Cyderes MDR

MDR · MSSP · Co-Managed SOC

Cyderes MDR is a managed detection and response service that can work as investigation support, a co-managed SOC workflow or a fuller managed model around the buyer's existing tools. After an alert, Cyderes analysts and automation investigate, correlate identity and asset context and can run approved containment actions, while the buyer still owns tool access, rules of engagement, remediation and business approvals.

What they do
Co-manage the SOC
Works with
Your stack
Built for
Mid-Market / Enterprise
Price
Quote-based subscription by environment size and service level
Best for
Mid-market and enterprise teams that want MDR around existing EDR, SIEM, IAM, cloud and network tools

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications

Your team still owns

  • Defining rules of engagement and which containment actions Cyderes can take without approval
  • Maintaining access, licenses and data quality for the connected EDR, SIEM, IAM, cloud and network tools
  • Remediation, recovery, user communication and business-owner decisions after containment
  • Confirming whether Cyderes manages the relevant EDR, SIEM and supporting tools or only monitors them
  • Separating MDR scope from IAM, exposure management, DLP, DFIR retainers and other Cyderes services

Pricing

Line Figure
Published price Quote-based subscription by environment size and service level
Billing model Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Good fit for buyers that want MDR without replacing their entire security stack
  • Flexible operating models let the buyer keep control or hand over more tool operation by contract
  • Identity, asset and access context can help prioritize alerts by blast radius and business impact
  • Global SOC locations support North America, Europe / UK and APAC coverage requirements

Watch out for

  • Public pricing does not expose a numeric floor, minimum contract or packaged tier comparison
  • The broad Cyderes portfolio can blur what is included in MDR versus IAM, exposure management, DLP or DFIR services
  • Containment value depends on connected tools, permissions and agreed response rules
  • Public customer-review depth is thinner and more mixed than larger MDR providers

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Gartner review excerpts mention organized SOC work and proactive engagement
  • One visible Gartner excerpt says several initiatives generally went well
  • Reddit discussion mentions Cyderes in MDR shortlists, but without enough buyer detail to treat as a trend

Watch out for

  • Gartner shows a small review base and 22% one-star ratings
  • One visible critical Gartner review title mentions deliverable delays
  • G2 and PeerSpot did not provide usable Cyderes first-hand review depth during this pass

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which operating model applies to our quote: investigation-only, co-managed or fully managed MDR?
  2. Which endpoint, identity, cloud and network containment actions can Cyderes run automatically or manually under our rules of engagement?
  3. Does pricing include Meridian, CNAP, CYCLOPS deployment, SIEM or EDR management, DFIR support and all required integrations?

Integrations

Google Security Operations / ChronicleCyderes CNAPMicrosoft SentinelSplunkCrowdStrikeSentinelOneMicrosoft DefenderAWSAzureGoogle CloudMicrosoft 365MeridianCYCLOPSOktaCyberArkSailPointSaviyntZscalerFortinetPalo Alto NetworksRapid7ForescoutDelinea

Editorial notes

Why co-managed SOC

Cyderes MDR is broader than alert forwarding because public material supports 24/7 analyst investigation, predefined containment actions, optional EDR and SIEM management, customer-specific workflows and shared operation across existing tools. It is not classified as full SOC because Cyderes sells flexible models and the buyer still controls scope, access, approvals and remediation.

Response boundary

Public MDR material says Cyderes can execute predefined containment and response actions and that analysts remain accountable for material decisions. Buyers should still verify the exact actions available in their stack, because response depends on integrations and rules of engagement.

Platform boundary

Cyderes now emphasizes Meridian as the context layer for MDR, while public documentation still shows CYCLOPS forwarding to Cyderes CNAP, Google Chronicle and Microsoft Sentinel. Treat this as a Cyderes-operated workflow over customer tools, not a single standalone product.

Pricing boundary

No official numeric MDR list price or marketplace price was found. Gartner's public product page describes subscription pricing by environment size, endpoint count, service level and options, so the public profile keeps pricing directional rather than inventing a range.

Review evidence

Gartner has current Cyderes MDR ratings with mixed sentiment. G2 and PeerSpot did not provide enough first-hand Cyderes review depth, and Reddit mentions are sparse, so the public customer section should stay cautious.

Questions

Is Cyderes MDR a full managed SOC?
This profile classifies it as Co-manage the SOC. Cyderes can sell fuller managed models and can manage some security tools, but public material also supports investigation-only and co-managed MDR models, so buyers need to confirm how much daily SOC workflow Cyderes owns in their quote.
Can Cyderes contain threats?
Yes, when the required integrations and rules of engagement are in place. Cyderes says its MDR can execute predefined containment and response actions, but buyers should confirm which actions are automated, analyst-initiated or approval-gated.
Is Cyderes MDR pricing public?
No official numeric list price was found. Gartner describes subscription pricing that varies by environment size, endpoint count, service level and selected options, so buyers should ask how each connected tool and response scope affects the quote.