A Fortify 24x7 brand. Managed security programs for multi-site organizations across North America.Rate scheduleClient sign in
Enterprise Secure Systems
Enterprise Secure Systems/Programs/01Detection and Response

Detection that is read in context and worked by people.

Detection is only useful if somebody competent looks at it quickly. Here SentinelOne goes onto the machine, its telemetry arrives in Fluency next to everything else you run, and our analysts stand between the resulting queue and anybody's inbox. Six published rates divide the tiers and keep cluster nodes distinct from ordinary endpoints.

Program
01 of 06
Platform
SentinelOne and Fluency
Line items
6 priced separately
Unit basis
Endpoints and Kubernetes nodes priced apart
Billing
Card, monthly in advance, no term
How it works

The mechanism, not the brochure.

Three things worth understanding about this program before you price it, written for somebody who will be asked to defend the decision internally.

01

The agent decides fast, locally

Rather than hold out for a match against some known sample, SentinelOne judges process behavior on the machine, and that is precisely why it can move against something nobody had seen before breakfast. The decision happens locally, so a laptop sitting in an airport with no corporate network anywhere near it gets defended on identical terms to a desktop parked beside the server room.

02

The platform supplies the context

One machine behaving oddly is a ticket. The same behavior on four machines, following a sign-in from an unfamiliar location, is an incident. Fluency retains and correlates the telemetry that lets the second reading exist, which is the difference between closing an alert and understanding an intrusion.

03

A person owns the escalation

Detections are triaged by our analysts before anything is sent to you. Your team gets a case carrying a timeline, an assessment, and a recommendation. On the remediation tiers that case turns up once containment is already done, not while the room waits on somebody to authorize it.

Line items

The 6 line items in this program.

Each control is priced against its own unit and can be bought without the others. Rates come live from the billing catalog. Anything added here is held in the schedule and checked out from the rate schedule.

Fortify-MDR

Managed Detection and Response

The baseline detection line. A SentinelOne agent runs on the machine with behavioral detection and rollback available, and its telemetry lands in Fluency where it is retained and correlated against the rest of the estate. Detections are worked by our analysts before anything reaches you, so what arrives is a case with a timeline rather than an alert with a colour.

Loadingper protected endpoint
published rate, per month
Units
Fortify-MDR-K8

Managed Detection, Kubernetes Node

Managed detection carrying the identical posture onto a worker node in a cluster. Container workloads produce a different shape of telemetry than a laptop does and they scale on a different axis, which is why a node carries its own rate instead of being counted as one more endpoint.

Loadingper Kubernetes node
published rate, per month
Units
Fortify-XDR

Extended Detection, Cross Layer

Detection widened past the endpoint. Identity events, cloud service activity, and additional log sources are pulled into the same correlation, so a credential used somewhere improbable and a process launched on a workstation can be recognized as one story instead of two unrelated tickets closed by two different people.

Loadingper protected endpoint
published rate, per month
Units
Fortify-XDR-K8

Extended Detection, Kubernetes Node

Correlation across layers, brought to the nodes of a cluster. Cluster activity is read alongside the identity and cloud telemetry from the rest of the estate, which is how a service account being used by somebody who should not have it stops looking like ordinary automation.

Loadingper Kubernetes node
published rate, per month
Units
Fortify-XDR+

Extended Detection with Remediation

This tier carries the mandate to remediate. Our analysts are authorized to act on the endpoint rather than write to you and wait: isolating a machine, ending a process tree, and reversing changes at the hour it matters instead of the morning after somebody reads the email.

Loadingper protected endpoint
published rate, per month
Units
Fortify-XDR+K8

Remediation Tier, Kubernetes Node

That same mandate carried onto cluster nodes, where containment happens at the node while the incident is live instead of waiting behind an approval that has to locate somebody awake first.

Loadingper Kubernetes node
published rate, per month
Units
Where this program stops

What these line items do not do.

This program shortens the time an intruder operates unnoticed and limits what they accomplish while they do. Here is what it is not, stated plainly.

Detection sits under the whole program. This is the layer that reveals whether the rest were ever exercised, and its absence tends to become obvious only looking backwards.

The other programs

What sits alongside this one.

Any program can be bought on its own. Most estates end up running several, and the reason they work well together is that one desk operates all of them.

Notice

Heads up: card statements show FORTIFY 24X7 - Enterprise Secure Systems is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.