Overview
Updated Jun 5, 2026
UK-owned MDR from Sapphire, delivered by a UK-based CREST-accredited SOC. Sapphire combines SIEM, EDR, threat intelligence, proactive hunting, behavioural analytics, case management and incident-response hours as standard. It fits UK organisations that want a sovereign services firm with IT and OT security depth, but buyers should confirm exact EDR actions, response authority and SLA terms during procurement.
Buyer fit
Good fit when
- ✓UK organisations that want MDR from a UK-owned provider with a UK-based CREST-accredited SOC
- ✓Teams that need MDR plus OT SOC, incident response, digital forensics or compliance support
- ✓Mid-market and enterprise buyers that want SIEM, EDR, threat intelligence and analyst-led case management
Watch out when
- ×Buyers that need public MDR pricing or contractual response SLAs before sales engagement
- ×Teams that require a named EDR action list such as endpoint isolation and account disable on the public page
- ×Organizations that want a pure-play MDR provider without broader consulting and managed-services scope
Coverage
4 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote.
How pricing works+−
Sapphire does not publish MDR package pricing.
Not published
Cost caveats
- –Public pages do not publish response SLAs or exact response-authority rules.
- –MDR, MXDR and OT SOC scope can differ materially, so buyers should define monitored surfaces in the order form.
- –The page publishes vendor-reported comparative metrics without independent methodology.
1 more+−
- –IR hours are included as standard, but buyers should confirm number of hours, coverage triggers and overage rates.
What costs extra (4)+−
- –Exact MDR pricing requires a Sapphire quote
- –Managed SIEM, MDR and MXDR package scope should be separated during quote review
- –OT SOC, digital forensics, incident response, vulnerability management and third-party risk services may have separate scope
- –Exabeam, Microsoft, EDR and SIEM licensing can affect total cost
Team and access
Certifications
Reputation
Sapphire has limited MDR-specific community review volume. The public buyer case is strongest for UK ownership, UK-based SOC delivery, CREST SOC accreditation and IT/OT services depth. Buyers should validate response authority, price, metrics and the exact split between MDR, MXDR, OT SOC and incident-response work.
What customers praise
- ✓100% UK-owned and UK-based SOC positioning
- ✓CREST SOC accreditation supports regulated-buyer diligence
- ✓IT and OT security services can support mixed environments
Common complaints
- ×No public MDR pricing
- ×No public contractual MDR response SLA
- ×Limited independent MDR-specific review volume
No meaningful Reddit signal found for Sapphire MDR specifically.
Questions to ask
- 1.
Are we buying Managed SIEM, MDR, MXDR or OT SOC coverage?
- 2.
Which EDR, SIEM, cloud, SaaS, network and OT sources are included in our quote?
- 3.
Which response actions can Sapphire take directly, and which require our approval?
- 4.
How many incident-response hours are included as standard, and what triggers overage?
- 5.
What contractual SLA applies to high-severity triage, escalation and containment?
- 6.
Which vendor-reported metrics apply to our service tier, and what methodology supports them?
- 7.
What case data, reports, tuning content and threat-intelligence context can we export if we leave?
- 8.
Which CREST SOC scope, UK SOC location and analyst certifications apply to our contract?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response workflows are described, but exact standard containment actions are not public.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
