24×7 SOC Monitoring

Powered by ValueMentor

24×7 security monitoring across your endpoints, identity, cloud and network.

Monitor threats across your wider technology environment — not just your endpoints. Secusy MDR + Managed SIEM combines Elastic-powered security analytics, SentinelOne endpoint protection and 24×7 monitoring by the Encyb security operations team to detect, investigate and help you respond to security threats.
Plans from $999/month.

Plans from$999/month
Ingestion5–15 GB/day included
Retention30 days included
Delivered byRegional Hosting + Global SOC

The definition

What is MDR + Managed SIEM?

MDR + Managed SIEM combines centralized security analytics with continuous human security monitoring, investigation and response guidance. Unlike endpoint-only MDR, the service can monitor supported telemetry from endpoints, identities, cloud infrastructure, firewalls, VPNs and other security systems. Secusy offers two plans — MDR Essential from $999/month (5 GB/day ingestion, 10 SentinelOne Core endpoints) and MDR Advanced from $2,299/month (15 GB/day, 25 endpoints) — both with 30-day retention, 24×7 monitoring and Level 2 guided response.
  • Plans from

    $999/month

  • Ingestion

    5–15 GB/day included

  • Retention

    30 days included

  • Delivered by

    Regional Hosting + Global SOC

Monitor more than your endpoints

Endpoint security provides one view of an attack. Secusy MDR + Managed SIEM brings security-relevant telemetry from supported endpoint, identity, cloud, network and application systems into a centralized monitoring environment, so analysts can investigate suspicious activity using context from multiple security sources rather than relying exclusively on endpoint alerts.

  • Endpoints

    • Windows
    • macOS
    • Linux
    • Servers
    • SentinelOne security telemetry
  • Identity & Productivity

    • Microsoft 365
    • Microsoft Entra ID
    • Google Workspace
    • Authentication systems
  • Cloud Infrastructure

    • AWS
    • Microsoft Azure
    • Google Cloud
  • Network & Security

    • Firewalls
    • VPN infrastructure
    • IDS/IPS
    • Web application firewalls
    • Other supported security infrastructure
  • Applications

    • Authentication logs
    • Security events
    • Selected application logs
    • Other supported security-relevant telemetry

All onboarded telemetry contributes toward your purchased ingestion allowance.

Choose your MDR + Managed SIEM plan

Both plans include the same 24×7 monitoring, investigation and guided response capabilities. Choose based on the size of your environment and the amount of security telemetry you need to monitor.

MDR Essential

Smaller environments

$999/month

Package scope
  • Security log ingestion5 GB/day
  • Monthly pooled ingestion150 GB
  • SentinelOne Core10 endpoints
  • Additional ingestion$135/GB/day

Timeline depends on your readiness, scope complexity and team availability.

Compare MDR Essential and MDR Advanced

FeatureMDR EssentialMDR Advanced
Best forSmaller environmentsGrowing & mid-market environments
Security log ingestion5 GB/day15 GB/day
Monthly pooled ingestion150 GB450 GB
Log retention30 days30 days
SentinelOne Core10 endpoints25 endpoints
Additional ingestion$135/GB/day$120/GB/day
Additional endpoints$5/endpoint/month$5/endpoint/month
Commitment12 months12 months
24×7 SOC monitoring
Alert triage
Security investigation
Threat detection & correlation
Guided response
Incident notification
Monthly security reporting
Elastic-powered SIEM

Additional ingestion is purchased in 2 GB/day increments. Additional endpoints are $5/endpoint/month on either plan.

One-time onboarding: $750. Need more than 31 GB/day or have a complex environment?

Which MDR plan should I choose?

  • Choose MDR Essential if:

    You have a smaller environment and expect to send approximately 5–13 GB of security telemetry per day. Essential gives you the full MDR service without requiring you to purchase capacity you don't currently need.

  • Choose MDR Advanced if:

    You expect approximately 15–31 GB/day, have more endpoints, or anticipate your security telemetry increasing. Advanced starts with 15 GB/day and 25 protected endpoints and provides lower incremental ingestion pricing as your environment grows.

