UnderDefense Cybersecurity
UnderDefense is a US-based private cybersecurity provider delivering AI-powered Managed Detection and Response, SOC-as-a-Service, Managed SIEM, compliance automation, and penetration testing through its MAXI platform to 500+ enterprises and mid-market organizations across five continents.
- Company typePrivate
- Founded2016
- HeadquartersNew York, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What UnderDefense Cybersecurity does
UnderDefense is a US-headquartered, private cybersecurity services provider founded in 2016 and operating globally across five continents, serving 500+ organizations in mid-market and security-conscious enterprise segments. Its core offering is UnderDefense MAXI, an agentic-AI SOC and compliance automation platform that combines autonomous AI investigation agents with human-analyst verification, delivering 2-minute alert triage and 15-minute mean-time-to-contain. The platform is structured as a unified suite of modules — MAXI MDR/SOC-as-a-Service, MAXI SOAR, MAXI Compliance, MAXI Cloud IR/CNAPP, and MAXI AI Copilot — supported by 250+ technology integrations across SIEM, EDR, cloud, identity, and ITSM ecosystems including Splunk, Microsoft, CrowdStrike, SentinelOne, Palo Alto, Google Chronicle, IBM QRadar, and Okta.
The company monetizes through a hybrid recurring-and-professional-services model: subscription-based MDR and SOCaaS priced at $11-$20 per asset/device/month, Managed SIEM at $15 per asset/month or $5,000-$10,000 monthly, compliance engagements at $70,000-$150,000, and penetration testing from $9,000 per engagement, complemented by a freemium self-serve tier and 14-day trial on the MAXI platform. Distribution combines direct enterprise field sales with product-led growth, AWS Marketplace procurement, and a partner referral network. UnderDefense is recognized through multiple 2024-2026 industry awards including Global Infosec Awards (MDR Service), G2 MDR Momentum Leader, Clutch Top Cybersecurity 2025, and a #2 ranking in Total Assure's Best Managed SOC Services 2026 evaluation.
UnderDefense Cybersecurity firmographics
Firmographics- Name
- UnderDefense Cybersecurity
- Legal name
- UnderDefense
- Website
- https://underdefense.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- UnderDefense is a US-based private cybersecurity provider delivering AI-powered Managed Detection and Response, SOC-as-a-Service, Managed SIEM, compliance automation, and penetration testing through its MAXI platform to 500+ enterprises and mid-market organizations across five continents.
- Ownership category
- akta.pro rank
UnderDefense Cybersecurity industry classification
Industry- Product category
- Managed Security Services / Cybersecurity
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)
- akta.pro secondary industries
- SOAR & Security Automation (HDADAGAB), Extended Detection & Response (XDR) (HDADAEAB), Vulnerability Management & Penetration Testing Services (BPAEADAD), Cybersecurity Support Operations (SOC Triage, Incident Intake) (BPAAACAF)
Keywords
Where UnderDefense Cybersecurity is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Markets served
UnderDefense Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Detection and Response (MDR): Core 24/7 threat monitoring, detection, and response service. Subscription-based pricing per asset/device/month with tiered plans. Includes human-led threat hunting, AI-powered investigation, and incident response.
- SOC as a Service (SOCaaS): Fully or co-managed SOC services with 24/7 monitoring and threat detection. Pricing starting at $11 per device/month with tiered plans including Standard, Enhanced, and Professional options.
- Managed SIEM Services: SIEM-as-a-Service with rule tuning, alert triage, and log management. Costs from $15 per asset/month or $5,000-$10,000/month based on log volume and platform complexity.
- Compliance Services: Audits, policy development, and compliance consulting for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS. Typically ranges from $70,000-$150,000 depending on scope.
- Penetration Testing Services: Network, application, and cloud penetration testing. Pricing starts around $9,000 per engagement based on scope, asset count, and testing depth.
- MAXI Platform Freemium: Freemium platform access with basic features free including 360-degree security assessment, forever-free certification kits, and AWS cloud security assessment.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Per seat | Monthly | MDR Basic tier with 24/7 monitoring |
| Subscription | Annual | MDR Premium plans with advanced features |
| Per seat | Monthly | SOC as a Service Standard tier |
| Per seat | Monthly | SOC as a Service Enhanced tier |
| Per seat | Monthly | SOC as a Service Professional tier |
| Usage-based | Monthly | Managed SIEM Services |
| Other | Multi-year contract | Compliance Services |
| One time/ perpetual license | Pay-as-you-go | Penetration Testing |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels6 records
UnderDefense Cybersecurity product offering
Product offeringCore offering
UnderDefense provides 24/7 managed cybersecurity services centered on the proprietary UnderDefense MAXI agentic AI SOC and compliance automation platform. Its core offerings include Managed Detection and Response (MDR), SOC-as-a-Service, Managed SIEM, Cloud Security Managed Services, Incident Response, Penetration Testing, Compliance Services (SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS), and Virtual CISO Services—delivered through product-agnostic integrations with 250+ security tools.
