Buyer fit
Good fit when
- ✓Dutch organisations that want MDR from a Netherlands-based cybersecurity services firm
- ✓Mid-market and enterprise teams that want T-SOC monitoring tied to XDR, SOAR and threat intelligence
- ✓Buyers that value local incident response, red team and advisory capabilities around the MDR service
Watch out when
- ×Buyers that need public MDR pricing or contractual response SLAs before sales engagement
- ×Teams that require a public list of endpoint isolation, account disable or network blocking actions
- ×Organizations that want a pure-play MDR provider without broader services-firm scope
Coverage
4 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
Cloud
Additional capabilities
Incident response
Pricing
Custom quote.
How pricing works+−
Tesorion does not publish MDR package pricing.
Not published
Cost caveats
- –Public pages do not publish response SLAs or named default response actions.
- –The public MDR page says mitigation is immediate where possible, but does not specify what Tesorion can do without customer approval.
- –T-CERT incident response is prominent, but buyers should confirm whether IR hours are included in MDR or sold separately.
1 more+−
- –Tesorion lists broad coverage across domains, so buyers should confirm which monitored sources are included in base MDR.
What costs extra (4)+−
- –Exact MDR pricing requires a Tesorion quote
- –T-CERT incident response, EDR, NDR, managed firewall, pentesting, red team and advisory work may be separate
- –Partner technology such as SentinelOne, Vectra AI, Recorded Future, Halcyon, Qualys, Proofpoint and KnowBe4 may affect total cost
- –Cloud, SaaS, identity, network and application source scope should be defined in the quote
Team and access
Certifications
Reputation
Tesorion has limited MDR-specific public review volume. The public buyer case rests on Dutch delivery, T-SOC operations, XDR and SOAR correlation, threat intelligence and nearby T-CERT incident response. Buyers should validate pricing, response authority, included source scope and whether T-CERT support is included before signing.
What customers praise
- ✓Dutch provider with Netherlands offices and local service delivery
- ✓MDR is tied to XDR, SOAR, threat intelligence and MITRE ATT&CK use cases
- ✓T-CERT incident response and offensive security teams can support broader security work
Common complaints
- ×No public MDR pricing
- ×No public contractual MDR response SLA
- ×Specific response actions and T-CERT inclusion need quote-level confirmation
No meaningful Reddit signal found for Tesorion MDR specifically.
Questions to ask
- 1.
Which endpoint, identity, network, cloud and application sources are included in the MDR quote?
- 2.
Which response actions can Tesorion take directly, and which require our approval?
- 3.
Is T-CERT incident-response support included in MDR, or is it sold as a separate retainer or project?
- 4.
What contractual SLA applies to high-severity triage, escalation and containment?
- 5.
Which partner technologies are required, optional or already covered by our existing licenses?
- 6.
How are MITRE ATT&CK use cases tuned for our environment, and what detection content can we export if we leave?
- 7.
Which Netherlands SOC location, shift model and analyst certifications apply to our contract?
- 8.
How are cloud, SaaS, identity and OT sources priced if we add them after onboarding?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response workflows are described, but exact standard containment actions are not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
