- Best for
- Lean IT or security teams that want an external team to monitor, investigate and help contain threats
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
- Containers & Kubernetes
Your team still owns
- Choosing the MDR bundle, Concierge tier, add-ons, warranty eligibility and retention scope
- Maintaining the endpoint, identity, email, cloud and network tools Arctic Wolf uses for telemetry and response
- Granting and testing Active Response permissions without overexposing privileged systems
- Remediation work outside configured Active Response, Managed Containment or incident-response scope
Pricing
| Line | Figure |
|---|---|
| Published price AWS Marketplace listing Public marketplace pricing is a starting signal, not a full quote. Confirm bundle level, Concierge tier, endpoint/security add-ons, warranty eligibility, retention and renewal terms. | AWS Marketplace MDR Basic: $44K/year for up to 100 users |
| Billing model | Per-user, Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Strong fit for lean teams that want MDR plus recurring security guidance
- Active Response gives buyers a clearer containment path than pure alert-and-advise services
- Broad public documentation makes integrations, permissions and response boundaries easier to verify
- AWS Marketplace gives at least one public pricing anchor for small MDR deals
Watch out for
- Buyers need to verify exactly which bundle, Concierge tier and add-ons are included
- Active Response depends on supported tools, licenses, API permissions and customer configuration
- Public reviews and Reddit threads mention alert volume, pricing increases, communication gaps and mixed endpoint-security experiences
- Arctic Wolf is not FedRAMP compliant, so US government and CUI environments need careful review
What buyers say
Alert noise
High
Transparency
Black-box
Customers like
- Buyers value having a named team that learns the environment and helps interpret alerts
- Reviews often mention easier audit documentation, NIST support and security posture reviews
- Customers like that MDR can cover endpoint, cloud, network and SaaS telemetry rather than a single control
Watch out for
- Some buyers report noisy alerts, weak investigation detail or slow communication
- Reddit renewal threads raise concerns about price increases and perceived scope changes
- Aurora Endpoint Security feedback is mixed after the Cylance acquisition, so endpoint replacement should be tested separately
Arctic Wolf's own 2025 report cites a 71% false-alarm rate. Reviewers repeatedly flag no raw-log access and a proprietary black-box approach.
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which bundle and Concierge tier are in the quote, and what changes between Core, Plus and Total?
- Which Active Response actions can Arctic Wolf run in our EDR, identity, email, network and cloud tools?
- Are Aurora Endpoint Security, Managed Risk, Managed Security Awareness, warranty or Incident360 included or separate?
Integrations
Editorial notes
Market position
Arctic Wolf is best read as MDR plus a broader security-operations platform, not just SOC alert forwarding. The named Concierge model and security touchpoints make it stronger for lean teams that want guided security operations, but MDR remains the core service label.
Response boundary
Arctic Wolf supports Managed Containment and Active Response across host, identity, email, network and URL surfaces. These actions depend on supported integrations, customer permissions, licensing and validation with the Concierge Security Team.
Bundle boundary
Arctic Wolf's public bundle terms separate Core, Plus and Total. Core centers on MDR, Plus adds Managed Risk, and Total adds Managed Security Awareness, JumpStart Retainer and warranty eligibility. Buyers should not assume every Arctic Wolf product is included in an MDR quote.
Endpoint change
Arctic Wolf closed its acquisition of BlackBerry's Cylance endpoint security assets in February 2025 and now offers Aurora Endpoint Security. Buyers should verify whether they are keeping an existing EDR integration or buying Aurora endpoint products.
Government boundary
Arctic Wolf supports some Microsoft GCC monitoring scenarios, but MDR supplemental terms say Arctic Wolf is not FedRAMP compliant. Government and CUI buyers should verify environment restrictions before treating it as a public-sector fit.