Research date: September 14–15, 2026. All pricing is list price or credible third-party range as of the dates cited. Enterprise security pricing is heavily negotiated and changes frequently — treat every number as an anchor for a conversation, not a quote.
Two caveats that apply to every product on this page
1. No tool is universally secure. Detection and protection results depend on configuration, tuning, policy mode (audit versus block), agent coverage, log-ingestion decisions, and the humans watching the console. MITRE itself stresses that its evaluations do not rank vendors, and Forrester's Allie Mellen warned that vendors claiming perfect scores may be running unrealistic configurations.
2. Tools need staffing. An unwatched EDR console, an untuned SIEM, and an unreviewed vulnerability report provide close to zero value. For organizations without 24/7 security staff, managed detection and response is the right purchase, not another product. Roughly 65% of organizations under 1,000 employees lack 24/7 SOC coverage.
1. Market context: what changed in 2024–2026
Consolidation reshaped the landscape. Verify current ownership before signing multi-year deals.
| Deal | Value | Status (Sept 2026) |
|---|---|---|
| Google → Wiz | $32B | Closed March 11, 2026 after DOJ antitrust clearance |
| Palo Alto Networks → CyberArk | ~$25B | Closed February 2026 — PAM is now a Palo Alto pillar |
| Cisco → Splunk | $28B | Closed March 2024; AI roadmap and pricing overhaul underway |
| Sophos → Secureworks | $859M | Closed Feb 2025; Taegis folded into Sophos |
| Proofpoint → Hornetsecurity | $1.8B | Completed 2025; extends Proofpoint into SMB/MSP |
| Mastercard → Recorded Future | $2.65B | Closed Dec 2024 |
| Akamai → Noname Security | ~$450M | Closed 2024 |
| Zscaler → Red Canary | — | 2025; verify current independence of the MDR offering |
| Arctic Wolf → BlackBerry Cylance | — | Feb 2025 |
Independent testing is thinning. In the 2025 MITRE ATT&CK Enterprise Evaluations, published December 11, 2025, only eleven vendors participated: Acronis, AhnLab, CrowdStrike, Cyberani, Cybereason, Cynet, ESET, Sophos, Trend Micro, WatchGuard, and WithSecure. Microsoft, Palo Alto Networks, and SentinelOne declined, citing resource demands. The 2025 round emulated Scattered Spider — the first cloud-infrastructure scenario — and Mustang Panda. Several vendors claim 100% detection; treat all such marketing skeptically.
The operational lesson of the era: CrowdStrike's July 19, 2024 faulty content update crashed roughly 8.5 million Windows machines globally. It was not a breach, but it is the canonical demonstration that kernel-level security agents are themselves operational risk. Stage updates, use N-1 rings, and keep recovery runbooks — regardless of vendor.
2. Endpoint: EDR, XDR, antivirus
| Product | List pricing (anchor) | Best fit | Independent evidence | Notes |
|---|---|---|---|---|
| CrowdStrike Falcon | Go $59.99, Pro $99.99, Enterprise $184.99 per device/yr list; real-world median contract ~$55K/yr; add-on modules can add 50–200% | Mid-market → enterprise; SMB via Go/Pro or MSPs | 2025 Gartner MQ EPP Leader; participated in MITRE 2025 and claims 100% (vendor claim) | Cloud-native, light sensor, strong hunting. Weaknesses: cost creep through modules, upward-only true-ups, and the 2024 outage as a governance lesson |
| Microsoft Defender for Endpoint / XDR | P1 ~$3/user/mo; P2 ~$5.20 standalone; P2 included in M365 E5; Defender for Business ~$3/user/mo in Business Premium | Anyone already on Microsoft 365 | 2025 Gartner MQ EPP Leader; skipped MITRE 2025; consumer Defender scores at or near top in AV-TEST June 2026 | Deep M365/Entra integration; XDR spans email, identity, endpoint. Requires licensing literacy; macOS and Linux parity lags Windows. Consumer Defender, free in Windows, is now a legitimately strong baseline |
| SentinelOne Singularity | Core $69.99, Control $79.99, Complete $179.99, Commercial $229.99 per endpoint/yr list; negotiated $35–$75 at 500–1,000 seats | SMB → enterprise; MSP-friendly | 2025 Gartner MQ EPP Leader, fifth consecutive year; skipped MITRE 2025 | On-device AI models work offline; ransomware rollback on Windows. Strong prior MITRE history; skipping 2025 removes fresh independent data |
