Foundation gets you managed endpoint coverage with no contract. Protected adds identity and training. Complete adds SIEM and audit-grade log retention. Pick the tier that matches your risk — not the salesperson's commission.
For your business
Managed cybersecurity tiers
Prices in USD · per agent or per user
Tier 01 · Foundation
Foundation
$15/ agent / mo
Month-to-month · no minimum
Always-on protection for the computers your practice depends on, watched 24/7 by a real security team.
What's included
Always-on protection on every computer in your practice.MDR / EDR: suspicious activity on workstations is watched 24/7 by a real security team, so one compromised laptop is less likely to interrupt client work.
Human review before alerts reach you.SOC triage: a real analyst reviews suspicious activity first, so your team is not expected to interpret raw security alerts during a busy day.
Quarterly review of how your security is holding up.Posture review: we look at what changed, what improved, and what still needs attention before small gaps become expensive problems.
Direct email support from a senior analyst on our team.Security advisory: a person to ask when something feels off, not a generic ticket queue.
Add or remove devices at any time.Agent-based deployment: coverage can follow the computers your practice actually uses without locking you into unused seats.
Replaces or complements
Antivirus subscriptions that flag everything and stop nothing
Generic IT-installed protection with no one reviewing alerts
Adds monitoring of the email and Microsoft 365 / Google Workspace accounts attackers actually target — plus the documentation your insurer asks for.
Everything in Foundation, plus
Email and cloud account monitoring.ITDR: Microsoft 365 or Google Workspace accounts are watched for break-in attempts and identity-based attacks.
Security training for staff.security awareness training: short lessons and realistic phishing simulations help your team recognize common attacks before they become an incident.
Training records for audits and insurance.Compliance evidence: you have documentation ready when HIPAA, SOC 2, ISO 27001, client questionnaires, or insurers ask what your staff received.
Monthly security summary in plain English.Executive reporting: you see what was watched, what was investigated, and what needs a decision without learning another dashboard.
Senior analyst included.Security advisory: the same email channel as Foundation, scoped for the wider Protected program.
Replaces or complements
Standalone antivirus or endpoint subscriptions
Separate phishing-training tools you bought and forgot to roll out
One-off compliance gap assessments with no follow-through
Not included by default
SIEM and 90-day searchable log retention — that's Complete
Quarterly tabletop exercise and incident-response drill — that's Complete
Reserved analyst hours each month — that's Complete
Full program plus audit-ready logs and quarterly drills. For practices that already feel the weight of compliance and want it handled.
Everything in Protected, plus
Audit-ready security records.SIEM: logs from your devices, accounts, firewall, and cloud tools are collected so insurance, HIPAA, SOC 2, PCI-DSS, and client questionnaires are easier to answer.
Searchable evidence for 90 days.Log retention: when someone asks what happened, we can investigate from stored security records instead of piecing together screenshots after the fact.
Quarterly practice drill.Tabletop exercise: we walk through what your team would do if a real incident hit, before the pressure is real.
Annual security assessment and audit-prep support.Framework alignment: we turn the year of security work into a clearer story for insurers, auditors, clients, and leadership.
Replaces or complements
Separate logging and alerting tools no one reads
Advisory retainers with no monitoring behind them
A patchwork of security tools that don’t talk to each other
Not included by default
Full SOC 2 Type II audit fieldwork (scoped separately, ~$25K–$60K)
Multi-entity HIPAA Security Rule program for a parent + 5+ subsidiaries (scoped separately)
Incident response retainers beyond included analyst hours (block-billed at $500/hr)
Hardware procurement, network architecture redesigns, or M&A IT integration
Help-desk, end-user support, or general IT services — we don't sell those
Cyber insurance baselineSOC 2 Type IIHIPAA · PCI-DSS
Foundation lists per agent because EDR runs on devices. Protected and Complete list per user because identity and training are people-based. Real numbers and term options come back in the proposal within one business day.
Who runs it
CISSP-ledEx-Deloitte forensicsEx-Varonis
Just want monitoring?
Not ready for the full program?
Ridge Watch is the escape hatch: real 24/7 managed monitoring on your computers for $15 per device per month, month-to-month, cancel any time. No program, no minimum beyond a single device — just the protection.
