UnderDefense vs Expel
UnderDefense
UnderDefense is a managed security services firm offering 24/7 managed detection and response, managed SOC and SIEM, incident response, penetration testing and compliance services. Delivery is vendor-agnostic: the firm's MAXI platform layers alert triage, automation and reporting on top of a client's existing EDR and SIEM tools, and it operates co-managed SIEM on Elastic, Splunk, QRadar, LogRhythm and Sumo Logic. Founded in 2017, it is headquartered in New York and runs delivery teams from Jacksonville in the US, Krakow in Poland and Lviv in Ukraine. Its own site states 120 certified security engineers across three continents.
Pros
- Clutch lists UnderDefense at 4.9 out of 5 across 66 verified reviews, with a stated minimum project size of $5,000 and an hourly range of $50 to $99 (source: Clutch profile)
- The firm publishes an entry MDR rate of $11 per device per month on its own pricing page, which is more than most MSSPs disclose publicly
- MDR is designed to run on tools the client already owns rather than requiring replacement, with co-managed SIEM support named for five SIEM products (source: UnderDefense MDR services page)
- UnderDefense states it achieved SOC 2 Type I attestation on 25 November 2024, audited by Prescient Assurance (source: UnderDefense company news)
Things to check
Pricing: MDR published from $11 per device per month; Standard, Enhanced and Professional tiers are custom quoted and all MDR plans are sold as annual contracts. A free tier gives 14 days of platform access. Penetration testing engagements are stated at $5,000 to $30,000 depending on scope.
Expel
Founded in May 2016 by ex-Mandiant/FireEye veterans Dave Merkel, Justin Bajko, and Yanek Korff, Expel takes a deliberate stance: no proprietary agent, full transparency into SOC activity via the Workbench portal, and integration with whatever security tools the customer already owns. The company reached unicorn status in November 2021 and was named a Leader in The Forrester Wave for MDR Services, Q1 2025. Independent and private.
Pros
- Genuinely vendor-neutral: no Expel agent, integrates with existing EDR/SIEM/cloud stack
- Transparent operations via Workbench (customers see every analyst action in real time)
- Strong public commitments such as a 13-minute MTTR for critical threats
- Founding team's Mandiant lineage gives credibility in IR and detection engineering
Things to check
- 'Bring your own tech' means customers must already own (and license) suitable EDR/SIEM/cloud tooling
- Premium pricing relative to bundled MSSP offerings
- Limited public pricing; sales-led
Pricing: Custom (contact sales)