How to choose a cybersecurity company
Work out which of four things you are buying first: continuous defence, incident response, offensive testing or compliance assessment. Then check every credential on the issuing body's own register rather than the vendor's slide, and get a unit price before the second meeting. Most of this market publishes none.
By Rajat Kapoor
Updated August 2026
Key takeaways
Cybersecurity company covers four different purchases, and because these are annual contracts, buying the wrong one is not a mistake you correct in March.
Every credential worth anything is published by the body that issued it, so verify it on that register rather than on the vendor's own website.
Paid-entry awards, magazine programmes and partner-association memberships are marketing rather than independent validation.
There is no Gartner Magic Quadrant for managed detection and response, so a vendor claiming a position in one is describing a different document.
Quotes are priced per endpoint, per identity, per log source, per application or per test, so two proposals are rarely comparable until you convert both to an annual figure against your own estate.
The clause that matters most is what the provider is allowed to do on your systems without asking you first.
Someone has told you to sort out security, or a customer's questionnaire has landed, or your insurer has started asking questions. You are now shopping in a market where the vocabulary is deliberately loose, most of the credentials on a vendor deck can be bought, and almost nobody publishes a price.
Four things decide whether this goes well: knowing which of four quite different services you actually need, being able to check a claim rather than take it, being able to compare two quotes that are priced in different units, and getting the right terms in the contract. This page covers each in turn. It will not tell you who to hire, which is what our rankings are for.
Four purchases hide behind one phrase
Start here, because it is the most expensive thing to get wrong and it is usually got wrong before anyone has spoken to a vendor. These are annual contracts. Buying continuous monitoring when what you needed was an incident response retainer is not a decision you revisit in March.
Continuous defence. Someone watching your systems every hour of every day, triaging what fires and acting on it. This is what managed detection and response, or a managed SOC, buys. It is the largest part of the market and the one most people mean.
Incident response. The team you call when it has already happened. They contain it, work out what was taken, handle the ransom conversation if there is one, and produce the report your insurer and possibly your regulator will ask for. Arranged as a retainer in advance, or bought expensively in a panic.
Offensive testing. People paid to break in first. A scoped penetration test, a red team exercise, or continuous adversarial pressure against your estate. It produces findings, not protection.
Compliance assessment. Someone who examines your controls and signs something a third party will accept: a SOC 2 report, a FedRAMP authorisation package, a CMMC assessment. The signature is the product, which is why the firm doing the assessing usually should not be the firm paid to fix what it finds.
Most providers do one of these well and sell adjacent versions of the other three. The most common confusion is between the first and the third: a firm that tests your estate does not watch it, and a firm that watches it will not usually break into it. Ask which one the firm does most of, by revenue.
Once you know which of the four you need, the shortlist is a different job. We rank the field against a published rubric in best cybersecurity companies, and separately for US-headquartered providers where procurement requires one. If you are an MSP reselling security rather than buying it, the economics are different enough to need their own list.
How to check a credential, and which ones mean anything
This is the section worth the most, because it is where a shortlist gets shorter for good reasons. Everyone will tell you to look for certifications and analyst recognition. What decides whether that is useful is knowing where to look them up, since the strongest credentials in this market are published by the body that issued them and the weakest exist only on the vendor's own slide.
Check these at the source:
- CREST accreditation. CREST publishes its members, so a claim is verifiable in about a minute on the CREST Marketplace or the service selection platform. Accreditation is held by the company and certification is held by individuals. A firm that employs one certified tester is not an accredited firm.
- MITRE ATT&CK Evaluations. A technical exercise against a named adversary emulation rather than an analyst interview, which makes it the hardest thing here to fake. Rounds and participants are published at evals.mitre.org. Participation is not a pass or a fail: the results are published as data, and vendors interpret them in their own marketing.
- FedRAMP authorisation and assessor status. Both are listed on the FedRAMP Marketplace, including which assessors are themselves accredited to do the assessing.
- Analyst evaluations. A Forrester Wave publishes its criteria and its scoring, so you can read what was actually measured. Being named in a market guide is a different thing: it means a vendor is representative of a market, not that it was ranked in one.
One correction worth carrying, because the ambiguity gets leaned on: there is no Gartner Magic Quadrant for managed detection and response. Gartner publishes a Market Guide for MDR, which names representative vendors without ranking them. Gartner Peer Insights Customers' Choice is a separate programme measuring verified customer sentiment, and it is real. If a deck implies a Magic Quadrant position for MDR, ask which document it means.
What is not independent validation, whatever the slide says: awards you enter and pay to enter, magazine programmes, vendor channel-partner awards, and membership of a partner association. Membership is a fee, not a finding. And a framework the firm helps its clients comply with is not a certification the firm holds. Those two blur constantly, and one question separates them: who audited you, and when?
The weakest credential still worth something is a SOC 2 Type II or ISO 27001 the firm holds itself. It means an external auditor examined that firm's own controls. Useful, and not evidence about the service you are buying.
Getting a number before the third meeting
Most of this market publishes nothing at all. Part of that is legitimate: endpoint count, data volume, cloud footprint, hours of coverage and how much of the response the provider owns can move a quote several times over, so a single published number would mislead more buyers than it helped. Part of it is not. Opacity is worth money in a negotiation where the buyer often cannot tell two providers apart technically.
