patch&proof.
← Research library

Tools / Research chapter

Security Tool Comparison Tables

Research date: September 14–15, 2026. All pricing is list price or credible third-party range as of the dates cited. Enterprise security pricing is heavily nego

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026. All pricing is list price or credible third-party range as of the dates cited. Enterprise security pricing is heavily negotiated and changes frequently — treat every number as an anchor for a conversation, not a quote.


Two caveats that apply to every product on this page

1. No tool is universally secure. Detection and protection results depend on configuration, tuning, policy mode (audit versus block), agent coverage, log-ingestion decisions, and the humans watching the console. MITRE itself stresses that its evaluations do not rank vendors, and Forrester's Allie Mellen warned that vendors claiming perfect scores may be running unrealistic configurations.

2. Tools need staffing. An unwatched EDR console, an untuned SIEM, and an unreviewed vulnerability report provide close to zero value. For organizations without 24/7 security staff, managed detection and response is the right purchase, not another product. Roughly 65% of organizations under 1,000 employees lack 24/7 SOC coverage.


1. Market context: what changed in 2024–2026

Consolidation reshaped the landscape. Verify current ownership before signing multi-year deals.

Deal Value Status (Sept 2026)
Google → Wiz $32B Closed March 11, 2026 after DOJ antitrust clearance
Palo Alto Networks → CyberArk ~$25B Closed February 2026 — PAM is now a Palo Alto pillar
Cisco → Splunk $28B Closed March 2024; AI roadmap and pricing overhaul underway
Sophos → Secureworks $859M Closed Feb 2025; Taegis folded into Sophos
Proofpoint → Hornetsecurity $1.8B Completed 2025; extends Proofpoint into SMB/MSP
Mastercard → Recorded Future $2.65B Closed Dec 2024
Akamai → Noname Security ~$450M Closed 2024
Zscaler → Red Canary 2025; verify current independence of the MDR offering
Arctic Wolf → BlackBerry Cylance Feb 2025

Independent testing is thinning. In the 2025 MITRE ATT&CK Enterprise Evaluations, published December 11, 2025, only eleven vendors participated: Acronis, AhnLab, CrowdStrike, Cyberani, Cybereason, Cynet, ESET, Sophos, Trend Micro, WatchGuard, and WithSecure. Microsoft, Palo Alto Networks, and SentinelOne declined, citing resource demands. The 2025 round emulated Scattered Spider — the first cloud-infrastructure scenario — and Mustang Panda. Several vendors claim 100% detection; treat all such marketing skeptically.

The operational lesson of the era: CrowdStrike's July 19, 2024 faulty content update crashed roughly 8.5 million Windows machines globally. It was not a breach, but it is the canonical demonstration that kernel-level security agents are themselves operational risk. Stage updates, use N-1 rings, and keep recovery runbooks — regardless of vendor.


