- Best for
- Regulated mid-market and enterprise buyers that need a UK-centered SOC partner
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
- OT/ICS
Your team still owns
- Defining whether the engagement is hybrid, fully outsourced or limited to a specific SOC function
- Keeping tenant access, SIEM, EDR, XDR, cloud and OT telemetry in scope and correctly connected
- Setting which containment and remediation actions Bridewell can take without extra approval
- Handling business-owner decisions, user communication, IT remediation and recovery work
- Confirming which incident response, forensics, testing and vulnerability services are included or separately scoped
Pricing
| Line | Figure |
|---|---|
| Published price | Indicative G-Cloud references start at £5.25 per user and £3.04 per server per month |
| Billing model | Per-user, Per-asset, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Fits buyers that want a managed SOC rather than a narrow endpoint-only MDR service
- Fully outsourced model can move daily SOC ownership to Bridewell inside the contracted scope
- Hybrid model lets internal teams keep context while Bridewell adds 24/7 analysts and process
- Public G-Cloud material gives directional pricing signals for government-style procurement
Watch out for
- Buyers need the contract to separate hybrid support from fully outsourced SOC ownership
- Response authority depends on agreed playbooks, tool permissions and approval rules
- Public pricing is procurement-specific and still varies by users, servers, service tier and deployment work
- Independent product-specific customer review evidence is thin
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which SOC tasks are fully outsourced, and which still sit with our internal team?
- Which containment and remediation actions can Bridewell take without waiting for approval?
- Are Microsoft Sentinel deployment, SIEM tuning, OT or ICS coverage and incident response included in the quoted scope?
Integrations
Editorial notes
Why Run the SOC
Bridewell's SOC page says the service can be hybrid or fully managed, and says the fully outsourced model takes complete ownership and responsibility for security operations. That supports Run the SOC when the contract covers the fully outsourced SOC model.
Hybrid boundary
The same offer can also operate as a hybrid SOC. Buyers should not assume Bridewell owns every SOC task unless the statement of work names covered tools, alert queues, response authority, reporting and handoff paths.
Stack boundary
Official material supports Microsoft Sentinel deployment, Microsoft Defender XDR expertise, cloud SIEM, supported EDR and XDR integration, SIEM and SOAR enhancement, and monitoring tools deployed as code in the buyer tenant. The public profile avoids implying every third-party tool has equal support.
Pricing boundary
Bridewell does not publish a normal commercial price list on the service page. UK G-Cloud material gives public procurement ranges by user, server, term, service tier and deployment work, so the profile treats pricing as indicative and quote-dependent.
Customer evidence
Public customer stories support use cases in regulated and high-context environments, but they are vendor-controlled. Independent Bridewell SOC or MDR review depth on Gartner, G2, PeerSpot, TrustRadius and Reddit is thin, so no public customer-sentiment section is included.