Product overview
UnderDefense offers UnderDefense MAXI, a unified AI SOC and compliance automation platform that serves as the central hub for its security operations. The platform integrates multiple modules including MAXI Compliance for automated audit readiness, MAXI MDR/SOC-as-a-Service for 24/7 threat detection and response, MAXI Cloud IR CNAPP for multi-cloud security, MAXI SOAR for workflow automation, and MAXI AI Copilot for natural language security queries. The company delivers managed cybersecurity services as either standalone offerings or fully integrated with the MAXI platform, including Managed Detection and Response (MDR), Managed SOC (SOCaaS), Managed SIEM, Cloud Security Managed Services, Incident Response Management, Penetration Testing Services, Compliance Services, and Virtual CISO Services. The architecture follows a platform-plus-modules model where customers can subscribe to individual services or benefit from integrated capabilities across the entire security operations lifecycle.
Differentiator
Problem solved
Functional benefit
Brands
- UnderDefense MAXI: Agentic AI SOC and compliance automation platform providing 24/7 threat detection, response, and compliance automation services.
Products and services
- UnderDefense MAXI Platform The primary AI SOC and compliance automation platform that unifies security operations, integrating MDR, SIEM management, SOAR, AI-powered investigation, and compliance automation into a single unified interface with 250+ out-of-the-box integrations.
- Managed Detection and Response (MDR) 24/7 managed threat detection, investigation, and incident response service combining AI-powered automation with human security experts, providing coverage across endpoints, networks, cloud, and SaaS environments.
- Managed SOC (SOCaaS) Security Operations Center as a Service providing fully or co-managed SOC capabilities including 24/7 monitoring, threat detection, alert triage, SIEM tuning, and incident escalation support.
- Managed SIEM SIEM-as-a-Service providing log aggregation, correlation rule management, SIEM tuning, and alert noise reduction across SIEM platforms including Splunk, Microsoft Sentinel, QRadar, and Elastic.
- Cloud Security Managed Services Managed cloud security services for AWS, Azure, and GCP providing real-time monitoring, misconfiguration detection, container security, and compliance assessment for cloud environments.
- Incident Response Management Rapid incident response services including ransomware containment, threat eradication, forensic analysis, and recovery support with 15-minute MTTC SLA and 24/7 expert availability.
- Penetration Testing Services Offensive security services including network penetration testing, cloud pen testing, web application testing, DORA TLPT, and ethical hacking to identify vulnerabilities before exploitation.
- Compliance Services Cybersecurity compliance consulting and audit support for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, and other regulatory frameworks with expert guidance and automated evidence collection.
- Virtual CISO Services On-demand security leadership providing strategic guidance, risk management, security program development, and compliance advisory without requiring full-time executive hire.
- Managed EDR Managed endpoint detection and response service integrated with leading EDR platforms (CrowdStrike, SentinelOne, Microsoft Defender, Palo Alto, BlackBerry, Tanium, Carbon Black, CyberArk, Sophos, FireEye, Check Point, Cisco) for unified endpoint threat detection and automated containment.
Quantifiable outcome
- 2-minute alert-to-triage with AI enrichment vs industry hours
- +8 more outcomes
Companies that use UnderDefense Cybersecurity
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles4 records
UnderDefense Cybersecurity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration30 records
AI capability8 records
Feature7 records
UnderDefense Cybersecurity partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered flagship and core.
- SplunkflagshipDeep technical integration with Splunk SIEM platform. UnderDefense provides custom Splunk applications and optimized SIEM correlation rules. Multiple Splunk Boss of the SOC competition rankings demonstrate technical proficiency.
- Microsoft (Defender, Sentinel, Azure, M365)coreIntegration with Microsoft security stack including Defender for Endpoint, Sentinel SIEM, Azure cloud security, and Microsoft 365 security monitoring.
- CrowdStrikecoreIntegration with CrowdStrike Falcon endpoint protection platform for unified threat detection and response.
- SentinelOnecoreIntegration with SentinelOne endpoint detection and response platform.
- Palo Alto NetworkscoreIntegration with Palo Alto Networks security products for network and endpoint security.
- Google (Chronicle, GCP)coreIntegration with Google Chronicle SIEM and Google Cloud Platform security monitoring.
- IBM QRadarcoreIntegration with IBM QRadar SIEM platform for log management and threat detection.
- ElasticcoreIntegration with Elastic SIEM and Elastic Security for threat detection and response.
- OktacoreIntegration with Okta identity management for SaaS security monitoring and identity threat detection.
- ElasticcoreIntegration with Elastic Security for endpoint and SIEM correlation.
- Jira, ServiceNow, Slack, TeamscoreTicketing and communication integrations for incident management and team collaboration during security incidents.