2. Endpoint: EDR, XDR, antivirus

Product List pricing (anchor) Best fit Independent evidence Notes
CrowdStrike Falcon Go $59.99, Pro $99.99, Enterprise $184.99 per device/yr list; real-world median contract ~$55K/yr; add-on modules can add 50–200% Mid-market → enterprise; SMB via Go/Pro or MSPs 2025 Gartner MQ EPP Leader; participated in MITRE 2025 and claims 100% (vendor claim) Cloud-native, light sensor, strong hunting. Weaknesses: cost creep through modules, upward-only true-ups, and the 2024 outage as a governance lesson
Microsoft Defender for Endpoint / XDR P1 ~$3/user/mo; P2 ~$5.20 standalone; P2 included in M365 E5; Defender for Business ~$3/user/mo in Business Premium Anyone already on Microsoft 365 2025 Gartner MQ EPP Leader; skipped MITRE 2025; consumer Defender scores at or near top in AV-TEST June 2026 Deep M365/Entra integration; XDR spans email, identity, endpoint. Requires licensing literacy; macOS and Linux parity lags Windows. Consumer Defender, free in Windows, is now a legitimately strong baseline
SentinelOne Singularity Core $69.99, Control $79.99, Complete $179.99, Commercial $229.99 per endpoint/yr list; negotiated $35–$75 at 500–1,000 seats SMB → enterprise; MSP-friendly 2025 Gartner MQ EPP Leader, fifth consecutive year; skipped MITRE 2025 On-device AI models work offline; ransomware rollback on Windows. Strong prior MITRE history; skipping 2025 removes fresh independent data
Sophos Intercept X ~$30–$80/endpoint/yr negotiated; MDR bundles common SMB/mid-market, MSP channel Participated in MITRE 2025; consistently top-tier in AV-Comparatives Business tests through mid-2026 Now incorporates Secureworks Taegis. Sensible default for SMBs wanting first-party MDR too
ESET Protect ~$40–$60/endpoint/yr SMB, constrained hardware, privacy-conscious EU orgs MITRE 2025 participant; consistently high AV-Comparatives marks with low false positives Lightweight agent; EU (Slovakia) HQ helps data-residency narratives. Less muscular EDR/XDR than leaders
Malwarebytes / ThreatDown Consumer ~$45/yr; business ~$69–$85/endpoint/yr Consumers, micro-business, remediation second opinion Consumer AV-Comparatives participant Strong cleanup reputation; business EDR is serviceable, not leading

Consumer antivirus reality. Independent labs show the top ten consumer engines clustering near 99–100% on real-world protection tests; the differences are in false positives and performance impact. For most consumers, built-in Microsoft Defender plus automatic updates plus a password manager plus browser hygiene beats buying a suite.

Open-source alternatives: Wazuh (free SIEM/XDR with file-integrity monitoring, vulnerability detection, and agent telemetry; cloud version from ~$571/mo), osquery and Fleet for telemetry, Velociraptor for DFIR at scale, ClamAV for mail and file-server scanning. Practitioner consensus: excellent learning and compliance value, not a drop-in replacement for commercial EDR without dedicated staff.


3. Firewalls and NGFW

Product Pricing anchor Best fit Notes
Palo Alto Networks Appliances ~$1K (PA-410) to $200K+; subscriptions often equal hardware cost annually Enterprise; best-of-breed inspection Consistent Gartner leader; premium price. Now owns CyberArk
Fortinet FortiGate Best price/performance in class; 40F–90F popular in SMB ($400–$2K plus ~$300–$1K/yr bundles) SMB → carrier; SD-WAN value leader The vulnerability track record is the story. Repeated critical, actively exploited FortiOS/FortiManager/FortiWeb flaws landed in CISA's KEV catalog through 2024–26, including additions in April and September 2026 with federal patch deadlines. If you run Fortinet edge devices you are signing up for an aggressive emergency-patch cadence, and management interfaces must never face the internet
Cisco (Secure Firewall, Meraki MX) Meraki MX ~$300–$4K/yr/site Cisco shops, distributed branch Cisco appeared alongside Citrix and Fortinet in Sept 2026 KEV additions. Firepower management UX is a chronic complaint; Meraki is loved for simplicity, disliked for license-expiry behavior
Cloudflare (Magic Firewall / Gateway) Zero Trust free tier ≤50 users; paid ~$7/user/mo Cloud-first orgs replacing appliance edge Firewall-as-a-service model

Open source: pfSense (Netgate) and OPNsense remain the standard free firewalls for labs and small business. They lack first-party TLS-inspection ecosystems and vendor SLAs; pair with Suricata or Zeek for detection.


4. Email security

Product Pricing anchor Best fit Notes
Microsoft Defender for Office 365 P1 ~$2/user/mo, P2 ~$5.20 (in E5) M365 organizations Configure SPF/DKIM/DMARC plus Safe Links and Safe Attachments correctly before buying anything additional
Proofpoint Quote-based; credible range ~$3–$8/user/mo Enterprise, regulated Category leader in gateways; acquired Hornetsecurity for SMB reach. Heavier administrative burden
Mimecast ~$3–$7/user/mo by bundle Mid-market Gateway plus archiving plus awareness
Abnormal Security Quote-only; third-party guides cite $4–$9/user/mo Organizations fighting BEC and vendor-email compromise API-based behavioral analysis layered on M365 or Google — the modern architecture

Open source and free: Rspamd and SpamAssassin for self-hosted mail; Sublime Security's free tier for detection-as-code on M365 and Google. DMARC enforcement using free tooling remains the highest-ROI email control available.