| Sophos Intercept X | ~$30–$80/endpoint/yr negotiated; MDR bundles common | SMB/mid-market, MSP channel | Participated in MITRE 2025; consistently top-tier in AV-Comparatives Business tests through mid-2026 | Now incorporates Secureworks Taegis. Sensible default for SMBs wanting first-party MDR too |
| ESET Protect | ~$40–$60/endpoint/yr | SMB, constrained hardware, privacy-conscious EU orgs | MITRE 2025 participant; consistently high AV-Comparatives marks with low false positives | Lightweight agent; EU (Slovakia) HQ helps data-residency narratives. Less muscular EDR/XDR than leaders |
| Malwarebytes / ThreatDown | Consumer ~$45/yr; business ~$69–$85/endpoint/yr | Consumers, micro-business, remediation second opinion | Consumer AV-Comparatives participant | Strong cleanup reputation; business EDR is serviceable, not leading |
Consumer antivirus reality. Independent labs show the top ten consumer engines clustering near 99–100% on real-world protection tests; the differences are in false positives and performance impact. For most consumers, built-in Microsoft Defender plus automatic updates plus a password manager plus browser hygiene beats buying a suite.
Open-source alternatives: Wazuh (free SIEM/XDR with file-integrity monitoring, vulnerability detection, and agent telemetry; cloud version from ~$571/mo), osquery and Fleet for telemetry, Velociraptor for DFIR at scale, ClamAV for mail and file-server scanning. Practitioner consensus: excellent learning and compliance value, not a drop-in replacement for commercial EDR without dedicated staff.
3. Firewalls and NGFW
| Product | Pricing anchor | Best fit | Notes |
|---|---|---|---|
| Palo Alto Networks | Appliances ~$1K (PA-410) to $200K+; subscriptions often equal hardware cost annually | Enterprise; best-of-breed inspection | Consistent Gartner leader; premium price. Now owns CyberArk |
| Fortinet FortiGate | Best price/performance in class; 40F–90F popular in SMB ($400–$2K plus ~$300–$1K/yr bundles) | SMB → carrier; SD-WAN value leader | The vulnerability track record is the story. Repeated critical, actively exploited FortiOS/FortiManager/FortiWeb flaws landed in CISA's KEV catalog through 2024–26, including additions in April and September 2026 with federal patch deadlines. If you run Fortinet edge devices you are signing up for an aggressive emergency-patch cadence, and management interfaces must never face the internet |
| Cisco (Secure Firewall, Meraki MX) | Meraki MX ~$300–$4K/yr/site | Cisco shops, distributed branch | Cisco appeared alongside Citrix and Fortinet in Sept 2026 KEV additions. Firepower management UX is a chronic complaint; Meraki is loved for simplicity, disliked for license-expiry behavior |
| Cloudflare (Magic Firewall / Gateway) | Zero Trust free tier ≤50 users; paid ~$7/user/mo | Cloud-first orgs replacing appliance edge | Firewall-as-a-service model |
Open source: pfSense (Netgate) and OPNsense remain the standard free firewalls for labs and small business. They lack first-party TLS-inspection ecosystems and vendor SLAs; pair with Suricata or Zeek for detection.
4. Email security
| Product | Pricing anchor | Best fit | Notes |
|---|---|---|---|
| Microsoft Defender for Office 365 | P1 ~$2/user/mo, P2 ~$5.20 (in E5) | M365 organizations | Configure SPF/DKIM/DMARC plus Safe Links and Safe Attachments correctly before buying anything additional |
| Proofpoint | Quote-based; credible range ~$3–$8/user/mo | Enterprise, regulated | Category leader in gateways; acquired Hornetsecurity for SMB reach. Heavier administrative burden |
| Mimecast | ~$3–$7/user/mo by bundle | Mid-market | Gateway plus archiving plus awareness |
| Abnormal Security | Quote-only; third-party guides cite $4–$9/user/mo | Organizations fighting BEC and vendor-email compromise | API-based behavioral analysis layered on M365 or Google — the modern architecture |
Open source and free: Rspamd and SpamAssassin for self-hosted mail; Sublime Security's free tier for detection-as-code on M365 and Google. DMARC enforcement using free tooling remains the highest-ROI email control available.
