Armis Managed Threat Service

MSSP

Armis Managed Threat Service is an analyst-assisted threat hunting and alert-investigation service for organizations already using Armis Centrix. After an alert, Armis analysts enrich findings, review suspicious activity, tune policies and advise on investigation priorities, while the buyer still owns containment actions, remediation, connected controls and business approvals.

What they do
Investigate and advise
Works with
Their platform
Built for
Mid-Market / Enterprise
Price
G-Cloud examples from £134,400 per asset block*
Best for
Security teams already using Armis Centrix for unmanaged, IoT, OT or medical-device visibility

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications
  • OT/ICS
  • IoT
  • Mobile

Your team still owns

  • Approving or executing containment actions in NAC, firewall, endpoint, identity or ITSM tools
  • Patching, remediation, recovery and business-owner decisions after Armis investigation support
  • Maintaining Armis sensors, integrations, asset context and criticality data
  • Owning the broader SIEM, SOAR, SOC workflow and escalation process outside Armis scope
  • Confirming whether optional assessments, policy tuning or resident-engineer services are included

Pricing

Line Figure
Published price G-Cloud examples from £134,400 per asset block
Billing model Tiered, Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Fits buyers that already use Armis and need help operationalizing connected-asset alerts
  • Covers unmanaged, OT, IoT and medical-device environments that endpoint MDR tools can miss
  • Public procurement material gives a directional service-specific pricing signal
  • Works beside a buyer's existing SOC tools instead of requiring a full SOC platform swap

Watch out for

  • Not a full managed SOC and not a general MDR service for non-Armis environments
  • Containment depends on buyer-owned controls, integrations and approval rules
  • Public customer reviews mostly describe Armis Centrix, not Managed Threat Service delivery
  • ServiceNow ownership may change packaging or integration path over time

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Reviews frequently mention visibility into unmanaged, OT, IoT and medical assets
  • Customers call out investigation search, risk context and support or training help
  • G2 reviews describe Armis as useful beside SIEM, endpoint and vulnerability workflows

Watch out for

  • Managed Threat Service-specific customer reviews were not found
  • G2 reviewers mention limited remediation, clunky integrations and add-on cost concerns
  • Reddit discussion is mostly platform evaluation, pricing and enforcement skepticism

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which findings will Armis analysts investigate versus only enrich and route back to our SOC?
  2. Which containment actions can be pre-approved through our integrated controls and who executes them?
  3. Does the quote include MTS Foundations, policy tuning, weekly reviews, onsite resources and the required Armis platform license?

Integrations

SplunkMicrosoft SentinelGoogle ChronicleGoogle Security Operations SOARExabeamLogRhythmIBM QRadarSumo LogicCrowdStrikeSentinelOneMicrosoft Defender for EndpointAWSAzureGoogle CloudArmis CentrixServiceNowJiraBMCCisco ISEPalo Alto Networks

Editorial notes

Why investigate and advise

The Managed Threat Service brief supports continuous threat hunting, human analysis, suspicious-activity review, policy tuning, weekly findings and support for active investigations. It does not prove that Armis analysts normally execute containment actions for the buyer.

Platform boundary

The service is tied to Armis Centrix. Public procurement material says Armis Asset Management and Security or Armis OT Security is required, so buyers should not treat MTS as a standalone managed SOC service.

Containment boundary

Armis Centrix can trigger actions through integrated NAC, firewall, endpoint, ticketing and SOAR tools. The public profile treats those as platform or buyer-control actions unless the contract states that Armis analysts execute them.

Ownership change

ServiceNow completed its acquisition of Armis on April 20, 2026. Armis Centrix remains available as a standalone solution, with more ServiceNow platform integration expected over time.

Questions

Is Armis Managed Threat Service an MDR service?
Not in the usual endpoint MDR sense. This profile treats it as a managed threat service for Armis Centrix because the public material centers on threat hunting, suspicious-activity review, alert enrichment, policy tuning and investigation support around Armis data.
Does Armis contain threats for the buyer?
Armis Centrix can trigger actions through integrated controls such as NAC, firewall, SOAR and ticketing systems. The Managed Threat Service material does not prove that Armis analysts normally execute those actions, so buyers should confirm response authority in the contract.
Is Armis Managed Threat Service pricing public?
Armis does not publish standard website pricing. UK G-Cloud material gives service-specific examples for Managed Threat Services asset blocks, but buyers should treat those as indicative procurement references and request a current quote.