The controls in every tier — MFA, managed EDR, identity monitoring, tested backups, staff training — are the same ones cyber-insurance carriers now require, and weigh when they set your premium. Carrying them doesn't just cut your risk; it can lower what you pay and keep you eligible for coverage carriers increasingly deny to applicants who can't show these controls. For many small businesses, a real share of this spend comes back as a smaller premium — security that partly pays for itself.
SOC 2 Type II foundation programs and HIPAA Security Rule alignment are scoped per environment — typical engagements run $25K–$60K depending on entity count and existing controls. Get a fixed-fee proposal in the briefing.
Other audiences
If you're not a growing business
Individuals & families
$199 one-time
to $89 / month for ongoing protection
Foundation, Protected, and Family plans for personal cybersecurity
Direct purchase available — no enterprise sales motion
Incident help available even without a subscription
Each tier reflects the licensed security platform we operate plus the time of a senior analyst on our team — deployment, tuning, 24/7 SOC escalation, and a written monthly report. No shelfware bundles, no hidden onboarding fee surprises.
Is there a contract?
Foundation runs month-to-month — install and uninstall agents at any time. Protected and Complete tiers are typically scoped on annual terms because identity coverage, training cadence, and SIEM data sources benefit from continuity. There is never silent auto-renewal; renewal terms are opt-in every year.
What is included in onboarding?
Discovery, agent deployment, identity baseline, alert routing, and a 30-day check-in. Onboarding is a flat fee disclosed in the proposal — $500 for under 25 agents, $1,000 for 26–100. Above 100 agents, we scope a custom onboarding window.
What is not included by default?
Major architecture transformations, deep incident response retainers, multi-entity SOC 2 Type II audit fieldwork, hardware procurement, and general IT/help-desk are scoped separately or are out of scope entirely. Each tier card shows the explicit exclusions so you don't pay for hours you don't need.
Can I start with a single product instead of a bundle?
Yes. Foundation is EDR-only and a fine starting point. Identity (ITDR) and training (SAT) can be added when you're ready — most clients add identity coverage within 60 days of starting once they see the first phishing simulation result or an ITDR alert come in on the demo tenant.
Do you sell only the underlying tools without the managed service?
No. The value is in the analyst who deploys correctly, watches the alerts that matter beyond the SOC's automatic triage, and tells you what to do when something happens. If you only want a bare license, buy direct from the vendor. We don't compete with the vendor's own channel — we operate the platform end-to-end and add the program around it.
Can we switch tiers later?
Yes. Tier upgrades are immediate and prorated. Tier downgrades take effect at the next renewal so identity-coverage history and SIEM retention aren't lost mid-cycle. There are no upgrade fees or downgrade penalties.
Is there a minimum seat count?
Foundation has no minimum — start with one agent if that's what you have. Protected and Complete are designed for organizations with at least 5 users; below that, the per-user pricing carries fixed overhead that we'd rather route to Foundation + bolt-on advisory hours instead.
Why not just buy Huntress direct?
Because Huntress publishes a 50-seat minimum per product on direct and reseller purchases, and none through an MSP (source: huntress.com/pricing). Managed EDR at Huntress' $8.99 per endpoint per month makes the direct floor $449.50/month whether you use 10 endpoints or 50. Below roughly 30 endpoints, Foundation at $15/agent/month with no minimum is cheaper: a 12-endpoint practice pays $180/month here versus $449.50 direct. Above 30 endpoints the direct license costs less on paper, and the difference pays for deployment done correctly, ongoing tuning, escalation into a named CISSP-led practitioner rather than a queue, and the HIPAA/ABA/FTC Safeguards/SOC 2 evidence package. If you have 50+ endpoints, someone in-house who will consistently own alerts and remediation, and no compliance evidence requirement, buy direct. We say so out loud.
How does billing work for partial months when we add or remove agents mid-cycle?
Adds are prorated from the day the agent comes online. Removes credit the next invoice, prorated to the day the agent goes offline. This is how the platform's billing flows through — we don't add a separate proration policy on top.
Next step
Not sure which tier fits?
Briefings are free and we tell you when you don't need us. 30 minutes, real answers, no follow-up sales sequence.