Scale indicators15 records
Recent moves6 records
Expansion highlights6 records
UnderDefense Cybersecurity competitors and assessment
Company assessmentEmerging players
- Huntress: Managed detection and response provider focused on SMB and mid-market, with strong emphasis on endpoint, identity (Microsoft 365), and SIEM triage. Closely matches UnderDefense's SMB-leaning PLG and self-serve GTM motion.
Broad incumbents
- CrowdStrike (Falcon Complete MDR): Endpoint security leader offering Falcon Complete, a fully managed MDR service built on the Falcon platform. A core competitive threat to UnderDefense, bundling MDR with the dominant endpoint vendor customers already deploy.
- Rapid7 (Managed Threat Complete): Public cybersecurity platform offering Managed Threat Complete (MDR) layered on its InsightIDR/InsightConnect SIEM/SOAR products. Competes with UnderDefense in MDR while also offering adjacent vulnerability management.
- Sophos (Sophos MDR): Broad cybersecurity vendor with a managed detection and response service built around its own endpoint and network products. Overlaps with UnderDefense in MDR delivery, particularly for SMB and mid-market customers.
Direct peers
- eSentire: Specialist MDR provider with 24/7 SOC services, threat hunting, and managed XDR across endpoint, network, and cloud. Closely overlaps UnderDefense's core MDR/SOCaaS value proposition and target mid-market/enterprise buyer.
- Expel: Managed detection and response vendor combining transparent SOC operations with MDR, phish testing, and cloud detection. Directly competes with UnderDefense's MDR and Managed SIEM, with similar mid-market and enterprise focus.
- Deepwatch: Managed detection and response and cloud MDR specialist delivering SOC-as-a-Service over Splunk, Sentinel, and other SIEMs. Direct overlap with UnderDefense's Managed SIEM and SOCaaS offerings, with similar cloud-first delivery.
- Arctic Wolf Networks: Pure-play MDR/SOCaaS vendor offering 24/7 managed detection, response, and security operations across endpoint, network, cloud, and identity. Direct competitor to UnderDefense's MDR, SOCaaS, and Managed SIEM offerings for mid-market and enterprise customers.
- ReliaQuest: Enterprise-focused MDR provider using its GreyMatter platform to unify detection, investigation, and response across SIEM, EDR, and cloud. Comparable to UnderDefense's MAXI platform-driven MDR approach for larger enterprises.
- Binary Defense: Managed detection and response and security operations vendor offering 24/7 SOC services, threat hunting, and managed SIEM. Closely comparable to UnderDefense's MDR and Managed SIEM service lines for mid-market customers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
UnderDefense Cybersecurity social profiles
Digital presenceUnderDefense Cybersecurity compliance and trust
Trust signalCompliance5 records
UnderDefense Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
UnderDefense Cybersecurity leadership team
Management profileNumber of profiles
Profiles2 records
UnderDefense Cybersecurity funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
UnderDefense Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about UnderDefense Cybersecurity
What does UnderDefense Cybersecurity do?
UnderDefense provides 24/7 managed cybersecurity services centered on the proprietary UnderDefense MAXI agentic AI SOC and compliance automation platform. Its core offerings include Managed Detection and Response (MDR), SOC-as-a-Service, Managed SIEM, Cloud Security Managed Services, Incident Response, Penetration Testing, Compliance Services (SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS), and Virtual CISO Services—delivered through product-agnostic integrations with 250+ security tools.
Is UnderDefense Cybersecurity a public or private company?
UnderDefense Cybersecurity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was UnderDefense Cybersecurity founded?
UnderDefense Cybersecurity was founded in 2016. It employs 101 to 250 people.
Where is UnderDefense Cybersecurity based?
UnderDefense Cybersecurity is headquartered in New York, United States, in the North America region.
How does UnderDefense Cybersecurity make money?
Six revenue lines are on record. Managed Detection and Response (MDR) is the primary driver. The others are SOC as a Service (SOCaaS), managed SIEM Services, compliance Services, penetration Testing Services and MAXI Platform Freemium.
Who are UnderDefense Cybersecurity's main competitors?
Huntress is listed as an emerging player. Broad incumbents are CrowdStrike (Falcon Complete MDR), Rapid7 (Managed Threat Complete) and Sophos (Sophos MDR). Direct peers are eSentire, Expel, Deepwatch, Arctic Wolf Networks, ReliaQuest and Binary Defense.
Does UnderDefense Cybersecurity have an API?
No public API is recorded for UnderDefense Cybersecurity.
What industry is UnderDefense Cybersecurity in?
UnderDefense Cybersecurity's product category is Managed Security Services / Cybersecurity. Its primary akta.pro industry code is BPAEADAH, Endpoint Security Managed Services (EDR/XDR), with a secondary code of HDADAGAB, SOAR & Security Automation. Its NAICS code is 5415 and its SIC code is 7370.