5. Identity, MFA, and hardware keys
| Product | Pricing anchor | Best fit | Notes |
|---|---|---|---|
| Microsoft Entra ID | Free tier; P1 ~$6/user/mo (in E3/Business Premium); P2 ~$9 (in E5); Entra Suite ~$12 | Any Microsoft shop | Marginal cost near zero if already on E3/E5 — the decisive procurement fact. Note that Microsoft's own identity plane has had incidents, including the 2023 Storm-0558 key theft; even IdPs get breached |
| Okta | SSO ~$2, Adaptive MFA ~$3, Lifecycle Mgmt ~$4, Universal Directory ~$2 per user/mo; realistic stack ~$11/user/mo, ~$132K/yr for 1,000 users at list | Heterogeneous and multi-cloud estates; best app catalog | Largest independent IdP, plus Auth0 for customer identity. Past incidents (2022 Lapsus$, 2023 support-system breach) drove a major security overhaul — evaluate current posture rather than assuming either extreme |
| Cisco Duo | Free ≤10 users; Essentials $3, Advantage $6, Premier $9 per user/mo | MFA-first buyers, healthcare, education | Easiest MFA rollout in the industry; Premier adds phishing-resistant options |
| JumpCloud | ~$9–$24/user/mo by bundle | SMBs without AD; Mac and Linux fleets | Directory plus SSO plus MDM plus MFA — "cloud AD" for small teams |
Open source: Keycloak (the de facto OSS IdP), Authentik, Authelia, Zitadel. Viable for engineering-led organizations, but you then own upgrades, high availability, and incident response for your own identity provider — a serious commitment.
Hardware keys. YubiKey 5 series roughly $50–$75; Security Key series (FIDO2-only) roughly $25–$29; Google Titan roughly $30–$35; Token2 and Nitrokey as cheaper and open-hardware alternatives. FIDO2/WebAuthn keys and passkeys are the only widely deployed phishing-resistant MFA. Buy two per user.
6. Privileged access management
| Product | Pricing anchor | Notes |
|---|---|---|
| CyberArk (Palo Alto Networks) | Quote-only; commonly $100K+ initial for enterprise vaulting | Market leader; acquisition closed February 2026, so expect platform bundling and roadmap shifts. Existing customers should watch renewal terms |
| Delinea, BeyondTrust | Mid-market friendlier; quote-based | BeyondTrust's Remote Support SaaS compromise in December 2024, connected to the US Treasury incident, is a reminder that PAM vendors are high-value targets |
| Open source: Teleport, JumpServer, Apache Guacamole, HashiCorp Vault / OpenBao | Free | Excellent for server and Kubernetes access; weaker on Windows administrative workflows and session-recording compliance packaging |
7. Password managers
| Product | Pricing (2026) | Independent evidence | Notes |
|---|---|---|---|
| Bitwarden | Free tier (unlimited passwords); Premium $10/yr; Families $40/yr; Teams $4, Enterprise $6 per user/mo | Open source; annual third-party audits with clean results; no known breach | Best value; self-hostable, including the community Vaultwarden server |
| 1Password | Individual $2.99/mo; Families $5.99/mo; Teams Starter $19.95/mo (≤10); Business $7.99/user/mo | SOC 2 Type II; audited; no known breach; higher autofill success in third-party testing | Best UX; the Secret Key design means a stolen server copy alone is insufficient. Travel Mode, SSH agent |
| Keeper | Business ~$3.75–$5/user/mo | SOC 2, FedRAMP | Strong compliance and government story; reviewers note aggressive upsells |
Context. The 2022 LastPass breach, in which encrypted vaults were exfiltrated and weak-iteration vaults were later cracked, remains the cautionary tale: vendor choice and master-password strength both matter. KeePassXC is the local-file option for individuals who refuse cloud sync.