  • Need more than 31 GB/day?

    Larger or more complex environments can be scoped separately.

Elastic-powered security analytics with regional data hosting

Secusy MDR + Managed SIEM is built on Elastic Cloud and deployed on supported AWS or Microsoft Azure cloud regions. Cloud provider and hosting region are selected during onboarding based on customer requirements and Elastic Cloud regional availability.

  • Where available, customer security data can be hosted in-country using an available Elastic Cloud region on AWS or Azure
  • Helps organizations address data residency, regulatory and internal security requirements
  • Cloud provider and hosting region selected during onboarding based on customer requirements

In-country hosting is subject to the availability of an appropriate Elastic Cloud region in the customer's required country.

Example MDR pricing

Your monthly subscription scales predictably with your security telemetry.

FeatureRecommended PlanMonthly Price*
5 GB/dayEssential$999
7 GB/dayEssential$1,269
9 GB/dayEssential$1,539
11 GB/dayEssential$1,809
13 GB/dayEssential$2,079
15 GB/dayAdvanced$2,299
17 GB/dayAdvanced$2,539
21 GB/dayAdvanced$3,019
25 GB/dayAdvanced$3,499
29 GB/dayAdvanced$3,979
31 GB/dayAdvanced$4,219

*Before additional endpoint licenses, extended retention or optional services. More than 31 GB/day? Custom pricing is available.

Monthly pooled ingestion

Security telemetry doesn't necessarily arrive at exactly the same volume every day, so your purchased daily capacity is converted into a monthly pooled ingestion allowance — flexibility for normal variations in daily security log volumes while maintaining your purchased monthly allowance.

  • 5 GB/day150 GB/month
  • 15 GB/day450 GB/month
  • 25 GB/day750 GB/month

Endpoint protection & retention included

Every MDR plan includes SentinelOne Core endpoint protection. MDR Essential includes 10 SentinelOne Core licenses, MDR Advanced includes 25 — additional endpoints cost $5 per endpoint/month on either plan. Both plans include 30 days of log retention; extended retention is available as an add-on, priced per GB, for security investigations, compliance or internal requirements.

  • MDR Essential: 10 SentinelOne Core endpoints included
  • MDR Advanced: 25 SentinelOne Core endpoints included
  • Additional endpoints: $5/endpoint/month on either plan
  • 30-day retention included on both plans
  • Extended retention available, priced per GB

What happens when we detect a threat?

Both MDR Essential and MDR Advanced include Level 2 Guided Response. The level of security monitoring and response does not change based on the plan you select.

  • Detect

    Security telemetry is continuously monitored for suspicious activity and potential threats.

  • Triage

    Encyb SOC analysts review security alerts and available context to identify activity requiring further investigation.

  • Investigate

    Relevant telemetry from onboarded systems is analyzed to understand the nature and available scope of suspicious activity.

  • Notify

    Validated incidents requiring action are escalated to your designated contacts.

  • Guide the Response

    Our analysts provide containment and remediation recommendations and work with your IT or security team through the response process.

  • Document

    Significant incidents and available findings are documented for follow-up.

What does guided response include?

Your organization remains responsible for executing containment, remediation and recovery actions unless separately agreed.

  • Security alert validation
  • Investigation using available onboarded telemetry
  • Incident notification
  • Analysis of available indicators
  • Identification of potentially affected systems where supported by available telemetry
  • Containment recommendations
  • Remediation recommendations
  • Guidance for your IT or security team
  • Incident documentation

Scope boundaries

What's not included

MDR + Managed SIEM is not a replacement for a full digital forensics or incident response engagement. When an incident requires additional expertise, ValueMentor's incident response capabilities can be separately engaged.

  • Extensive digital forensic investigation
  • Malware reverse engineering
  • Large-scale compromise assessments
  • Hands-on system recovery
  • Ransomware negotiation
  • Legal or regulatory incident management
  • On-site incident response
  • Unlimited remediation engineering

Built on Elastic. Protected by SentinelOne. Monitored by Encyb.