5. Identity, MFA, and hardware keys

Product Pricing anchor Best fit Notes
Microsoft Entra ID Free tier; P1 ~$6/user/mo (in E3/Business Premium); P2 ~$9 (in E5); Entra Suite ~$12 Any Microsoft shop Marginal cost near zero if already on E3/E5 — the decisive procurement fact. Note that Microsoft's own identity plane has had incidents, including the 2023 Storm-0558 key theft; even IdPs get breached
Okta SSO ~$2, Adaptive MFA ~$3, Lifecycle Mgmt ~$4, Universal Directory ~$2 per user/mo; realistic stack ~$11/user/mo, ~$132K/yr for 1,000 users at list Heterogeneous and multi-cloud estates; best app catalog Largest independent IdP, plus Auth0 for customer identity. Past incidents (2022 Lapsus$, 2023 support-system breach) drove a major security overhaul — evaluate current posture rather than assuming either extreme
Cisco Duo Free ≤10 users; Essentials $3, Advantage $6, Premier $9 per user/mo MFA-first buyers, healthcare, education Easiest MFA rollout in the industry; Premier adds phishing-resistant options
JumpCloud ~$9–$24/user/mo by bundle SMBs without AD; Mac and Linux fleets Directory plus SSO plus MDM plus MFA — "cloud AD" for small teams

Open source: Keycloak (the de facto OSS IdP), Authentik, Authelia, Zitadel. Viable for engineering-led organizations, but you then own upgrades, high availability, and incident response for your own identity provider — a serious commitment.

Hardware keys. YubiKey 5 series roughly $50–$75; Security Key series (FIDO2-only) roughly $25–$29; Google Titan roughly $30–$35; Token2 and Nitrokey as cheaper and open-hardware alternatives. FIDO2/WebAuthn keys and passkeys are the only widely deployed phishing-resistant MFA. Buy two per user.


6. Privileged access management

Product Pricing anchor Notes
CyberArk (Palo Alto Networks) Quote-only; commonly $100K+ initial for enterprise vaulting Market leader; acquisition closed February 2026, so expect platform bundling and roadmap shifts. Existing customers should watch renewal terms
Delinea, BeyondTrust Mid-market friendlier; quote-based BeyondTrust's Remote Support SaaS compromise in December 2024, connected to the US Treasury incident, is a reminder that PAM vendors are high-value targets
Open source: Teleport, JumpServer, Apache Guacamole, HashiCorp Vault / OpenBao Free Excellent for server and Kubernetes access; weaker on Windows administrative workflows and session-recording compliance packaging

7. Password managers

Product Pricing (2026) Independent evidence Notes
Bitwarden Free tier (unlimited passwords); Premium $10/yr; Families $40/yr; Teams $4, Enterprise $6 per user/mo Open source; annual third-party audits with clean results; no known breach Best value; self-hostable, including the community Vaultwarden server
1Password Individual $2.99/mo; Families $5.99/mo; Teams Starter $19.95/mo (≤10); Business $7.99/user/mo SOC 2 Type II; audited; no known breach; higher autofill success in third-party testing Best UX; the Secret Key design means a stolen server copy alone is insufficient. Travel Mode, SSH agent
Keeper Business ~$3.75–$5/user/mo SOC 2, FedRAMP Strong compliance and government story; reviewers note aggressive upsells

Context. The 2022 LastPass breach, in which encrypted vaults were exfiltrated and weak-iteration vaults were later cracked, remains the cautionary tale: vendor choice and master-password strength both matter. KeePassXC is the local-file option for individuals who refuse cloud sync.