8. SIEM
The most staffing-sensitive category in security. An untuned SIEM is an expensive log bucket.
| Product | Pricing | Best fit | Notes |
|---|---|---|---|
| Splunk (Cisco) | ~$665–$1,620/GB/day/yr; entry ~$8–15K; workload pricing overhaul under Cisco | Large enterprise with budget and staff | Gold-standard search and ecosystem; notorious cost at scale |
| Microsoft Sentinel | $4.30/GB pay-as-you-go; commitment tiers to ~$2.05/GB; Basic Logs $1.00/GB | M365 and Azure shops | Most transparent pricing in the category; E5 customers get some free ingestion; KQL skill required |
| Elastic Security | Free Basic tier self-hosted; Platinum from ~$131/mo cloud | Engineering-led teams | Cost shifts from license to engineer time |
| CrowdStrike NG-SIEM (LogScale) | $5.95/GB pay-as-you-go; 10GB/day free tier | Falcon customers | Index-free architecture, fast |
| Rapid7 InsightIDR | $70.40/asset/yr (251-asset minimum) | Mid-market wanting SIEM plus UEBA bundled | |
| Google SecOps (Chronicle) | Quote-only | Large estates | Flat-ish data-cap model |
Open source: Wazuh (free, SIEM plus XDR) and Security Onion (free distribution bundling Suricata, Zeek, and Elastic; 2.4.201 released January 2026 with version 3 rolling out). Every serious total-cost analysis reaches the same conclusion: free SIEM costs one or more engineers.
9. SOAR and automation
Twelve of the major vendors are quote-only; the exceptions are Tines (free community tier, then per-workflow pricing) and Shuffle (open source, free self-hosted). Leaders: Palo Alto Cortex XSOAR/XSIAM, Splunk SOAR, Tines, Torq, Swimlane. The trend is that standalone SOAR is dissolving into SIEM and XDR platforms and into general hyperautomation tools. Open source: Shuffle, n8n, StackStorm.
The reality check worth publishing: SOAR pays off only after detections are tuned. Automating a noisy SOC automates the noise.
10. Vulnerability scanning and patch management
| Product | Pricing anchor | Notes |
|---|---|---|
| Tenable | Nessus Professional $4,790/yr; Tenable VM/One per-asset quote | De facto standard scanner |
| Qualys VMDR | Per-asset, quote | Strong compliance and cloud-agent story |
| Rapid7 InsightVM | ~$22–$26/asset/yr at volume | Good remediation-workflow integration |
Open source: OpenVAS / Greenbone Community Edition (free, capable, slower feeds than paid appliances), Nuclei (template-based, web-focused), OSV-Scanner (dependencies).
Patch management: Action1 is genuinely free for the first 200 endpoints; NinjaOne runs roughly $3–$5 per endpoint per month and is an MSP favorite; PDQ Deploy and Inventory are long-standing Windows-admin favorites; ManageEngine Patch Manager Plus is free up to 20–50 endpoints. Open source and built-in: WSUS, Ansible, unattended-upgrades, Chocolatey and winget scripting.
The honest framing: scanning is the easy part. Remediation SLAs and asset inventory are where programs fail. Prioritize KEV-listed vulnerabilities first.
11. WAF and API security
| Product | Pricing | Notes |
|---|---|---|
| Cloudflare | Free (basic managed rules) / Pro ~$25/mo / Business ~$250/mo / Enterprise quote | Best ease of use plus CDN and DDoS bundle |
| AWS WAF | Pay per rule and request (~$5/ACL + $1/rule + $0.60 per million requests) | Fits AWS-native infrastructure; rule sprawl costs accumulate |
| Akamai, Imperva, Fastly | Enterprise quote | High end |
Open source WAF: ModSecurity (engine stewardship moved to OWASP) with the OWASP Core Rule Set; the modern successor Coraza; CrowdSec for collaborative blocking; BunkerWeb.
API security platforms: Salt Security, Akamai API Security (formerly Noname), Traceable (acquired by Harness in 2025), Cequence, 42Crunch. All quote-only, typically $30K+ per year entry. CNAPPs such as Wiz are absorbing API discovery. Open source: OWASP ZAP for API DAST, plus gateway schema validation.
