Obsidian Ridge

Huntress MDR Partner

Huntress, operated end-to-end.

Obsidian Ridge is a Huntress MDR Partner. We operate the managed detection, identity, security awareness, and SIEM layers around the Huntress platform. You get deployment, alert triage, response coordination, and evidence packaging from one practitioner-led program.

Operated by
Huntress Managed EDRManaged ITDRManaged SATManaged SIEM
CISSP-led practiceHuntress Secure Partner

TL;DR

Why the managed partner layer matters

Huntress is the right detection platform for most small and mid-market organizations. That decision is usually easy. The harder question is what surrounds it:

  • Who deploys the agents correctly
  • Who follows up on what the 24/7 SOC escalates
  • Who packages the HIPAA evidence the auditor wants to see
  • Who coordinates the breach notification when something happens

Buying Huntress direct gets you the detection platform. Buying through a managed partner gets you the program around the platform. We are that program.

Pricing is straightforward:

  • $25 per person per month for Ridge Core (Huntress Managed EDR and Managed ITDR)
  • $50 per person per month for Ridge Plus (adds Managed SAT, Email Security and a secure browser for work apps)
  • $70 per person per month for Ridge Reserve (adds the incident response plan, access reviews and patch reporting; log collection through Huntress Managed SIEM is Ridge Log, an add-on on any tier at $8 per data source per month)

Every tier covers the licensed Huntress platform plus a senior analyst operating it: deployment, tuning, escalations from the 24/7 SOC reviewed within one business day, and a written monthly report.

What we operate

The full Huntress product line

Huntress Managed EDR

24/7 endpoint detection and response across every laptop, desktop, and server. Ransomware canaries, credential-theft alerts, process-injection detection, and the Huntress SOC reading the alerts before they reach you.

See the EDR page

Huntress Managed ESPM

App Control (application allowlisting) and RMM Guard (detects and can block remote monitoring and management tools) for eligible Windows endpoints. Early access, no published price, in no tier.

See the ESPM page

Huntress Managed ITDR

Identity threat detection on Microsoft 365 and Google Workspace: on either platform it catches stolen session tokens replayed from somewhere new and the inbox rules that hide wire-fraud activity. On Microsoft 365 it also catches the adversary-in-the-middle kits themselves (EvilProxy, Tycoon) and the OAuth-consent attacks.

See the ITDR page

Huntress Managed Security Awareness Training

Story-driven 5-minute micro-lessons, realistic phishing simulations, and a report-phishing button that ties back to the same Huntress 24/7 SOC running MDR and ITDR.

See the Security Awareness Training page

Huntress Managed SIEM

Centralized log retention with 90-day searchable evidence. Pulls from endpoints, identity, firewall, and cloud. The audit-ready answer when an insurer, regulator, or auditor asks what happened.

See the SIEM page

Why managed partner

The six things that change with us in front

Deployment done right the first time

We deploy agents on every endpoint and connect every M365 / Google Workspace tenant, configure alert routing, and run the first tabletop. Most firms cover workstations but miss the server — we don't.

Escalation routed through us, not back to you

Two clocks. The Huntress 24/7 SOC reviews alerts around the clock and can revoke a session or take a host off the network to contain it, without waiting for business hours. Escalations come to us, not to you, and we pick them up within one business day: confirm what happened, decide the next step, and loop you in with context and a recommendation, not a vendor-portal link to interpret.

Compliance evidence the carrier and the auditor actually want

HIPAA Security Rule, ABA Formal Opinion 483, FTC Safeguards Rule, SOC 2, PCI-DSS — packaged the way each one expects to see it. Huntress runs the detection platform; we package the evidence.

Cyber-insurance renewal support

The questionnaire controls carriers ask about are the same controls Huntress Managed EDR + ITDR + SAT can help evidence. We map our coverage to your carrier's exact form and answer the questions with attestable evidence.

Incident response coordination, not just notification

If something happens, we coordinate forensics, breach-notification timing (HIPAA, FTC, state AGs, ABA FO 483), cyber-insurance claim filing, and the client-facing or patient-facing communication. You stay the decision-maker; we operate the steps.

Managed pricing, no shelfware bundles

Ridge Core $25 per person per month. Ridge Plus $50 per person per month. Ridge Reserve $70 per person per month. Each tier covers the licensed Huntress platform and a CISSP-led practitioner operating it: deployment, tuning, escalations from the 24/7 SOC reviewed within one business day, and a written monthly report. Log collection through Huntress Managed SIEM is Ridge Log, an add-on on any tier at $8 per data source per month.

