Back to Blog
Managed Services
4 min read

MDR Pricing Explained: Per-Endpoint, Per-User and the Hidden Lines

Per endpoint, per user, per seat or per gigabyte — and the log ingestion charge that turns a predictable contract into a variable one.

GuardsArm Team

Security Experts

September 25, 2026

MDR pricing models and cost drivers

MDR quotes are hard to compare because providers price on different units and include different things. Two proposals with the same monthly figure can differ by a factor of two in what they actually cover.

Units differ by vendor
Endpoint, user, asset band or ingested volume
Ingestion is the overrun
Log volume grows without anyone deciding to grow it
Response depth is the point
Notifying you is not the same as acting

The pricing units

UnitHow it worksWatch for
Per endpointServers and workstations countedServers often priced higher than workstations
Per userHeadcount-basedSimpler, but decoupled from actual device count
Per asset, tieredBands rather than linearCrossing a band boundary is a step change
Per GB ingestedLog volumeThe least predictable and most common overrun
Flat platform fee plus usageHybridThe usage component is where the risk sits

Per-GB ingestion is the line that bites. Your log volume grows with your estate, your verbosity settings and any new data source you add. A contract priced against last year's volume can be materially more expensive this year without anyone making a decision. Ask for a volume estimate, a rate card above it, and a mechanism for tuning noisy sources down. See logging strategy.


What drives the number

What actually differentiates MDR quotesResponse authority, coverage hours, retention, technology ownership, onboarding and ongoing detection engineering.Response authorityCan they isolate, disable, block — or only tell you?Coverage hours24/7 including holidays, confirmed in writingLog retention, hot versus archiveThirty days hot is shorter than typical dwell timeTechnology ownershipTheir stack or yours — compare totals, not line itemsOnboarding and tuningThe first sixty days decide whether it worksDetection engineeringNew detections over time, not a static rule set
Two quotes at the same price can differ twofold on these.

Coverage hours. 24/7 is what most buyers assume they are getting and not always what they are quoted. Confirm explicitly, including holidays.

Response depth. The largest differentiator, and the one that separates MDR from a managed SIEM. Does the provider notify you, or do they act — isolate a host, disable an account, block an address? Authorised response costs more and is the whole point. See MDR versus MSSP.

Technology. Some providers require their own stack; some run on the EDR you already have. Bringing your own licence can reduce the MDR line while leaving the licence cost elsewhere — compare totals, not line items.

Log retention. Hot searchable retention is expensive, archive is cheap. A low headline price sometimes comes with thirty days of hot retention, which is shorter than the dwell time of a typical intrusion and shorter than most regulatory expectations.


What should be included, and often is not

  • Onboarding and tuning — the first sixty days determine whether the service is useful or a noise generator
  • Threat hunting, as a scheduled activity rather than a marketing word
  • Incident response hours beyond containment, or at least a defined handover point
  • Reporting that an executive can read
  • Detection engineering — new detections as threats change, not a static rule set at go-live
Ask what happens at 3am on a Sunday
The single most revealing question in an MDR evaluation. Who is awake, what are they authorised to do without waiting for you, and how quickly does a human — not an automated email — make contact. The answer separates genuine managed response from an alert forwarding service.

The real comparison

Against building internally, the arithmetic is not close for most organisations. 24/7 coverage requires five to six analysts to staff a rotation sustainably, plus tooling, plus the recruitment and retention problem in a market where experienced analysts are scarce. Below a certain size, buying is cheaper and better. See build, buy or hybrid.

Against doing nothing, the comparison is dwell time. An intrusion detected in hours is an incident; the same intrusion detected in six weeks is a breach notification.


Reading a quote properly

Put every proposal into the same table before comparing totals:

LineProvider AProvider B
Pricing unit and count
Coverage hours, confirmed
Response actions they may take without asking
Hot log retention
Archive retention
Ingestion allowance and overage rate
Technology included, or bring your own
Onboarding cost and duration
IR hours included
Contract length and exit terms

Two lines decide most disputes later. Ingestion allowance and overage rate determines whether next year's invoice resembles this year's. Response actions without asking determines whether you bought detection or response.


The exit question

MDR contracts are stickier than they look. If the provider owns the platform, the detections and the historical data, leaving means starting again — no history to search, no tuning, no baseline.

Ask before signing: on termination, do you get your historical log data, in what format, and for how long is it available? A provider confident in their service answers this without difficulty.


Where to start

Count your endpoints and estimate your daily log volume before requesting quotes. Those two numbers determine most of the price, and providing them makes proposals comparable instead of each vendor guessing differently.

GuardsArm provides managed detection and response with authorised containment. See MDR services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.