12. Cloud, container, and Kubernetes security
| Product | Pricing anchor | Notes |
|---|---|---|
| Wiz (Google) | Quote-only per workload; commonly ~$120–$350/workload/yr | Category leader on agentless graph-based risk; now Google-owned as of March 2026. Multi-cloud customers should watch for roadmap gravity toward Google Cloud — Google's neutrality pledge is a vendor claim to monitor |
| Palo Alto Prisma Cloud / Cortex Cloud | Credit-based, complex | Broadest feature list; complexity and pricing opacity are common complaints |
| Microsoft Defender for Cloud | Published Azure meters (Defender for Servers P2 ~$15/server/mo) | Azure-first organizations |
| Orca, Sysdig, Lacework (now Fortinet FortiCNAPP) | Quote | Credible alternatives |
Open source CSPM: Prowler, ScoutSuite, CloudSploit, Steampipe/Powerpipe benchmarks, Checkov for IaC. These cover posture checks well but do not provide attack-path graphs or runtime correlation.
Container and Kubernetes security is the strongest open-source category in this document: Trivy (the image and IaC scanning standard), Falco (CNCF-graduated runtime detection), Tetragon (eBPF), Kyverno and OPA Gatekeeper (policy), kube-bench and kube-hunter. A skilled platform team can build roughly 80% of a container-security program from open source; the commercial value is correlation, interface, and multi-cluster operations. Commercial: Wiz, Sysdig Secure, Aqua, Prisma, Upwind.
13. Application and dependency security
| Product | Pricing anchor | Notes |
|---|---|---|
| Snyk | Free tier; Team from ~$25/dev/mo; Enterprise quote | Best SCA and developer experience; SAST weaker than dedicated tools |
| GitHub Advanced Security | Since April 2025 sold as two SKUs: Secret Protection ~$19/committer/mo and Code Security ~$30/committer/mo; free for public repos | CodeQL is genuinely strong; zero friction if you live in GitHub |
| Semgrep | Free OSS engine; Pro per contributor | Fast, tunable, low false-positive reputation among practitioners |
| SonarQube, Checkmarx, Veracode | Community free (Sonar); others quote | Established enterprise options |
Open source: Semgrep OSS, CodeQL (free for open source), Trivy and Grype plus Syft for SCA and SBOM, OWASP ZAP and Nuclei for DAST, Gitleaks and TruffleHog for secrets, Dependency-Track for SBOM operations.
The adoption test: measure the false-positive rate in a pilot on your own code, not in a vendor demo. In this category, false positives decide whether developers use the tool or route around it.
14. DLP, MDM, and backup
DLP. Microsoft Purview DLP is included in E5 or the E5 Compliance add-on and is the default for M365 data. Forcepoint offers the deepest classifiers and regulatory templates at roughly $35–$60 per user per year; Netskope and Zscaler provide SSE-integrated DLP. There is no maintained full open-source DLP — honest advice for small organizations is to use the Purview or Google Workspace rules they already pay for. DLP is roughly 20% tool and 80% data classification; expect high false positives for six to twelve months.
MDM. Microsoft Intune at roughly $8/user/mo standalone and included in M365 Business Premium and E3; Jamf Pro at roughly $4–$10.50 per device per month for Apple-heavy fleets; JumpCloud for cross-OS SMB. Consensus: Jamf for Mac-heavy, Intune for Windows-first with some Macs. Open source: Fleet (osquery-based, open core), MicroMDM, Headwind MDM — all niche, since enrollment plumbing favors commercial tools.
Backup. Veeam Data Platform leads, sold per workload on quote, with third-party guides putting typical spend around $1–2K per year per ten VMs for Foundation and more for editions with malware detection and clean-restore features. Alternatives: Rubrik, Cohesity, Druva, Acronis, Datto. Open source: Restic, BorgBackup, Proxmox Backup Server, Bacula/Bareos, UrBackup.
The non-negotiables regardless of vendor: 3-2-1, immutability through object lock or a hardened repository, offline or out-of-band copies, and tested restores. Backup jobs that succeed nightly and were never restore-tested are the most common ransomware post-mortem finding.
