Buyer fit
Good fit when
- ✓Enterprise organizations wanting open XDR with existing CrowdStrike, Defender, SentinelOne, or Carbon Black EDR
- ✓Organizations valuing deep threat intelligence from CTU (now Sophos X-Ops)
- ✓Companies needing OT/ICS MDR coverage alongside IT MDR
Watch out when
- ×Buyers concerned about organizational stability after Sophos acquisition and significant headcount losses
- ×Buyers wanting fast onboarding (30-45 day typical deployment is slower than competitors)
- ×SMBs needing affordable MDR (per-endpoint pricing, $60K-$320K+/year reported)
Coverage
4 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Per-endpoint pricing, quoted per environment with no public list price.
Checked Jul 2026
Sourced figures
Taegis XDR software license (TG-XDR-SW-000500-COM) plus Taegis Managed XDR service…
Shawnee Mission USD 512 board records (BoardDocs) · 2024-02-08
12-month contract, managed 'Taegis MDR Combo' dimension covering 10,001 to 25,000…
AWS Marketplace, Secureworks Taegis XDR listing · checked Jul 2026
12-month contract, 'TDR - 1000 Endpoints' dimension. This is Taegis XDR…
AWS Marketplace, Secureworks Taegis XDR listing · checked Jul 2026
All 5 sourced figures+−
Blended annual contract value across the Secureworks/Taegis suite (ManagedXDR, NDR…
Vendr marketplace, Secureworks · checked Jul 2026
Single buyer's negotiated per-endpoint rate, pre-acquisition (2020). Vendor…
PeerSpot, reviewer1310127 (Security Consultant) · 2020-12-06
How pricing works+−
Per-endpoint, quote-based (custom). Licensed by device count (excludes firewalls and routers). Tiers: MDR Essentials, MDR, MDR Plus, MDR Enhanced, plus add-ons (MDR for OT, Elite Threat Hunting, Emergency IR via Service Units).
Sold direct and via resellers (CDW, SHI) and AWS/Azure marketplaces by private offer. No public list price on secureworks.com or sophos.com.
Cost caveats
- –Taegis Endpoint Agent reaches end of support on 2027-07-31 (Japan 2028-07-31); all customers must migrate to Sophos Endpoint. The license is included, but the fleet-wide agent swap is a migration project to budget before that date.
- –Sophos acquisition closed Feb 2025; secureworks.com/services/mdr now redirects to the Sophos MDR page and Sophos Fusion (GA reported 2026-08-15) points toward long-term platform consolidation. Confirm Taegis roadmap continuity before multi-year commitments.
- –Base-tier 'unlimited' remote IR is conditional (confirmed human adversary, 7+ days of prior telemetry, legal-counsel matters excluded); full Emergency IR requires Service Units. MDR Essentials caps remote IR at 40 hours per year.
1 more+−
- –Per-endpoint pricing varies widely (roughly $70-$170/endpoint reported, pre-acquisition) and is negotiable; anchor on endpoint-band quotes, not the blended suite median.
What costs extra (7)+−
- –Emergency Incident Response beyond the tier allowance (purchased as Service Units)
- –Proactive Services (Service Units)
- –Elite Threat Hunting add-on
- –MDR for OT (operational technology add-on)
- –Extended data retention beyond 12 months (up to 48 additional months for a fee)
- –Penetration / adversarial testing (AWS Marketplace lists External Small at $9,280/yr)
- –Vulnerability management services
Warranty conditions+−
No breach warranty on Taegis MDR. Conditional unlimited remote IR for confirmed active-adversary incidents is included in the standard tiers (Essentials caps it at 40 hours/year). Note: the $1M Sophos Breach Protection Warranty belongs to the separate Sophos MDR Complete product, not Taegis.
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Reputation
G2 4.6/5 (48 reviews). PeerSpot 7.8/10 (#2 MSSP, #15 MDR). Glassdoor 3.5/5 with 64% recommending. Taegis achieved 100% visibility and 95% detection in MITRE evaluation. Product quality respected, but organizational stability is the concern after Sophos acquisition and significant headcount losses.
What customers praise
- ✓CTU (now Sophos X-Ops) still publishing threat research, intelligence capability maintained
- ✓100% MITRE ATT&CK visibility and 95% detection in inaugural evaluation
- ✓Remote IR for confirmed active-adversary incidents included in base MDR (unlimited on standard tiers, 40 h/yr cap on Essentials)
Common complaints
- ×~6% workforce cut post-Sophos close on top of ~44% headcount loss 2021-2024
- ×Long-term platform consolidation into Sophos Central creates migration uncertainty for enterprise buyers
- ×Console usability and reporting quality criticized per multiple reviewers
Limited publicly visible Reddit discussions in r/msp, r/cybersecurity, r/sysadmin as of February 2026.
Questions to ask
- 1.
What is the long-term platform plan: will Taegis remain independent or fully merge into Sophos Central?
- 2.
After the workforce reduction post-acquisition, what is the current analyst staffing across the 5 SOCs?
- 3.
If we bring our own EDR, do we get the same detection fidelity as using the Taegis Agent plus Sophos Endpoint?
- 4.
What data can we export if we leave, and can we take detection rules, playbooks, and historical data?
Evidence
Sources reviewed
Public-data caveats
- –SLA caveat: 60-minute investigation SLA from case initiation to customer notification. Service-level credits apply if missed. This is an investigation SLA, not a containment or remediation guarantee.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