Honest fit check

When direct-buy is the right answer

We tell you when you don't need us. Buying Huntress direct is the right move if any of these describe you:

  • You have a dedicated internal security team operating the platform 24/7
  • You want only the detection technology, not the program around it
  • You're an enterprise with in-house counsel, in-house IR, and in-house compliance handling the evidence side
  • You'd rather have a single procurement line item than a managed-service relationship

If none of those describe you, a managed partner relationship is almost certainly the right path.

Questions buyers ask

Frequently asked questions

What am I paying for above the Huntress platform itself?

A CISSP-led practitioner operating the platform end to end: deployment, tuning, escalations from the 24/7 SOC reviewed within one business day, incident response coordination, and the compliance evidence package (HIPAA / ABA / FTC Safeguards / SOC 2) auditors and carriers ask to see.

If you only want the detection license and can operate it yourself, buy direct from Huntress. If you want the program around the platform, that's what the tier covers.

Why not just buy Huntress direct?

Because of the seat minimum, not the rate. Huntress publishes a 50-seat minimum per product on direct purchases and on reseller purchases, and none through an MSP (source: huntress.com/pricing, checked 2026-09-30).

Its published Managed EDR rate is $7.99 per endpoint per month at 100 endpoints, and Huntress states the per-unit rate goes down as volume goes up, so a smaller deployment pays more per endpoint, and no rate below 50 units is published.

At the 50-seat minimum its own in-house-team calculator reads $449.50 a month, or $8.99 per endpoint.

So the direct floor for Managed EDR is at least $399.50 a month, and $449.50 by Huntress' own calculator, whether you deploy 10 endpoints or 50, on Huntress' standard 12-month term.

Managed ITDR is a separate product with its own 50-seat minimum: $240.00 a month at 50 identities by the same calculator, so $689.50 a month for the two together.

Ridge Core includes both at $25 per person per month with no minimum, so a practice of up to 27 people pays less here than the direct floor for the same two products.

For a home or a very small office that only needs its computers watched, Ridge Watch is $15 per computer per month.

Above that size the direct licenses cost less on paper, and the difference is what pays for deployment done correctly the first time, ongoing tuning, escalation to a named CISSP-led practitioner rather than a queue, and the HIPAA/ABA/FTC Safeguards/SOC 2 evidence package.

If you have 50+ endpoints, someone in-house who will consistently own alerts and remediation, and no compliance evidence requirement, buy direct. We say so out loud.

What's the difference between Huntress' own SOC and Obsidian Ridge?

Huntress operates the 24/7 Security Operations Center that watches every Huntress-instrumented endpoint and tenant.

In the Obsidian Ridge operating model, the SOC watches around the clock and contains a threat when it needs to, and its escalations come to the practitioner who runs your program, reviewed within one business day, who coordinates the response and explains what changed.

Without a managed partner layer, every Huntress escalation lands directly in your inbox for you to interpret yourself.

Do you sell the underlying Huntress license without the managed service?

No. The value is in the practitioner who deploys the platform correctly, reviews what the SOC escalates, and tells you what to do when something happens. If you only want the platform license, buy direct from Huntress.

Can Obsidian Ridge manage an existing Huntress deployment?

Usually, yes. The process is coordinated through Huntress' partner team and depends on the current account setup, the existing relationship, and the products in scope. We confirm the mechanics during the briefing before promising timing.

What if Huntress is the wrong platform for our environment?

It usually isn't, for small and mid-market organizations — Huntress' product fit is unusually good for the 5- to 500-employee range we serve. But we tell you when it's not the right fit, and we'll honestly point you to the better-suited platform. That's the same voice you'll hear in every briefing.

Are you a Huntress employee or reseller?

Neither. Obsidian Ridge is an independent managed cybersecurity practice and Huntress MDR Partner. We operate the practitioner side of the program around the Huntress platform for businesses that choose us to run the managed partner layer.

Huntress provides the detection technology and the back-end SOC.

How is this different from a generic MSP that resells Huntress?

Most MSPs sell Huntress as one line item on a help-desk bundle. We are not an MSP — we don't sell help-desk, Wi-Fi, hardware procurement, or print management.

We sell the managed cybersecurity program around the Huntress platform, with a CISSP-led practitioner on every engagement and industry-specific evidence packages for dental, law firms, accounting, and regulated SMB.

What's included beyond the Huntress platform itself?

The written information security plan, the incident response plan with a yearly ransomware tabletop (in Ridge Reserve), the cyber-insurance renewal support, the HIPAA / ABA / FTC Safeguards / SOC 2 evidence package, the executive briefing cadence, and a direct line to the practitioner, with calls returned within one business day.

None of that is in the Huntress product. All of it is in the managed partner relationship.

Next step

Talk to a senior analyst.

Briefings are 30 minutes, direct, and free. We walk through your environment, the Huntress fit, the partner relationship, and an honest read on whether we're right for your business — or whether buying direct is.

Talk with us