection bundled into the contract, and how does that change pricing?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response workflows are described, but exact standard containment actions are not public.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
