How Much Does MDR Cost? A Pricing Breakdown
Most MDR vendors won't publish a number. Here's what actually drives the price, what gets quietly left out of the headline quote, and what Touchpoint's own pricing looks like, published and unhidden.
Why MDR pricing is so hard to compare
Ask three MDR vendors for a quote on the same environment and you'll likely get three numbers that look nothing alike, not because one is ripping you off, but because "MDR" doesn't have a standard scope. One quote might cover alert monitoring only. Another might include containment. A third might bundle in threat intelligence, a named analyst team and monthly reporting as standard, while a cheaper-looking quote treats each of those as a paid add-on.
That makes "how much does MDR cost" the wrong first question. The useful version is: for this price, what exactly happens when something goes wrong, and who does it?
What actually drives the price
- Device or endpoint count. The most common pricing unit. More devices monitored means more telemetry to process and more potential alerts to investigate.
- Whether containment is included, not just monitoring. A tier where the provider only tells you about a threat is cheaper than one where they're authorised to act on it, because the second one carries more liability and more analyst time per incident.
- Coverage hours. True 24/7/365 coverage, with analysts actually staffed overnight and on weekends rather than an on-call escalation, costs more to deliver than business-hours monitoring with after-hours alerting only.
- Threat intelligence depth. A generic feed is cheap. Intelligence matched to the specific operating systems, hardware and software you actually run takes more work to maintain and is usually priced accordingly.
- What's bundled for incident response. Containing an active threat and fully investigating and recovering from one are different amounts of work. Pricing that includes meaningful incident response hours, not just containment, sits higher.
- Volume. Most providers offer discounts once you cross a device-count threshold, since the marginal cost per device drops as the environment grows.
What's commonly left out of the headline number
The lowest quote in a shortlist is often the one with the most missing. Before comparing a number, check whether these are included, available as a paid add-on, or simply absent:
- Digital forensics and full incident response, beyond initial containment
- Threat intelligence tailored to your actual stack, rather than a generic feed
- A named analyst team you can actually reach, versus a rotating pool
- Written SLAs for acknowledgement and containment time, not just "fast response"
- Onboarding and tuning time, which can be billed separately in the first months
- Monthly or board-ready reporting, rather than raw alert logs
A simple way to compare quotes
Before comparing the monthly figure, normalise each quote against the same checklist: 24/7 staffed coverage or on-call escalation; containment included or billed separately; threat intelligence generic or tailored; named analysts or a pool; written SLA numbers or vague language; incident response hours included and how many. Two quotes that look $4 per device apart can represent very different services once you line them up this way, and the "expensive" one is sometimes the one that actually removes work from your team rather than just forwarding it.
What Pulse actually costs
Touchpoint publishes its starting price rather than requiring a sales call to find out: Pulse starts from $9 per device per month (€8.50 / £7.50), with volume discounts from 250 devices, billed annually on a 12-month term. Every tier includes 24/7 monitoring and Signal threat intelligence as standard, not as an upsell.
| Tier | What changes | Who executes response |
|---|---|---|
| Core — watchful eyes, guided hands | 24/7 monitoring and triage, guided response playbooks, monthly reporting | Your team, with step-by-step direction |
| Assured — we act, you approve | Everything in Core, plus written SLAs: 15-minute acknowledge, 60-minute contain | Touchpoint, within pre-approved actions |
| Elite — full incident response, included | Everything in Assured, plus full IR and forensics with no separate retainer | Touchpoint, end to end |
See the full feature breakdown and request a quote for your device count on the Packages page, or read about what Pulse monitors and how containment works on the Pulse MDR page.
Frequently asked questions
Is MDR priced per device, per user, or a flat fee?+
Most providers, including Touchpoint, price per device or endpoint per month, since that scales with the number of things that actually need watching. Per-user pricing is less common and can undercount environments with lots of servers or unmanaged devices relative to staff.
Why do MDR quotes for the same company vary so much between vendors?+
Almost always because the quotes cover different scopes of work, not because one vendor is simply cheaper. A low quote that excludes containment, forensics or tailored threat intel is not comparable to a higher quote that includes them until you normalise what's actually inside each number.
Does MDR pricing include incident response?+
It depends on the tier and provider. Containment of an active threat is often included at mid and upper tiers; full forensic investigation and recovery support is frequently a separate line item or a higher tier entirely. Always ask specifically where containment ends and billed incident response begins.
Are there volume discounts for MDR pricing?+
Typically yes, once you pass a device-count threshold, since the marginal cost of monitoring an additional endpoint in an existing environment is lower than onboarding a new customer. Touchpoint's published pricing includes volume discounts starting at 250 devices.
Want a number for your actual device count?
Tell us roughly how many devices you need covered and we'll give you a real quote, not a range.