Protection plans
Protect
$14 per computer / month
$300 monthly minimum
24/7 managed detection and response for every computer
Included:
- Huntress EDR on Windows, macOS, Linux
- 24/7 threat review by Huntress SOC
- Isolation and removal of threats
- Microsoft Defender management
- Monthly summary report
- Priority incident response at reduced rate
- Small incidents on protected devices included*
Protect + Identity
$25 per user / month
$400 monthly minimum
Detection and response for your computers, your Microsoft 365 or Google Workspace accounts, and your people, with awareness training included
Everything in Protect, plus:
- Identity threat detection and response for Microsoft 365 or Google Workspace
- Security awareness training with phishing tests
Protect + Harden
$40 per user / month
$750 monthly minimum
Onboarding $500 to 1,500 once, waived after an assessment
Everything in Protect + Identity, plus the hardening, patching and reviews that prevent most incidents
Everything in Protect + Identity, plus:
- Security patching (OS and third-party apps)
- Monthly vulnerability scan
- Microsoft 365 or Google Workspace hardening, maintained
- Monthly review of sign-ins and account activity
- Quarterly review meeting
Protect + Harden + Respond
$55 per user / month
$1,000 monthly minimum
Onboarding $500 to 1,500 once, waived after an assessment
Everything in Protect + Harden, with the incident response retainer built in: 10 prepaid hours a year, work started within 4 hours any day, and your incident plan on file
Everything in Protect + Harden, plus:
- Incident response retainer: 10 prepaid hours a year
- We start work within 4 hours, any day
- Emergency contacts, access and a one-page incident plan on file
- Unused retainer hours convert to hardening or assessment credit at renewal
Month to month with 30 days' notice, or 10% off on a 12-month term. The two larger plans have a 3-month minimum.
What each plan includes
| Feature | Protect | Protect + Identity | Protect + Harden | Protect + Harden + Respond |
|---|---|---|---|---|
| Huntress EDR on Windows, macOS, Linux | Included | Included | Included | Included |
| 24/7 threat review by Huntress SOC | Included | Included | Included | Included |
| Isolation and removal of threats | Included | Included | Included | Included |
| Microsoft Defender management | Included | Included | Included | Included |
| Monthly summary report | Included | Included | Included | Included |
| Priority incident response at reduced rate | Included | Included | Included | Included |
| Small incidents on protected devices included* | Included | Included | Included | Included |
| Identity threat detection and response for Microsoft 365 or Google Workspace | Not included | Included | Included | Included |
| Security awareness training with phishing tests | Not included | Included | Included | Included |
| Security patching (OS and third-party apps) | Not included | Not included | Included | Included |
| Monthly vulnerability scan | Not included | Not included | Included | Included |
| Microsoft 365 or Google Workspace hardening, maintained | Not included | Not included | Included | Included |
| Monthly review of sign-ins and account activity | Not included | Not included | Included | Included |
| Quarterly review meeting | Not included | Not included | Included | Included |
| Incident response retainer: 10 prepaid hours a year | Not included | Not included | Not included | Included |
| We start work within 4 hours, any day | Not included | Not included | Not included | Included |
| Emergency contacts, access and a one-page incident plan on file | Not included | Not included | Not included | Included |
| Unused retainer hours convert to hardening or assessment credit at renewal | Not included | Not included | Not included | Included |
Projects and incident response
| Service | Price | Notes |
|---|---|---|
| Security Assessment | From $2,500 | Fixed price, report and walkthrough in about two weeks |
| Microsoft 365 or Google Workspace hardening | From $1,500 | Fixed price, before and after report |
| Incident response retainer | From $2,250 / year | For businesses not on a plan. 10 prepaid hours, work started within 4 hours, reduced rate |
| Emergency incident response (non-clients) | $350 / hour | 4-hour minimum, rate confirmed before work starts |
Pricing questions
What counts as a computer?
Any desktop, laptop or server running Windows, macOS or Linux. Phones and tablets are not billed. Plans cover every computer the business uses; we don't protect some and leave others.
What counts as a user?
Each person with a sign-in account. Shared mailboxes are not billed. A user's price covers one computer; extra computers, servers and shared computers are $14 a month each.
What is a small incident?
The first hour of follow-up on a confirmed detection on one protected device or account is included. Time beyond that, incidents that reach a second device or account, and any recovery or rebuild are billed at the client rate.
Can I sign up during an incident?
Yes, and we help right away. Client rates and included incidents apply to incidents that begin after onboarding is complete and the agents have been in place for 14 days; an incident already under way when you sign up is billed at the emergency rate. Anything we find already on your machines during onboarding is cleaned up as a separate, quoted project.
Can I cancel?
Month-to-month plans: cancel any time with 30 days' notice. Protect + Harden and Protect + Harden + Respond have a 3-month minimum, because the hardening work happens up front. A 12-month term takes 10% off the monthly plan price (one-time fees excluded) and renews yearly unless cancelled 30 days before renewal. Projects are billed as agreed in the quote.
Are there setup costs?
Protect and Protect + Identity have none. The two larger plans have a one-time onboarding fee, waived after a Security Assessment.
How is billing handled?
A monthly invoice, paid by ACH or card, for the number of users and computers at the end of the month. On a 12-month term, counts can go up any time and come down at renewal.