Tier 01 · 1 device
1 device
$15 per device · billed monthly
Your primary computer, monitored 24/7 by our security team. No setup session. No advisory wrap. Just the protection.
Ridge Watch
Real people watching your computers 24/7. When something bad happens, they stop it. $15 per device, per month. No enterprise sales process. No setup session. No contract. Cancel any time.
TL;DR
Ridge Watch puts the endpoint agent we deploy on your computer and connects it to a 24×7 Security Operations Center. When something acts like an attacker, the agent can isolate the machine from the network to contain it and a real analyst investigates what happened.
Alerts are triaged before they reach you, so you hear from us when there is something real to tell you. No chatbot, no upsell loop.
Device pricing is below. For the per-user business tiers, see full pricing.
Pricing
Prices in USD · per agent or per user
Tier 01 · 1 device
$15 per device · billed monthly
Your primary computer, monitored 24/7 by our security team. No setup session. No advisory wrap. Just the protection.
Tier 02 · 5 devices
$12 per device · billed monthly
Cover your laptop, your kid's laptop, your parent's laptop, the home-office machine, the family iMac. Same 24/7 protection on every one.
Tier 03 · 10 devices
$10 per device · billed monthly
Extended family or small home-office. Same managed protection on every machine.
What happens when an alert fires. A security analyst reviews it around the clock and acts on it — remediating it, noting it in the console, or taking the device off the network to contain it. Containment is one of those three outcomes, not what happens every time.
A contained device stays off the network until we review it.
Monitoring, containment and that review are included. Work beyond containment — troubleshooting, incident response, recovery — is $250 per incident. That is the one difference between this and the serviced plans: Protected includes up to 2 incident response sessions a year. The review window is the same on both.
Subscriptions renew automatically until you cancel. Monthly plans renew every month; annual plans are charged for the full year up front and renew every twelve months, at the price shown above. Cancel any time in the billing portal — no phone call, no notice period. Full terms in our Refund & Cancellation Policy.
Need more than 10 devices? Talk to us about bulk pricing. Above 25 devices, custom rates apply.
What you get
A real Security Operations Center watches your computer continuously. Not a chatbot, not an automated response — actual analysts, awake at 3 a.m. on a Sunday.
When something acts like an attacker, your computer can be automatically cut off from the network so the activity is contained while an analyst investigates it.
Hidden decoy files that surface ransomware encryption activity as a high-priority signal, so the security operations team sees it and can act on the host.
Software flags, humans decide. Alerts are triaged before they reach you, so you hear from us when something is actually worth telling you.
Desktops, laptops, Windows Server 2016 or newer, and most Linux systems. Light agent (under 50 MB memory). No browser slowdowns, no fan noise, no popups.
Month-to-month. No contract, no minimum. Cancel in the billing portal and service runs to the end of the period you have already paid for.
How it fits
Two real-time anti-malware agents on the same machine conflict, so Ridge Watch replaces third-party AV like Norton or McAfee. Microsoft Defender automatically goes passive and stays as a second layer. Backups and your own vigilance stay too — they do jobs the SOC doesn't.
| What you already have | What it's good at | What Ridge Watch adds |
|---|---|---|
| Third-party antivirus (Norton, McAfee, Bitdefender, etc.) | Signature-based malware detection on a paid annual license. | Ridge Watch replaces it. Two real-time agents conflict; we'll uninstall yours during setup. The endpoint agent does the same signature work plus 24×7 SOC monitoring for behavior signatures miss. |
| Microsoft Defender (Windows) or XProtect (macOS) | Built-in OS-level malware protection at no extra cost. | Stays active. Defender automatically goes passive (or runs in EDR-block-mode) when the endpoint agent is detected — they're designed to coexist. You keep both layers. |
| Backups (Time Machine, OneDrive, Backblaze, etc.) | Lets you recover after ransomware encrypts your files. | Ransomware canary detection that surfaces encryption activity for the SOC to act on, and host isolation to contain it. Backups remain your recovery path — keep them. |
| You — careful about what you click | Reduces the chance of you being the entry point. | A 24/7 SOC awake at 3 a.m. on a Sunday when you're asleep. Modern attacks bypass signatures and human caution alike — that's where managed detection fits. |
Most modern attacks — ransomware, credential theft, session hijacking, business email compromise — rarely trip antivirus signatures because they look like normal programs doing slightly-weird things. That's the gap a 24×7 SOC fills. Ridge Watch is the thing you used to need to be a Fortune 500 to afford.