  • Elastic-Powered Security Analytics

    Elastic provides the underlying security analytics platform used to centralize, search, correlate and analyze security telemetry.

  • SentinelOne Endpoint Protection

    SentinelOne Core provides endpoint protection and security telemetry. Licenses are included with both MDR plans, with additional endpoints available for $5 per endpoint/month.

  • Encyb Security Operations

    The Encyb security operations team provides 24×7 security monitoring, alert triage, investigation, escalation and guided response.

  • Powered by ValueMentor

    Secusy provides the digital purchasing and service experience backed by ValueMentor's broader cybersecurity testing, assurance, advisory, incident response and managed security capabilities.

How it works

Simple MDR onboarding

Standard onboarding: $750 one-time. Custom integrations or complex environments may require additional onboarding services.

  1. Step 1

    Choose your plan

    Select MDR Essential or MDR Advanced based on your expected security telemetry.

  2. Step 2

    Configure your environment

    Choose additional ingestion capacity, endpoints and retention if required.

  3. Step 3

    Complete onboarding

    Provide the required information about your environment, systems, security technologies and escalation contacts.

  4. Step 4

    Connect your security telemetry

    We configure the agreed supported integrations and SentinelOne endpoints.

  5. Step 5

    Validate monitoring

    Our team validates telemetry flow and establishes the monitoring environment.

  6. Step 6

    Begin 24×7 monitoring

    Your environment transitions into continuous security monitoring, investigation and guided response.

Who is MDR + Managed SIEM for?

Secusy MDR is designed for organizations that need continuous security monitoring across more than just endpoints but don't want to build and operate an internal 24×7 SOC.

  • Organization profile

    • SaaS and technology companies
    • Startups and scale-ups
    • SMEs and mid-market organizations
    • Fintech companies
    • Healthcare organizations
    • Financial services businesses
    • E-commerce companies
  • Environment

    • Cloud-first businesses
    • Organizations with small internal security teams
    • Businesses with cybersecurity and compliance requirements
    • Environments spanning endpoints, identity, cloud and network systems
  • What you get

    • Centralized security telemetry and analytics, not just endpoint alerts
    • 24×7 human monitoring without building an internal SOC
    • Investigation using context from multiple onboarded security sources

Managed EDR or MDR + Managed SIEM?

Not every organization needs a SIEM. If your primary requirement is endpoint protection and endpoint security monitoring, Secusy Managed EDR provides a lower-cost entry point.

FeatureManaged EDRMDR + Managed SIEM
Endpoint protection
SentinelOne Core
24×7 monitoring
Endpoint investigation
Guided response
Centralized SIEM—
Identity monitoring—
Cloud monitoring—
Firewall/network monitoring—
Application/security logs—
SIEM log retention—30 days
Starting price$9/endpoint/month$999/month

Why Secusy MDR + Managed SIEM?

Secusy gives you a structured digital path for purchasing and managing 24×7 SIEM monitoring. Encyb security operations and ValueMentor's broader cybersecurity capabilities power the engagement.

Monitor more than endpoints

Bring endpoint, identity, cloud, network and other supported security telemetry into one monitoring operation.

24×7 human monitoring

Security analysts continuously monitor alerts rather than leaving your internal team to watch another security console.

Investigation before escalation

Our analysts triage and investigate suspicious activity before escalating incidents requiring customer action.

Broader cybersecurity expertise

When you need capabilities beyond MDR, the service is backed by ValueMentor's wider cybersecurity expertise.

Guided response included

When an incident is validated, our team helps your IT or security team understand the issue and determine appropriate containment and remediation actions.

Transparent pricing

See how much your MDR service costs based on your security telemetry and endpoint requirements.

Start small and scale

Start at 5 GB/day and expand as your infrastructure and security requirements grow.

Questions

Frequently asked questions

Start 24×7 security monitoring

MDR Essential

$999/month

Larger environment or complex integration requirements? Get custom pricing.