- Year established
- 2013
- Team size
- 400+
- Pricing model
- Subscription
- Notable clients
- DuPont, Ansys, Schumacher Homes
- Best for
- Mid-market and enterprise security teams that want 24/7 detection triage handled for them and are willing to keep their existing tooling.
About Red Canary
One of the better known names in managed detection and response, positioned explicitly as human led with AI assistance rather than automation first, which is the live argument in this category. Stated sector coverage is broad and enterprise weighted: financial services, healthcare, technology, manufacturing, education and government.
Worth being precise about what is being bought. The site describes both a managed service with 24/7 expert support and a platform that integrates with an existing stack, so this is a hybrid rather than a pure service engagement. For a buyer comparing managed SOC options that distinction matters and should be stated plainly on any list it appears in.
Named customers are limited to three on the pages read, DuPont, Ansys and Schumacher Homes. No headquarters, team size, founding year or pricing is stated, so `country` is blank and needs confirming before this record can serve a location filtered list. Copyright suggests operation since 2014.
Only three clients are named publicly, DuPont, Ansys and Schumacher Homes, which is a thin roster to check for a firm of this scale.
Featured work
Fortune 500 manufacturer — ransomware caught during an acquisition spree
A packaging manufacturer with 10,000+ employees and 300 locations was growing by acquisition and drowning in worm-generated alerts. A Red Canary threat hunter flagged irregular activity at 1am, identified credential dumping and encrypted files on a subsidiary network, and the customer added SentinelOne for wider visibility. It demonstrates out-of-hours human hunting on top of tooling, not just alert forwarding.
- MDR
- Ransomware
- Threat hunting
Kaseya / REvil supply chain attack response
During the July 2021 Kaseya VSA compromise, Red Canary detected the activity in two customer environments — Unitus Community Credit Union and a dental insurance provider — hours before the attack was public, and both reported zero business disruption. Unitus was exposed indirectly through a phone vendor, so the case shows detection based on behaviour rather than on knowing the vulnerable product in advance.
- MDR
- Supply chain
- Financial Services
Retail chain — Active Remediation as hands-on-keyboard response
A retailer with no in-house SOC and an MSP that could not perform response used Red Canary MDR plus its Active Remediation add-on, going from detection to containment and remediation within an hour. It shows the offering extends past notification into acting inside the customer's environment, which matters for buyers with no security staff to act on an alert.
- MDR
- Active Remediation
- Retail