8. SIEM

The most staffing-sensitive category in security. An untuned SIEM is an expensive log bucket.

Product Pricing Best fit Notes
Splunk (Cisco) ~$665–$1,620/GB/day/yr; entry ~$8–15K; workload pricing overhaul under Cisco Large enterprise with budget and staff Gold-standard search and ecosystem; notorious cost at scale
Microsoft Sentinel $4.30/GB pay-as-you-go; commitment tiers to ~$2.05/GB; Basic Logs $1.00/GB M365 and Azure shops Most transparent pricing in the category; E5 customers get some free ingestion; KQL skill required
Elastic Security Free Basic tier self-hosted; Platinum from ~$131/mo cloud Engineering-led teams Cost shifts from license to engineer time
CrowdStrike NG-SIEM (LogScale) $5.95/GB pay-as-you-go; 10GB/day free tier Falcon customers Index-free architecture, fast
Rapid7 InsightIDR $70.40/asset/yr (251-asset minimum) Mid-market wanting SIEM plus UEBA bundled
Google SecOps (Chronicle) Quote-only Large estates Flat-ish data-cap model

Open source: Wazuh (free, SIEM plus XDR) and Security Onion (free distribution bundling Suricata, Zeek, and Elastic; 2.4.201 released January 2026 with version 3 rolling out). Every serious total-cost analysis reaches the same conclusion: free SIEM costs one or more engineers.


9. SOAR and automation

Twelve of the major vendors are quote-only; the exceptions are Tines (free community tier, then per-workflow pricing) and Shuffle (open source, free self-hosted). Leaders: Palo Alto Cortex XSOAR/XSIAM, Splunk SOAR, Tines, Torq, Swimlane. The trend is that standalone SOAR is dissolving into SIEM and XDR platforms and into general hyperautomation tools. Open source: Shuffle, n8n, StackStorm.

The reality check worth publishing: SOAR pays off only after detections are tuned. Automating a noisy SOC automates the noise.


10. Vulnerability scanning and patch management

Product Pricing anchor Notes
Tenable Nessus Professional $4,790/yr; Tenable VM/One per-asset quote De facto standard scanner
Qualys VMDR Per-asset, quote Strong compliance and cloud-agent story
Rapid7 InsightVM ~$22–$26/asset/yr at volume Good remediation-workflow integration

Open source: OpenVAS / Greenbone Community Edition (free, capable, slower feeds than paid appliances), Nuclei (template-based, web-focused), OSV-Scanner (dependencies).

Patch management: Action1 is genuinely free for the first 200 endpoints; NinjaOne runs roughly $3–$5 per endpoint per month and is an MSP favorite; PDQ Deploy and Inventory are long-standing Windows-admin favorites; ManageEngine Patch Manager Plus is free up to 20–50 endpoints. Open source and built-in: WSUS, Ansible, unattended-upgrades, Chocolatey and winget scripting.

The honest framing: scanning is the easy part. Remediation SLAs and asset inventory are where programs fail. Prioritize KEV-listed vulnerabilities first.


11. WAF and API security

Product Pricing Notes
Cloudflare Free (basic managed rules) / Pro ~$25/mo / Business ~$250/mo / Enterprise quote Best ease of use plus CDN and DDoS bundle
AWS WAF Pay per rule and request (~$5/ACL + $1/rule + $0.60 per million requests) Fits AWS-native infrastructure; rule sprawl costs accumulate
Akamai, Imperva, Fastly Enterprise quote High end

Open source WAF: ModSecurity (engine stewardship moved to OWASP) with the OWASP Core Rule Set; the modern successor Coraza; CrowdSec for collaborative blocking; BunkerWeb.

API security platforms: Salt Security, Akamai API Security (formerly Noname), Traceable (acquired by Harness in 2025), Cequence, 42Crunch. All quote-only, typically $30K+ per year entry. CNAPPs such as Wiz are absorbing API discovery. Open source: OWASP ZAP for API DAST, plus gateway schema validation.


