Best Cyber Solutions Request service

Services & pricing

Managed Detection and Response, sized for small teams.

A person reading your alerts, software that contains threats the moment they appear, and prices you can see before you ever get on a call.

Mesh · Acme Design · mbp-07one incident

Overnight, automatically

  1. Detected CriticalChrome Safe Storage key read from the Keychain and 5 related alerts on this Mac · T1555.001
  2. Contained AutoSuspended 2 processes, quarantined the LaunchAgent, blocked 203.0.113.45 TTD<1sTTR2s

Next business morning, a person

  1. Reviewed Analyst confirmed the chain and isolated the Mac
  2. Escalated Summary and next steps in your Slack channel Reset the user's browser sessions and passwords
  3. Hunted Every other Acme Design machine checked: No other matches
A fictional demo Mac. Detections, actions and timings match the real Mesh console. See the full example.

Monitoring plans

Three plans. All of them contain threats automatically.

Every plan gets the same monitoring, the same automated response and the same analyst. What changes is how many machines are covered, and how much of our time comes with it. We recommend Contain+ for teams that field security questionnaires.

Solo

From

$49 / month · up to 3 endpoints

  • Continuous monitoring on every enrolled Mac and Linux machine
  • Automated response on every detection, around the clock
  • Human triage and investigation during business hours
  • Continuous threat hunting, with a monthly report
  • Email and Slack escalation
  • No onboarding fee

Contain

From

$99 / month · up to 10 endpoints

  • Everything in Solo — the same monitoring, response, analyst and hunting
  • Sized for a team, with up to 10 Mac and Linux endpoints
  • Add machines as you grow, $9 / month each
  • Guided onboarding and baseline tuning available
Recommended

Contain+

From

$149 / month · up to 15 endpoints

Just $50 a month more than Contain.

  • Everything in Contain, for up to 15 endpoints
  • Response policy tuned to how your team actually works
  • Quarterly posture review call
  • Help answering security questionnaires
  • Priority escalation

Side by side

What each plan includes.

SoloContainContain+
Automated detection and containment, around the clockIncludedIncludedIncluded
Human triage, 8am–6pm Eastern, Mon–FriIncludedIncludedIncluded
Continuous threat huntingIncludedIncludedIncluded
Monthly report, with every threat hunt we ranIncludedIncludedIncluded
Email and Slack escalationIncludedIncludedPriority
Scouter's console on your own machinesIncludedIncludedIncluded
Response policy tuningStandard policyStandard policyCustom
Quarterly posture review——Included
Security questionnaire help——Included
Endpoints includedUp to 3Up to 10Up to 15
Additional endpoints—$9 / month each$9 / month each
OnboardingNoneFrom $500From $500
Starting price$49 / month$99 / month$149 / month

How pricing works

Starting prices, stated plainly.

Each plan has a monthly base that covers a set number of machines. Past that, machines are priced per month, and the rate falls as your fleet grows, so you can work out your own number before you call us. There is no minimum: One machine is enough to start, and there's no bundled helpdesk you didn't ask for.

Machines beyond your planEach, per month
Up to 25$9
26 and above$6
More than 50Quoted, and the rate keeps falling
  • Onboarding, from $500 one-time: Deployment, baseline tuning and your response policy, rolled out in stages. Waived when you pay annually, and there's no onboarding fee on Solo.
  • Annual prepay gets two months free.
  • Assessment credit: $500 of a Compromise Assessment fee is credited toward your first year if you continue within 60 days.
  • 30-day exit either way, with your data exported on the way out.

For example: 12 machines on Contain is $117 a month, 30 machines is $264, and 50 machines is $384.

Coverage

What's monitored, and what happens when something fires.

Platforms

macOS, and Linux servers and workstations running Debian or Ubuntu. Windows is in development; we won't put a date in your contract until it ships.

Automated response

Suspend a process, quarantine a file or block a network address, automatically. An analyst can also isolate a Mac from the network. Every action is reversible, and we'll pause, narrow or undo any of it when you ask.

Silence is an alert

If a machine's agent stops reporting, that's treated as a detection in its own right. Disabling the agent is one of the first things an attacker tries.

Start here

Not ready to commit to monitoring?

The Compromise Assessment is a fixed-fee, one-week look at what's already on your machines. It stands on its own, and it's where we recommend starting.

From

$2,000 fixed fee

About the assessment

Straight answer on hours. Automated response is continuous. Human triage, investigation and judgment happen 8am–6pm Eastern, Monday to Friday. We are not a 24/7 staffed SOC and won't describe ourselves as one. More in the FAQ.

Tell us about your fleet.

We'll recommend a plan and send an exact quote, usually within one business day.