15. Network security monitoring, threat intel, DFIR, awareness, GRC
NSM. Zeek for network metadata, Suricata for signature and anomaly detection, Wireshark for packet analysis. Security Onion packages all of these with Elastic into a free distribution, actively maintained (2.4.201, January 2026). Encryption limits payload inspection, so the value now is metadata, DNS, and east-west visibility — budget sensor hardware and an analyst or skip it.
Threat intelligence. Recorded Future (Mastercard) at roughly $60K–$150K+ per year entry, plus Mandiant/Google TI, CrowdStrike Falcon Intelligence, and Flashpoint. Open source and free: MISP (the sharing standard), OpenCTI (STIX-native, current momentum leader), abuse.ch feeds, AlienVault OTX, and the CISA KEV catalog and advisories. Small teams need curated, actionable intelligence far more than a platform.
DFIR. Velociraptor — free, open source, Rapid7-stewarded — is the single best force multiplier for a lean team doing endpoint forensics and hunting at scale. Autopsy and The Sleuth Kit for disk, KAPE for triage collection, Volatility 3 for memory. Commercial: Magnet Axiom, Cellebrite for mobile, Binalyze AIR — needed for court-grade mobile and eDiscovery workflows.
Security awareness. KnowBe4 leads at roughly $10–$30 per user per year by tier and volume; alternatives include Proofpoint SAT, Hoxhunt, SoSafe, usecure, and Curricula. Open source: GoPhish for phishing simulation plus free CISA and SANS materials. Evidence note: training measurably reduces click rates, but independent research on durable behavior change is mixed — pair it with phishing-resistant MFA.
GRC and compliance automation. Vanta and Drata for SOC 2 and ISO 27001 automation, with SMB entry around $10K–$25K per year and enterprise far higher; Secureframe and Sprinto are cheaper. Open source: eramba community edition, CISO Assistant. These compress audit preparation dramatically but do not replace the auditor's fee.
16. MDR and MSSP — the answer for small teams
If an organization cannot staff 24/7 eyes on glass — roughly, fewer than five dedicated security FTEs — buy MDR before buying more tools.
Pricing transparency is poor: only Huntress ($7.99 per endpoint per month at 100 endpoints, $8.99 at the 50-endpoint minimum) and Red Canary ($10 per endpoint per month via AWS Marketplace) publish rates. Working estimates: 100 endpoints roughly $4K–$30K per year; 1,000 endpoints roughly $96K–$300K per year. Other sources put organization-level MDR contracts at $50K–$300K+ annually for mid-size environments.
| Provider | Model and fit | Notes |
|---|---|---|
| Huntress | SMB and mid-market up to ~1,000 endpoints; MSP-native | Cheapest credible 24/7 SOC; added Managed SIEM and M365/Defender integration; limited Linux and cloud depth. Strong practitioner reputation |
| CrowdStrike Falcon Complete | Enterprise; fastest claimed response (15-minute median containment, a vendor metric); $1M warranty | Requires the full Falcon stack — real lock-in |
| Arctic Wolf | Mid-enterprise; per-user pricing (~$96–$180/user/yr estimated); named "concierge" analysts; platform-agnostic | Per-user pricing can beat or badly lose to per-endpoint depending on device ratios. Practitioner grumbles about alert quality varying by assigned team |
| Sophos MDR | SMB → mid-market; works with third-party EDRs; includes Secureworks Taegis | |
| SentinelOne Vigilance | Add-on roughly $15–$30/endpoint/yr for existing S1 customers | Cheapest path if you already own Singularity Complete |
| Expel, Red Canary | Technology-agnostic, transparent, strong reporting | Red Canary is now Zscaler-owned; verify current independence |
When buying MDR, the questions that matter are: will they contain, or only notify? Does coverage include cloud and identity, not just endpoints? What is the SLA on time-to-notify, in writing? Are detections portable if you leave? Who specifically will be on your account? MITRE runs managed-services evaluations too, and those are worth reading alongside vendor materials.