The bigger practical problem is that the quotes you do get are not comparable, because the unit changes underneath them. Huntress publishes a full rate card and it makes the point on its own: managed EDR at $8.99 per endpoint per month, identity detection at $4.80 per licensed identity, managed SIEM at $4.00 per source and awareness training at $2.08 per learner, on a 50 unit minimum and a 12 month standard term. Elsewhere, testing is priced per application or per test, consulting is priced hourly against a minimum engagement, and enterprise monitoring is quoted as an annual floor with tiers above it.
So normalise before you compare. Convert every proposal to an annual figure against your own estate: your endpoints, your identities, your log sources, your applications. Then ask what happens to that figure when any of them grows, because per-unit pricing scales without a renegotiation and also without a warning.
Ask for a range in the first email rather than the third meeting. A provider that will not give one before three calls is telling you something about how it negotiates. And treat any figure quoted as a given firm's rate by somebody else with care, because general market averages circulate in this category constantly and get repeated as though they were rate cards.
The terms that decide what happens at three in the morning
Everything above helps you pick. This is what decides whether the thing you picked works when it is needed, and it is the part a vendor's own buying guide never covers. Six questions, and the first matters more than the rest together.
What may they do without asking? The single most important clause. Some providers detect, investigate and hand you a recommendation. Some take contained action on your estate: isolating a host, disabling an account, killing a process. Get the list of what they may do unilaterally, what needs your approval, and what is explicitly out of scope, in writing, before signing.
Is there a consequence attached to the response time? A commitment with no consequence is a marketing figure. The question is not what the service level says, it is what happens when it is missed, and whether that is a service credit, a termination right, or nothing.
Who owns the tooling and the detection content when you leave? Platform-delivered services can mean the detections tuned for your environment leave with the vendor. Two years of tuning is a real asset, and it is worth establishing early whose asset it is.
Is incident response included, or does it start with a new statement of work? Some contracts sell response separately, which means the commercial conversation opens at the worst possible moment. Ask what an incident costs on top of the retainer.
What is the term, and how does it renew? Twelve months is common. So is auto-renewal on a short notice window, and that is the term people discover late.
What does leaving look like? Data export, log retention, and how long you keep access after the final invoice.
Frequently asked questions
What does a cybersecurity company actually cost?
It depends which of the four purchases you are making, and most providers publish nothing, so expect a scoping call. Where rates are published they are per unit rather than per company: Huntress lists managed EDR at $8.99 per endpoint per month, identity detection at $4.80 per licensed identity, managed SIEM at $4.00 per source and awareness training at $2.08 per learner, on a 50 unit minimum and a 12 month standard term. Testing is usually priced per application or per engagement instead, and consulting hourly against a minimum. The practical move is to convert every proposal into an annual figure against your own endpoint, identity and log source counts before comparing any two, and to ask for a range in your first email rather than after three meetings.
Do I need a cybersecurity company, or just better tools?
Tools produce alerts. The question is who reads them, and when. A week has 168 hours and one full-time analyst covers around 40 of them before holiday, sickness and training, so continuous coverage is a staffing problem before it is a software one, and that arithmetic is usually what decides it. If you have nobody who will look at an alert overnight, buying more tooling adds noise rather than defence. If you already have someone competent watching during the day, the honest purchase is often coverage for the hours they are asleep, which is a smaller and cheaper contract than a full managed service and is worth asking for by name.
How do I check that a security certification is real?
Check it with the body that issued it rather than on the vendor's website, because the credentials that mean the most are all published at the source. CREST publishes its accredited member companies, MITRE publishes its ATT&CK Evaluations rounds and the vendors that took part, and the FedRAMP Marketplace lists authorised offerings alongside the assessors accredited to assess them. Analyst evaluations such as the Forrester Wave publish their criteria and scoring, so you can read what was measured. Two distinctions catch people out: accreditation is held by a company while certification is held by individuals, and a framework a firm helps its clients comply with is not a certification that firm holds.
What should be in the contract before I sign?
Six things, and the first matters more than the rest combined. What the provider may do on your systems without asking, what needs your approval, and what is explicitly out of scope. Whether a missed response time carries a consequence, such as a service credit or a termination right, rather than being a stated intention. Who owns the tooling and the detection content tuned for your environment when the contract ends. Whether incident response is included or begins as a separate statement of work at the worst possible moment. The term length and how it renews, since auto-renewal on a short notice window is common. And what leaving involves: data export, log retention, and how long you keep access after the final invoice.
How long does it take to get a provider up and running?
Ask, and treat a vague answer as a finding, because the range is wide and the drivers are knowable. What moves it: whether the service runs on the provider's platform or over tooling you already own, how many log sources have to be connected and whether any are custom, how much tuning your environment needs before alerts become meaningful, and whether the contract requires you to migrate off a SIEM you already pay for. A service running on its own sensors can start producing alerts quickly but takes time to become accurate. One operating your existing stack starts slower and inherits your history. Get the onboarding plan in writing with named milestones, because the gap between contract signature and useful coverage is where most disappointment in this market lives.
How small is too small to need a security provider?
Size is the wrong test. What decides it is whether anyone outside your company requires you to prove something, and whether you would survive the week after an incident. A customer security questionnaire, a cyber insurance renewal, a regulator or a contract clause will each force the purchase regardless of headcount, and per-unit pricing means small estates can buy real coverage without an enterprise contract. The genuinely small buyer is usually better served starting with one purchase rather than a programme: coverage for the hours nobody is watching, or an incident response retainer arranged in advance so the contracting delay does not cost you the first day of a breach.