- Best for
- Security teams already using Armis Centrix for unmanaged, IoT, OT or medical-device visibility
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
- OT/ICS
- IoT
- Mobile
Your team still owns
- Approving or executing containment actions in NAC, firewall, endpoint, identity or ITSM tools
- Patching, remediation, recovery and business-owner decisions after Armis investigation support
- Maintaining Armis sensors, integrations, asset context and criticality data
- Owning the broader SIEM, SOAR, SOC workflow and escalation process outside Armis scope
- Confirming whether optional assessments, policy tuning or resident-engineer services are included
Pricing
| Line | Figure |
|---|---|
| Published price | G-Cloud examples from £134,400 per asset block |
| Billing model | Tiered, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Fits buyers that already use Armis and need help operationalizing connected-asset alerts
- Covers unmanaged, OT, IoT and medical-device environments that endpoint MDR tools can miss
- Public procurement material gives a directional service-specific pricing signal
- Works beside a buyer's existing SOC tools instead of requiring a full SOC platform swap
Watch out for
- Not a full managed SOC and not a general MDR service for non-Armis environments
- Containment depends on buyer-owned controls, integrations and approval rules
- Public customer reviews mostly describe Armis Centrix, not Managed Threat Service delivery
- ServiceNow ownership may change packaging or integration path over time
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Customers like
- Reviews frequently mention visibility into unmanaged, OT, IoT and medical assets
- Customers call out investigation search, risk context and support or training help
- G2 reviews describe Armis as useful beside SIEM, endpoint and vulnerability workflows
Watch out for
- Managed Threat Service-specific customer reviews were not found
- G2 reviewers mention limited remediation, clunky integrations and add-on cost concerns
- Reddit discussion is mostly platform evaluation, pricing and enforcement skepticism
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which findings will Armis analysts investigate versus only enrich and route back to our SOC?
- Which containment actions can be pre-approved through our integrated controls and who executes them?
- Does the quote include MTS Foundations, policy tuning, weekly reviews, onsite resources and the required Armis platform license?
Integrations
Editorial notes
Why investigate and advise
The Managed Threat Service brief supports continuous threat hunting, human analysis, suspicious-activity review, policy tuning, weekly findings and support for active investigations. It does not prove that Armis analysts normally execute containment actions for the buyer.
Platform boundary
The service is tied to Armis Centrix. Public procurement material says Armis Asset Management and Security or Armis OT Security is required, so buyers should not treat MTS as a standalone managed SOC service.
Containment boundary
Armis Centrix can trigger actions through integrated NAC, firewall, endpoint, ticketing and SOAR tools. The public profile treats those as platform or buyer-control actions unless the contract states that Armis analysts execute them.
Ownership change
ServiceNow completed its acquisition of Armis on April 20, 2026. Armis Centrix remains available as a standalone solution, with more ServiceNow platform integration expected over time.