Setup
Optional but recommended. We confirm fit, walk through what you'd get, and answer questions. If Ridge Watch isn't the right fit, we tell you.
You receive a one-line installer (or .msi / .pkg file) by email. Run it once. Monitoring begins once the agent checks in.
We send a confirmation when the SOC sees your device check in. From that point forward, you only hear from us when something matters.
Which is the goal. Real protection should be invisible until it's needed.
Where this fits
Ridge Watch is the program, not a single tool: Foundation ($15 per device per month), Protected ($32 per user per month), and Complete (from $55 per user per month). Foundation is MDR on every device; Protected adds ITDR and awareness training; Complete adds SIEM and the compliance evidence program.
Pairs with Managed Detection & Response, Managed ITDR, and Managed SIEM.
Most single-location practices start at Protected — MDR on the endpoints plus identity monitoring and training on the mailbox where payment fraud starts. Complete is the tier for a practice with an insurance renewal or an OCR-facing evidence need.
How this works for dentalSolo and small firms building a defensible program for the first time usually land at Protected; firms renewing cyber insurance or handling high-sensitivity matters move to Complete for the SIEM and written evidence package.
How this works for law firmsA four-preparer firm typically starts at Protected and steps up to Complete ahead of a cyber-insurance renewal or a state-AG-facing question, where the SIEM and WISP evidence earn their keep.
How this works for accountingThe insurance wedge
The controls that move a cyber-insurance application — endpoint detection, identity monitoring, awareness training, logging — are the tiers of Ridge Watch. If a renewal questionnaire just landed, the Readiness Sprint maps your carrier's questions to the exact tier that answers them.
From $1,500, delivered in 7 business days — final quote depends on scope, up to $3,500. Signed evidence pack mapped to your carrier's questionnaire — delivered, or we keep working at no additional cost until it is. We don't control underwriter decisions. We control whether you walk in with the evidence they ask for.
Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
FAQ
Both. Ridge Watch is designed for individuals, families, and sole proprietors who want enterprise-grade protection without an enterprise sales process. The same endpoint agent businesses pay $25+/month for is $15 here, billed directly to you.
Yes. Two real-time anti-malware agents on the same machine conflict — they fight over file access and slow your computer down.
The endpoint agent we deploy does the signature-based malware detection that Norton/McAfee/Bitdefender do, plus the 24×7 SOC layer they don't, so you don't lose coverage. We walk you through removing the existing AV during setup.
Microsoft Defender is the exception: it detects the endpoint agent and automatically goes passive (or runs in EDR-block-mode), so you keep Defender as a second layer at no extra cost.
We send you a one-line installer or a packaged .msi/.pkg file. You run it once, and we confirm by email when monitoring is active on each device.
No. The endpoint agent uses under 50 MB of memory, has no kernel hooks, and is signed by Microsoft. You will not notice it running.
Talk to us about bulk pricing. The economics get better at higher volumes, so an extended family or a small office with more devices than the largest plan covers can get a custom rate.
Yes — month-to-month means you can scale up or down whenever. Add a kid's laptop next semester, drop one when someone moves out. Each plan covers a set number of devices, so email support@obsidianridge.io and we move you to the one that fits. No penalty for changing.
A security analyst reviews the alert around the clock and acts on it — remediating it, noting it in the console, or taking the device off the network to contain it. Containment is one of those three outcomes, not what happens every time.
A contained device stays off the network until we review it; you cannot put it back yourself, and that review happens within one business day, so an alert overnight or at the weekend holds contained until the next business day.
You get a written summary of what happened and what to do next. Monitoring, containment and that review are included; work beyond containment — troubleshooting, incident response, recovery — is $250 per incident.
Need more than just MDR?
Ready to start
See where you stand, or start now. Pick a device count, run the installer we send you, and monitoring begins once each device checks in.