17. CISA free tools and services (US)
CISA maintains a catalog of no-cost services worth a dedicated page on any US-focused site:
- Cyber Hygiene Vulnerability Scanning — free continuous external scanning for US public and private critical-infrastructure organizations; CISA reports roughly 40% exposure reduction in the first year. Enroll via vulnerability@cisa.dhs.gov.
- The KEV catalog — the best free patch-prioritization signal in the industry.
- CSET (assessment tool), Logging Made Easy (Windows log collection for small organizations), Malcolm (network traffic analysis), Decider (ATT&CK mapping), Untitled Goose Tool (Azure and M365 incident triage), and the Tabletop Exercise Packages.
Caveat: CISA's 2025–26 budget and staffing turbulence has affected some program cadence; verify service availability at intake.
18. Cross-cutting guidance
A defensible stack order for a small organization: phishing-resistant MFA → patching (Action1's free tier covers 200 endpoints) → Microsoft 365 Business Premium or equivalent, which bundles Defender for Business, Intune, and Entra P1 → password manager → immutable, tested backups → MDR → then everything else.
An evidence hierarchy for product claims: MITRE ATT&CK Evaluations (read the raw results, not the press releases) > AV-Comparatives and AV-TEST > Gartner and Forrester positioning > peer reviews > vendor claims. Note that declining MITRE participation weakens the public evidence base specifically for Microsoft, Palo Alto, and SentinelOne — absence of data is not evidence of weakness, but it shifts the burden onto buyer-run proofs of concept.
Privacy and data handling. EDR, XDR, and SIEM tools ship endpoint telemetry to vendor clouds. Check data residency options — CrowdStrike, SentinelOne, and Microsoft all offer regional clouds, while Wazuh and Security Onion keep data on premises, which is a genuine open-source advantage for sovereignty-sensitive organizations. ESET's EU headquarters and self-hosted stacks are common answers to GDPR-driven requirements.
False positives are a cost center. Labs penalize them; in SAST the rate decides developer adoption; in SIEM and MDR, alert fidelity is the product. Pilot on your own environment and measure.
Every tool is a program. Budget 0.25 to 1.0 FTE per major console you operate, or consolidate onto a platform and accept concentration risk — which 2024–26 events (the CrowdStrike outage, Fortinet's exploit cadence, vendor breaches at Okta and BeyondTrust) show is real in both directions.
Appendix: open-source alternative map
| Commercial category | Best open-source alternative(s) |
|---|---|
| EDR/EPP | Wazuh + osquery/Fleet + Velociraptor (visibility, not full prevention) |
| NGFW | pfSense / OPNsense with Suricata |
| SIEM | Wazuh; Security Onion; Elastic Basic |
| SOAR | Shuffle; n8n; StackStorm |
| Vulnerability scanning | Greenbone/OpenVAS Community; Nuclei |
| Patch management | Ansible; WSUS; unattended-upgrades; Action1 free ≤200 |
| WAF | Coraza/ModSecurity with OWASP CRS; CrowdSec |
| API security | OWASP ZAP; gateway policies |
| CSPM/CNAPP | Prowler; ScoutSuite; Checkov |
| Container/K8s | Trivy; Falco; Tetragon; Kyverno |
| SCA/SAST/DAST | Semgrep OSS; Grype/Syft; Gitleaks; ZAP |
| IAM/SSO | Keycloak; Authentik |
| PAM | Teleport; JumpServer; Guacamole; Vault/OpenBao |
| Password manager | Bitwarden (itself open source); KeePassXC; Vaultwarden |
| Email security | Rspamd; GoPhish for simulation; free DMARC tooling |
| DLP | No strong OSS — use built-in Purview or Workspace rules |
| MDM | Fleet; MicroMDM; Headwind |
| Backup | Restic; Borg; Proxmox Backup Server; Bareos |
| NSM | Zeek; Suricata; Wireshark; Security Onion |
| Threat intel | MISP; OpenCTI; abuse.ch; OTX; CISA KEV |
| Forensics | Velociraptor; Autopsy/Sleuth Kit; Volatility 3 |
| Awareness | GoPhish plus free CISA/SANS content |
| GRC | eramba CE; CISO Assistant |
| MDR | No open-source substitute — MDR is people. This is the category where you pay |