Obsidian Ridge is a Huntress MDR Partner. We operate the managed detection, identity, security awareness, and SIEM layers around the Huntress platform. You get deployment, alert triage, response coordination, and evidence packaging from one practitioner-led program.
Huntress is the right detection platform for most small and mid-market organizations. That decision is usually easy. The harder question is what surrounds it: who deploys the agents correctly, who reads the escalated alerts at 2 a.m., who packages the HIPAA evidence the auditor wants to see, who coordinates the breach notification when something happens.
Buying Huntress direct gets you the detection platform. Buying through a managed partner gets you the program around the platform. We are that program.
Pricing is straightforward: $15 per agent per month for Foundation (Huntress Managed EDR), $32 per user per month for Protected (adds Managed ITDR + SAT), and from $55 per user per month for Complete (adds Managed SIEM and the full compliance evidence program). Every tier covers the licensed Huntress platform plus a senior analyst operating it — deployment, tuning, 24/7 SOC escalation into a real person, and a written monthly report.
What we operate
The full Huntress product line
Huntress Managed EDR
24/7 endpoint detection and response across every laptop, desktop, and server. Ransomware canaries, credential-theft alerts, process-injection detection, and the Huntress SOC reading the alerts before they reach you.
Endpoint security posture management for app control visibility, vulnerability visibility, and unified posture reporting. Obsidian Ridge turns the findings into prioritized remediation work.
Identity threat detection on Microsoft 365 and Google Workspace. Catches the adversary-in-the-middle phishing kits (EvilProxy, Tycoon) that bypass MFA, the inbox rules that hide wire-fraud activity, and the OAuth-consent attacks.
Story-driven 5-minute micro-lessons, realistic phishing simulations, and a report-phishing button that ties back to the same Huntress 24/7 SOC running MDR and ITDR.
Centralized log retention with 90-day searchable evidence. Pulls from endpoints, identity, firewall, and cloud. The audit-ready answer when an insurer, regulator, or auditor asks what happened.
We deploy agents on every endpoint and connect every M365 / Google Workspace tenant, configure alert routing, and run the first tabletop. Most firms cover workstations but miss the server — we don't.
Escalation routed through an analyst on our team, not back to you
When the Huntress SOC escalates an alert, we receive it first. We make the call to revoke the session, isolate the host, or wake the owner — then loop you in with context and a recommendation, not a vendor-portal link to interpret.
Compliance evidence the carrier and the auditor actually want
HIPAA Security Rule, ABA Formal Opinion 483, FTC Safeguards Rule, SOC 2, PCI-DSS — packaged the way each one expects to see it. Huntress runs the detection platform; we package the evidence.
Cyber-insurance renewal support
The questionnaire controls carriers ask about are the same controls Huntress Managed EDR + ITDR + SAT can help evidence. We map our coverage to your carrier's exact form and answer the questions with attestable evidence.
Incident response coordination, not just notification
If something happens, we coordinate forensics, breach-notification timing (HIPAA, FTC, state AGs, ABA FO 483), cyber-insurance claim filing, and the client-facing or patient-facing communication. You stay the decision-maker; we operate the steps.
Managed pricing, no shelfware bundles
Foundation $15 per agent per month. Protected $32 per user per month. Complete from $55 per user per month. Each tier covers the licensed Huntress platform and a CISSP-led practitioner operating it — deployment, tuning, 24/7 SOC escalation into a real analyst, and a written monthly report.
Honest fit check
When direct-buy is the right answer
We tell you when you don't need us. Buying Huntress direct is the right move if any of these describe you:
You have a dedicated internal security team operating the platform 24/7
You want only the detection technology, not the program around it
You're an enterprise with in-house counsel, in-house IR, and in-house compliance handling the evidence side
You'd rather have a single procurement line item than a managed-service relationship
If none of those describe you, a managed partner relationship is almost certainly the right path.
Questions buyers ask
Frequently asked questions
What am I paying for above the Huntress platform itself?
A CISSP-led practitioner operating the platform end to end: deployment, tuning, 24/7 SOC escalation into a real person who can make the call, incident response coordination, and the compliance evidence package (HIPAA / ABA / FTC Safeguards / SOC 2) auditors and carriers ask to see. If you only want the detection license and can operate it yourself, buy direct from Huntress. If you want the program around the platform, that's what the tier covers.
Why not just buy Huntress direct?
Because Huntress publishes a 50-seat minimum per product on direct and reseller purchases, and none through an MSP (source: huntress.com/pricing). Managed EDR at Huntress' $8.99 per endpoint per month makes the direct floor $449.50/month whether you use 10 endpoints or 50. Below roughly 30 endpoints, Foundation at $15/agent/month with no minimum is cheaper: a 12-endpoint practice pays $180/month here versus $449.50 direct at the 50-seat minimum. Above 30 endpoints the direct license costs less on paper, and the difference is what pays for deployment done correctly the first time, ongoing tuning, escalation to a named CISSP-led practitioner rather than a queue, and the HIPAA/ABA/FTC Safeguards/SOC 2 evidence package. If you have 50+ endpoints, someone in-house who will consistently own alerts and remediation, and no compliance evidence requirement, buy direct. We say so out loud.
What's the difference between Huntress' own SOC and Obsidian Ridge?
Huntress operates the 24/7 Security Operations Center that watches every Huntress-instrumented endpoint and tenant. In the Obsidian Ridge operating model, Huntress escalations route through a senior analyst on our team who can make the call, coordinate the response, and explain what changed. Without a managed partner layer, every Huntress escalation lands directly in your inbox for you to interpret in real time.
Do you sell the underlying Huntress license without the managed service?
No. The value is in the person on our team who deploys the platform correctly, watches the alerts that matter beyond the SOC's automatic triage, and tells you what to do when something happens. If you only want the platform license, buy direct from Huntress.
Can Obsidian Ridge manage an existing Huntress deployment?
Usually, yes. The process is coordinated through Huntress' partner team and depends on the current account setup, the existing relationship, and the products in scope. We confirm the mechanics during the briefing before promising timing.
What if Huntress is the wrong platform for our environment?
It usually isn't, for small and mid-market organizations — Huntress' product fit is unusually good for the 5- to 500-employee range we serve. But we tell you when it's not the right fit, and we'll honestly point you to the better-suited platform. That's the same voice you'll hear in every briefing.
Are you a Huntress employee or reseller?
Neither. Obsidian Ridge is an independent managed cybersecurity practice and Huntress MDR Partner. We operate the practitioner side of the program around the Huntress platform for businesses that choose us to run the managed partner layer. Huntress provides the detection technology and the back-end SOC.
How is this different from a generic MSP that resells Huntress?
Most MSPs sell Huntress as one line item on a help-desk bundle. We are not an MSP — we don't sell help-desk, Wi-Fi, hardware procurement, or print management. We sell the managed cybersecurity program around the Huntress platform, with a CISSP-led practitioner on every engagement and industry-specific evidence packages for dental, law firms, accounting, and regulated SMB.
What's included beyond the Huntress platform itself?
The written information security plan, the incident response plan, the quarterly tabletop, the cyber-insurance renewal support, the HIPAA / ABA / FTC Safeguards / SOC 2 evidence package, the executive briefing cadence, and the on-call line to our team. None of that is in the Huntress product. All of it is in the managed partner relationship.
Next step
Talk to a senior analyst.
Briefings are 30 minutes, direct, and free. We walk through your environment, the Huntress fit, the partner relationship, and an honest read on whether we're right for your business — or whether buying direct is.