
MDR Pricing Explained: Per-Endpoint, Per-User and the Hidden Lines
Per endpoint, per user, per seat or per gigabyte — and the log ingestion charge that turns a predictable contract into a variable one.
GuardsArm Team
Security Experts

MDR quotes are hard to compare because providers price on different units and include different things. Two proposals with the same monthly figure can differ by a factor of two in what they actually cover.
The pricing units
| Unit | How it works | Watch for |
|---|---|---|
| Per endpoint | Servers and workstations counted | Servers often priced higher than workstations |
| Per user | Headcount-based | Simpler, but decoupled from actual device count |
| Per asset, tiered | Bands rather than linear | Crossing a band boundary is a step change |
| Per GB ingested | Log volume | The least predictable and most common overrun |
| Flat platform fee plus usage | Hybrid | The usage component is where the risk sits |
Per-GB ingestion is the line that bites. Your log volume grows with your estate, your verbosity settings and any new data source you add. A contract priced against last year's volume can be materially more expensive this year without anyone making a decision. Ask for a volume estimate, a rate card above it, and a mechanism for tuning noisy sources down. See logging strategy.
What drives the number
Coverage hours. 24/7 is what most buyers assume they are getting and not always what they are quoted. Confirm explicitly, including holidays.
Response depth. The largest differentiator, and the one that separates MDR from a managed SIEM. Does the provider notify you, or do they act — isolate a host, disable an account, block an address? Authorised response costs more and is the whole point. See MDR versus MSSP.
Technology. Some providers require their own stack; some run on the EDR you already have. Bringing your own licence can reduce the MDR line while leaving the licence cost elsewhere — compare totals, not line items.
Log retention. Hot searchable retention is expensive, archive is cheap. A low headline price sometimes comes with thirty days of hot retention, which is shorter than the dwell time of a typical intrusion and shorter than most regulatory expectations.
What should be included, and often is not
- Onboarding and tuning — the first sixty days determine whether the service is useful or a noise generator
- Threat hunting, as a scheduled activity rather than a marketing word
- Incident response hours beyond containment, or at least a defined handover point
- Reporting that an executive can read
- Detection engineering — new detections as threats change, not a static rule set at go-live
The real comparison
Against building internally, the arithmetic is not close for most organisations. 24/7 coverage requires five to six analysts to staff a rotation sustainably, plus tooling, plus the recruitment and retention problem in a market where experienced analysts are scarce. Below a certain size, buying is cheaper and better. See build, buy or hybrid.
Against doing nothing, the comparison is dwell time. An intrusion detected in hours is an incident; the same intrusion detected in six weeks is a breach notification.
Reading a quote properly
Put every proposal into the same table before comparing totals:
| Line | Provider A | Provider B |
|---|---|---|
| Pricing unit and count | ||
| Coverage hours, confirmed | ||
| Response actions they may take without asking | ||
| Hot log retention | ||
| Archive retention | ||
| Ingestion allowance and overage rate | ||
| Technology included, or bring your own | ||
| Onboarding cost and duration | ||
| IR hours included | ||
| Contract length and exit terms |
Two lines decide most disputes later. Ingestion allowance and overage rate determines whether next year's invoice resembles this year's. Response actions without asking determines whether you bought detection or response.
The exit question
MDR contracts are stickier than they look. If the provider owns the platform, the detections and the historical data, leaving means starting again — no history to search, no tuning, no baseline.
Ask before signing: on termination, do you get your historical log data, in what format, and for how long is it available? A provider confident in their service answers this without difficulty.
Where to start
Count your endpoints and estimate your daily log volume before requesting quotes. Those two numbers determine most of the price, and providing them makes proposals comparable instead of each vendor guessing differently.
GuardsArm provides managed detection and response with authorised containment. See MDR services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