12. Cloud, container, and Kubernetes security

Product Pricing anchor Notes
Wiz (Google) Quote-only per workload; commonly ~$120–$350/workload/yr Category leader on agentless graph-based risk; now Google-owned as of March 2026. Multi-cloud customers should watch for roadmap gravity toward Google Cloud — Google's neutrality pledge is a vendor claim to monitor
Palo Alto Prisma Cloud / Cortex Cloud Credit-based, complex Broadest feature list; complexity and pricing opacity are common complaints
Microsoft Defender for Cloud Published Azure meters (Defender for Servers P2 ~$15/server/mo) Azure-first organizations
Orca, Sysdig, Lacework (now Fortinet FortiCNAPP) Quote Credible alternatives

Open source CSPM: Prowler, ScoutSuite, CloudSploit, Steampipe/Powerpipe benchmarks, Checkov for IaC. These cover posture checks well but do not provide attack-path graphs or runtime correlation.

Container and Kubernetes security is the strongest open-source category in this document: Trivy (the image and IaC scanning standard), Falco (CNCF-graduated runtime detection), Tetragon (eBPF), Kyverno and OPA Gatekeeper (policy), kube-bench and kube-hunter. A skilled platform team can build roughly 80% of a container-security program from open source; the commercial value is correlation, interface, and multi-cluster operations. Commercial: Wiz, Sysdig Secure, Aqua, Prisma, Upwind.


13. Application and dependency security

Product Pricing anchor Notes
Snyk Free tier; Team from ~$25/dev/mo; Enterprise quote Best SCA and developer experience; SAST weaker than dedicated tools
GitHub Advanced Security Since April 2025 sold as two SKUs: Secret Protection ~$19/committer/mo and Code Security ~$30/committer/mo; free for public repos CodeQL is genuinely strong; zero friction if you live in GitHub
Semgrep Free OSS engine; Pro per contributor Fast, tunable, low false-positive reputation among practitioners
SonarQube, Checkmarx, Veracode Community free (Sonar); others quote Established enterprise options

Open source: Semgrep OSS, CodeQL (free for open source), Trivy and Grype plus Syft for SCA and SBOM, OWASP ZAP and Nuclei for DAST, Gitleaks and TruffleHog for secrets, Dependency-Track for SBOM operations.

The adoption test: measure the false-positive rate in a pilot on your own code, not in a vendor demo. In this category, false positives decide whether developers use the tool or route around it.


14. DLP, MDM, and backup

DLP. Microsoft Purview DLP is included in E5 or the E5 Compliance add-on and is the default for M365 data. Forcepoint offers the deepest classifiers and regulatory templates at roughly $35–$60 per user per year; Netskope and Zscaler provide SSE-integrated DLP. There is no maintained full open-source DLP — honest advice for small organizations is to use the Purview or Google Workspace rules they already pay for. DLP is roughly 20% tool and 80% data classification; expect high false positives for six to twelve months.

MDM. Microsoft Intune at roughly $8/user/mo standalone and included in M365 Business Premium and E3; Jamf Pro at roughly $4–$10.50 per device per month for Apple-heavy fleets; JumpCloud for cross-OS SMB. Consensus: Jamf for Mac-heavy, Intune for Windows-first with some Macs. Open source: Fleet (osquery-based, open core), MicroMDM, Headwind MDM — all niche, since enrollment plumbing favors commercial tools.

Backup. Veeam Data Platform leads, sold per workload on quote, with third-party guides putting typical spend around $1–2K per year per ten VMs for Foundation and more for editions with malware detection and clean-restore features. Alternatives: Rubrik, Cohesity, Druva, Acronis, Datto. Open source: Restic, BorgBackup, Proxmox Backup Server, Bacula/Bareos, UrBackup.

The non-negotiables regardless of vendor: 3-2-1, immutability through object lock or a hardened repository, offline or out-of-band copies, and tested restores. Backup jobs that succeed nightly and were never restore-tested are the most common ransomware post-mortem finding.


