Mandiant Managed Defense

MDR

Mandiant Managed Defense is an MDR service from Google Cloud that combines Mandiant analysts, Google Security Operations and supported endpoint, network, cloud, identity, email and OT telemetry. After an alert, Mandiant triages, investigates, hunts and can run scoped response actions such as host containment through supported technologies, while the buyer still owns Google SecOps licensing, connected tools, access rules, remediation and recovery.

What they do
Contain threats
Works with
Either
Built for
Mid-Market / Enterprise
Price
CDW reseller listing shows $53.99 for one subscription license SKU
Best for
Mid-market and enterprise teams standardizing security operations on Google Security Operations

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications
  • OT/ICS

Your team still owns

  • Licensing and operating the Google Security Operations environment and required partner technologies
  • Connecting enough endpoint, cloud, identity, network, email and OT telemetry for Mandiant to investigate
  • Approving which response actions Mandiant can run through partner tools or SOAR playbooks
  • Handling internal remediation, recovery, user communication and business-owner decisions
  • Confirming whether incident response handoff, threat briefings and extra consulting are included or separate

Pricing

Line Figure
Published price CDW reseller listing shows $53.99 for one subscription license SKU
Billing model Per-asset, Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Fits buyers that want Mandiant expertise without replacing every endpoint or network tool
  • Official documentation names the supported technologies and parser requirements buyers need to verify
  • Response evidence goes beyond advice-only MDR when the right partner tooling and authority are in scope
  • Public review surfaces give more customer signal than many consulting-led security operations services

Watch out for

  • Google Cloud does not publish a universal Managed Defense price list
  • Full value depends on Google SecOps ingestion and supported telemetry coverage
  • Response authority must be negotiated because not every action is available in every connected tool
  • Review evidence includes configuration and reporting caveats, plus incentivized TrustRadius reviews

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Gartner excerpts mention smooth onboarding, monitoring and proactive alert handling
  • TrustRadius reviewers cite 24/7 analyst review, threat hunting, response support and reduced manual monitoring
  • Review evidence fits buyers that need outside SOC capacity around existing security tools

Watch out for

  • Gartner visible dislikes mention configuration effort and training needs
  • TrustRadius complaints include reporting, asset views and integration coverage
  • Public Reddit evidence is too sparse to treat as a buyer consensus

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which supported technologies are required for Mandiant to contain hosts or collect files in our environment?
  2. Which actions are pre-authorized, which require approval and which remain recommendation-only?
  3. How are Google SecOps ingestion, partner product licensing, Managed Defense service fees and incident response handoff priced?

Integrations

Google Security OperationsCrowdStrike Falcon Insight XDRSentinelOne Singularity XDRMicrosoft Defender for EndpointTrellix Endpoint SecurityGoogle CloudAWSAzureManaged Defense PortalGoogle SecOps SOARGoogle Threat IntelligenceCorelight Open NDRPalo Alto Networks Next-Generation FirewallMicrosoft Defender for IdentityTrellix Email SecurityNozomi NetworksClaroty Continuous Threat DetectionArmis Centrix

Editorial notes

Why contain threats

Official Google Cloud material says Mandiant investigates and responds, and the datasheet gives examples such as host containment, file acquisition and closing alerts through supported technology partners. That supports Contain threats, but only inside the connected tools and rules of engagement.

Why not full SOC

Managed Defense gives 24/7 monitoring, investigation, hunting and response support, but the buyer still owns Google SecOps licensing, telemetry onboarding, partner tools, approvals and remediation. The evidence does not support saying Mandiant runs the entire SOC by default.

Platform boundary

The service is most specific around Google Security Operations and supported technologies. Buyers should not assume every SIEM, EDR, identity, email, cloud or OT source gets the same depth of investigation or response unless it appears in the supported-technology scope.

Pricing boundary

CDW provides a public reseller SKU price for one subscription license, while TrustRadius reports no listed pricing plans and Google Cloud routes buyers to sales. The public profile uses the CDW signal but does not turn it into a universal per-endpoint rate.

Customer evidence

Gartner and TrustRadius provide usable review evidence, but TrustRadius marks many visible reviews as incentivized. Public sentiment is therefore limited to repeated operational themes and does not rely on ratings alone.

Questions

Does Mandiant Managed Defense only investigate and advise?
No. This profile classifies it as Contain threats because official Google Cloud material and the technology datasheet support response actions such as host containment, file acquisition and alert closure through supported technologies. Buyers still need to confirm what Mandiant may do in their own tools.
Does Managed Defense require Google Security Operations?
The current public material is built around Google Security Operations and supported partner technologies. Buyers should confirm whether their deployment is Managed Defense for Google SecOps, Managed Defense Standard or a partner-specific scope, because telemetry and response actions depend on that scope.
Is Mandiant Managed Defense pricing public?
Only partly. CDW lists one Managed Defense subscription license SKU at $53.99, while Google Cloud does not publish universal list pricing and TrustRadius shows no listed plans. Treat public reseller pricing as a procurement signal, not a complete quote.