Buyer fit
Good fit when
- ✓Buyers already committed to Microsoft Defender and Sentinel that want a services firm to manage detection and response
- ✓Organizations that want attack-surface management and XDR monitoring reviewed together
- ✓UK and South Africa buyers that prefer a provider with SOC delivery in those regions
Watch out when
- ×Buyers that need public MDR pricing before sales
- ×Teams that require named autonomous endpoint or identity actions in public docs
- ×Organizations that want a pure-play MDR provider with broad published third-party EDR integrations
Coverage
2 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote.
How pricing works+−
Performanta does not publish MDR, Safe XDR or managed SOC package pricing.
Not published
Cost caveats
- –Public pages do not publish MDR pricing, contract minimums or service-credit language.
- –The explicit MDR offer is tied to Defender for Endpoint, so Microsoft licensing and customer tenant readiness can drive total cost.
- –Public pages do not define default MDR response authority, so buyers need the managed-technology boundary in writing.
2 more+−
- –Cloud and SaaS coverage appear tied to Microsoft security controls and Safe XDR scope, so non-Microsoft telemetry should be confirmed early.
- –Incident response is listed as a consulting service, so buyers should confirm what is included in MDR versus a separate incident-response engagement.
What costs extra (4)+−
- –Exact MDR and Safe XDR pricing requires a Performanta quote
- –Microsoft Defender and Microsoft Sentinel licensing may be separate from Performanta's service fee
- –Incident response and digital forensics scope should be priced separately
- –Attack surface management, security assurance, managed controls and vulnerability management may be separate service lines
Team and access
Reputation
No meaningful MDR-specific buyer-review signal was found in major English-language review communities during this pass. The public buyer case rests on Performanta's Microsoft security focus, UK and South Africa SOC operations, Safe XDR platform, threat-hunting process and incident-response consulting depth. Buyers should validate pricing, response authority, non-Microsoft telemetry support and exact incident-response inclusion directly.
No meaningful Reddit signal found for Performanta MDR specifically.
Questions to ask
- 1.
Is our scope the Defender for Endpoint MDR service, Safe XDR, managed SOC or a mix of the three?
- 2.
Which response actions can Performanta take directly, and which require our team to execute?
- 3.
Which Microsoft licenses and Sentinel data costs sit outside the service fee?
- 4.
Which non-Microsoft EDR, SIEM, cloud and SaaS telemetry sources are supported in our environment?
- 5.
What incident-response work is included in MDR and what requires a separate consulting engagement?
- 6.
What contractual SLA applies to high-severity triage, escalation and containment?
- 7.
What detection rules, playbooks, reports and case history can we export if we leave?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response workflows are described, but exact standard containment actions are not public.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