15. Network security monitoring, threat intel, DFIR, awareness, GRC

NSM. Zeek for network metadata, Suricata for signature and anomaly detection, Wireshark for packet analysis. Security Onion packages all of these with Elastic into a free distribution, actively maintained (2.4.201, January 2026). Encryption limits payload inspection, so the value now is metadata, DNS, and east-west visibility — budget sensor hardware and an analyst or skip it.

Threat intelligence. Recorded Future (Mastercard) at roughly $60K–$150K+ per year entry, plus Mandiant/Google TI, CrowdStrike Falcon Intelligence, and Flashpoint. Open source and free: MISP (the sharing standard), OpenCTI (STIX-native, current momentum leader), abuse.ch feeds, AlienVault OTX, and the CISA KEV catalog and advisories. Small teams need curated, actionable intelligence far more than a platform.

DFIR. Velociraptor — free, open source, Rapid7-stewarded — is the single best force multiplier for a lean team doing endpoint forensics and hunting at scale. Autopsy and The Sleuth Kit for disk, KAPE for triage collection, Volatility 3 for memory. Commercial: Magnet Axiom, Cellebrite for mobile, Binalyze AIR — needed for court-grade mobile and eDiscovery workflows.

Security awareness. KnowBe4 leads at roughly $10–$30 per user per year by tier and volume; alternatives include Proofpoint SAT, Hoxhunt, SoSafe, usecure, and Curricula. Open source: GoPhish for phishing simulation plus free CISA and SANS materials. Evidence note: training measurably reduces click rates, but independent research on durable behavior change is mixed — pair it with phishing-resistant MFA.

GRC and compliance automation. Vanta and Drata for SOC 2 and ISO 27001 automation, with SMB entry around $10K–$25K per year and enterprise far higher; Secureframe and Sprinto are cheaper. Open source: eramba community edition, CISO Assistant. These compress audit preparation dramatically but do not replace the auditor's fee.


16. MDR and MSSP — the answer for small teams

If an organization cannot staff 24/7 eyes on glass — roughly, fewer than five dedicated security FTEs — buy MDR before buying more tools.

Pricing transparency is poor: only Huntress ($7.99 per endpoint per month at 100 endpoints, $8.99 at the 50-endpoint minimum) and Red Canary ($10 per endpoint per month via AWS Marketplace) publish rates. Working estimates: 100 endpoints roughly $4K–$30K per year; 1,000 endpoints roughly $96K–$300K per year. Other sources put organization-level MDR contracts at $50K–$300K+ annually for mid-size environments.

Provider Model and fit Notes
Huntress SMB and mid-market up to ~1,000 endpoints; MSP-native Cheapest credible 24/7 SOC; added Managed SIEM and M365/Defender integration; limited Linux and cloud depth. Strong practitioner reputation
CrowdStrike Falcon Complete Enterprise; fastest claimed response (15-minute median containment, a vendor metric); $1M warranty Requires the full Falcon stack — real lock-in
Arctic Wolf Mid-enterprise; per-user pricing (~$96–$180/user/yr estimated); named "concierge" analysts; platform-agnostic Per-user pricing can beat or badly lose to per-endpoint depending on device ratios. Practitioner grumbles about alert quality varying by assigned team
Sophos MDR SMB → mid-market; works with third-party EDRs; includes Secureworks Taegis
SentinelOne Vigilance Add-on roughly $15–$30/endpoint/yr for existing S1 customers Cheapest path if you already own Singularity Complete
Expel, Red Canary Technology-agnostic, transparent, strong reporting Red Canary is now Zscaler-owned; verify current independence

When buying MDR, the questions that matter are: will they contain, or only notify? Does coverage include cloud and identity, not just endpoints? What is the SLA on time-to-notify, in writing? Are detections portable if you leave? Who specifically will be on your account? MITRE runs managed-services evaluations too, and those are worth reading alongside vendor materials.


