Buyer fit
Good fit when
- ✓Mid-market to enterprise organizations (500+ assets) wanting full SIEM data transparency alongside MDR
- ✓Security teams wanting active remediation via Velociraptor without a fully outsourced model
- ✓Organizations that value analyst pod continuity and environment familiarity over time
Watch out when
- ×Organizations with fewer than 500 assets (minimum requirement)
- ×Companies unwilling to deploy Rapid7 Insight Agent across 80%+ of their environment
- ×Organizations needing OT/ICS coverage or fully technology-agnostic MDR
Coverage
5 of 6 attack surfaces in the base price; the rest are separately priced.
Platform
Additional capabilities
Incident response
Pricing
Per-asset monthly pricing.
Checked Jun 2026
How pricing works+−
Three tiers: Essential, Advanced, Ultimate. Managed Threat Complete (MTC) bundles MDR + SIEM + VM + SOAR. MDR Elite available as standalone MDR service.
Third-party estimate: starting ~$17/asset/month. Mid-market deployments typically $60K-$80K/year. Enterprise $150K+/year.
Cost caveats
- –Requires Rapid7 Insight Agent on 80%+ of supported assets, minimum 500 assets
- –Breach warranty and unlimited DFIR only available on Ultimate tier
- –Essential tier has no dedicated cybersecurity advisors (Support Center only)
1 more+−
- –Custom event sources and custom detections only on Advanced/Ultimate tiers
What costs extra (5)+−
- –MDR for Microsoft Defender (dedicated service launched Jan 2026)
- –Vulnerability Management (InsightVM, separate product)
- –Application Security (InsightAppSec, separate product)
- –Custom event source integration (Advanced/Ultimate tiers only)
- –InsightConnect SOAR (unlimited in MTC, separate otherwise)
Warranty conditions+−
Only available with Managed Threat Complete Ultimate tier. Covers forensics, legal counsel, post-incident response, PR. Coverage based on environment size. Must maintain security best practices.
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Certifications
Reputation
PeerSpot 8.6/10 (MDR). Gartner SIEM MQ recognized 7th year (2025). MITRE 2023: all 19 Turla attack phases detected. Praised for data transparency and analyst pod familiarity. Company underwent 18% layoffs in Aug 2023, explored PE sale in Q4 2024 (no deal), Jana Partners activist investor added 3 board seats in 2025. Revenue $860M (FY2025), guidance for 2026 slightly lower ($835-843M).
What customers praise
- ✓Full SIEM query access to 13 months of data with no black box
- ✓Analyst pod model provides environment familiarity and partnership feel over time
- ✓Active Response with Velociraptor for direct endpoint remediation without reimaging
Common complaints
- ×Requires Rapid7 Insight Agent on 80%+ of assets, significant platform lock-in
- ×Pricing opacity and unexpected overage charges reported in reviews
- ×Company instability: 18% layoffs (2023), activist investor, PE interest, declining 2026 guidance
Limited recent discussion. One 2024 r/ITManagers review praised 24/7 monitoring and no overage charges for log ingestion. Data transparency positioning resonates with practitioners.
Questions to ask
- 1.
What is the exact per-asset pricing for our environment size (minimum 500 assets), and how does cost scale?
- 2.
How does the analyst pod assignment work, and how many customers does our pod serve?
- 3.
What specific Active Response actions can analysts take via Velociraptor, and how do we configure the Slack ChatOps approval workflow?
- 4.
How does the breach warranty qualification work, and what best-practice requirements must we meet?
- 5.
How does Managed Threat Complete Ultimate differ from MDR Elite in terms of included services?
- 6.
What happens to our 13 months of SIEM data if we don't renew, and can we export it?
Evidence
Sources reviewed
Main public source used for the provider profile.
Technical documentation for Active Response threat containment capabilities
Official terms and conditions for Managed Detection and Response services
Comprehensive compliance certifications including SOC 2, ISO 27001, and GDPR
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