17. CISA free tools and services (US)

CISA maintains a catalog of no-cost services worth a dedicated page on any US-focused site:

  • Cyber Hygiene Vulnerability Scanning — free continuous external scanning for US public and private critical-infrastructure organizations; CISA reports roughly 40% exposure reduction in the first year. Enroll via vulnerability@cisa.dhs.gov.
  • The KEV catalog — the best free patch-prioritization signal in the industry.
  • CSET (assessment tool), Logging Made Easy (Windows log collection for small organizations), Malcolm (network traffic analysis), Decider (ATT&CK mapping), Untitled Goose Tool (Azure and M365 incident triage), and the Tabletop Exercise Packages.

Caveat: CISA's 2025–26 budget and staffing turbulence has affected some program cadence; verify service availability at intake.


18. Cross-cutting guidance

A defensible stack order for a small organization: phishing-resistant MFA → patching (Action1's free tier covers 200 endpoints) → Microsoft 365 Business Premium or equivalent, which bundles Defender for Business, Intune, and Entra P1 → password manager → immutable, tested backups → MDR → then everything else.

An evidence hierarchy for product claims: MITRE ATT&CK Evaluations (read the raw results, not the press releases) > AV-Comparatives and AV-TEST > Gartner and Forrester positioning > peer reviews > vendor claims. Note that declining MITRE participation weakens the public evidence base specifically for Microsoft, Palo Alto, and SentinelOne — absence of data is not evidence of weakness, but it shifts the burden onto buyer-run proofs of concept.

Privacy and data handling. EDR, XDR, and SIEM tools ship endpoint telemetry to vendor clouds. Check data residency options — CrowdStrike, SentinelOne, and Microsoft all offer regional clouds, while Wazuh and Security Onion keep data on premises, which is a genuine open-source advantage for sovereignty-sensitive organizations. ESET's EU headquarters and self-hosted stacks are common answers to GDPR-driven requirements.

False positives are a cost center. Labs penalize them; in SAST the rate decides developer adoption; in SIEM and MDR, alert fidelity is the product. Pilot on your own environment and measure.

Every tool is a program. Budget 0.25 to 1.0 FTE per major console you operate, or consolidate onto a platform and accept concentration risk — which 2024–26 events (the CrowdStrike outage, Fortinet's exploit cadence, vendor breaches at Okta and BeyondTrust) show is real in both directions.


Appendix: open-source alternative map

Commercial category Best open-source alternative(s)
EDR/EPP Wazuh + osquery/Fleet + Velociraptor (visibility, not full prevention)
NGFW pfSense / OPNsense with Suricata
SIEM Wazuh; Security Onion; Elastic Basic
SOAR Shuffle; n8n; StackStorm
Vulnerability scanning Greenbone/OpenVAS Community; Nuclei
Patch management Ansible; WSUS; unattended-upgrades; Action1 free ≤200
WAF Coraza/ModSecurity with OWASP CRS; CrowdSec
API security OWASP ZAP; gateway policies
CSPM/CNAPP Prowler; ScoutSuite; Checkov
Container/K8s Trivy; Falco; Tetragon; Kyverno
SCA/SAST/DAST Semgrep OSS; Grype/Syft; Gitleaks; ZAP
IAM/SSO Keycloak; Authentik
PAM Teleport; JumpServer; Guacamole; Vault/OpenBao
Password manager Bitwarden (itself open source); KeePassXC; Vaultwarden
Email security Rspamd; GoPhish for simulation; free DMARC tooling
DLP No strong OSS — use built-in Purview or Workspace rules
MDM Fleet; MicroMDM; Headwind
Backup Restic; Borg; Proxmox Backup Server; Bareos
NSM Zeek; Suricata; Wireshark; Security Onion
Threat intel MISP; OpenCTI; abuse.ch; OTX; CISA KEV
Forensics Velociraptor; Autopsy/Sleuth Kit; Volatility 3
Awareness GoPhish plus free CISA/SANS content
GRC eramba CE; CISO Assistant
MDR No open-source substitute — MDR is people. This is the category where you pay

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval