Netsurion
Netsurion is a Fort Lauderdale-based managed cybersecurity company delivering MDR, 24x7 SOC-as-a-Service, and Open XDR platform services to mid-market, SMB, and MSP customers in regulated verticals, operating as a subsidiary of Lumifi.
- Company typePrivate
- Founded1989
- HeadquartersFort Lauderdale, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Netsurion does
Netsurion is a US-based managed cybersecurity company headquartered in Fort Lauderdale, Florida, delivering managed detection and response (MDR), 24x7 SOC-as-a-Service, and an Open XDR platform to mid-market organizations, SMBs, MSPs, and regulated verticals including banking and financial services, healthcare, and retail and hospitality. The company operates as a wholly-owned subsidiary of Lumifi following an acquisition announced on the corporate website as 'Netsurion: Now Part of Lumifi!' and continues to operate under the Netsurion brand. Revenue is generated primarily through recurring subscription contracts on a pay-as-you-grow pricing model, distributed channel-first through MSPs and resellers, with direct enterprise field sales and inside sales motions complementing the partner channel. With 251-500 employees and a corporate lineage dating to 1989, Netsurion is a mature MSSP with a substantial install base and an industry tenure of nearly two decades.
The technical core is the Open XDR (formerly EventTracker) platform, a vendor-agnostic, cloud-native security platform that ingests, normalizes, and correlates telemetry from nearly 300 data source integrations spanning endpoints, servers, networks, cloud, and SaaS applications. The platform is built on a SIEM foundation augmented by User and Entity Behavior Analytics (UEBA) and MITRE ATT&CK-aligned threat detections, with machine learning applied to behavioral baselining and anomaly detection. Layered around the platform is a managed services suite covering threat hunting, incident response, managed endpoint protection (integrating CrowdStrike, SentinelOne, Carbon Black, Microsoft Defender, and Deep Instinct), vulnerability management, threat intelligence, and application control, delivered as co-managed or fully managed engagements. The platform holds SOC 2 Type 2 certification and is positioned against more than a dozen compliance frameworks including HIPAA, PCI DSS, ISO 27001, NIST 800-53/171/CSF, FFIEC, NERC CIP, NYDFS 23 NYCRR 500, SOX, and GDPR. Recognized as a Major Player in the IDC MarketScape for MDR in 2023 and the recipient of consecutive Global Infosec Awards and Cybersecurity Excellence Awards in 2022 and 2023, Netsurion positions itself as a comprehensive platform-plus-managed-services alternative for organizations that need enterprise-grade security operations without building an in-house SOC.
Netsurion firmographics
Firmographics- Name
- Netsurion
- Legal name
- Netsurion
- Website
- https://netsurion.com
- Company type
- Private
- Founded year
- 1989
- Operating status
- Acquired
- Headcount range
- 251–500 employees
- Short description
- Netsurion is a Fort Lauderdale-based managed cybersecurity company delivering MDR, 24x7 SOC-as-a-Service, and Open XDR platform services to mid-market, SMB, and MSP customers in regulated verticals, operating as a subsidiary of Lumifi.
- Ownership category
- akta.pro rank
Netsurion industry classification
Industry- Product category
- Managed Cybersecurity Services (XDR / MDR)
- NAICS
- Computer Systems Design and Related Services (5415), Computer Facilities Management Services (541513), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
Keywords
Where Netsurion is headquartered
LocationHeadquarters
- HQ city
- Fort Lauderdale
- HQ country
- United States
- HQ region
- North America
Markets served
Netsurion business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Detection and Response (MDR) Services: Subscription-based managed security services providing 24x7 SOC monitoring, threat detection, and incident response. Delivered through MSP partners or directly to enterprise customers. Annual or multi-year contract terms with 'pay-as-you-grow' pricing model.
- EventTracker Platform Subscription: SIEM and XDR platform licensing as part of managed services bundle or standalone subscription. Includes continuous monitoring, threat intelligence, and automation capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Pay-as-you-grow subscription pricing |
Go-to-market motion4 records
Distribution channels3 records
Marketing channels6 records
Netsurion product offering
Product offeringCore offering
Netsurion delivers managed cybersecurity services built around its Open XDR platform, which ingests and correlates telemetry from nearly 300 data sources using SIEM, UEBA, and MITRE ATT&CK mapping. Layered on top of the platform are 24x7 SOC-as-a-Service operations providing Managed Detection and Response (MDR), Threat Hunting, Incident Response, Managed Endpoint Protection, and Vulnerability Management delivered as co-managed or fully managed services.
Product overview
Netsurion is a managed cybersecurity company offering a unified platform-plus-managed-services architecture centered on its Open XDR (Extended Detection & Response) platform. The core Open XDR platform provides the technology foundation — ingesting, normalizing, and correlating telemetry from hundreds of data sources using SIEM, UEBA, and MITRE ATT&CK integration. Around this platform, Netsurion layers a suite of managed services including Managed Detection and Response (MDR), a 24×7 Security Operations Center (SOC-as-a-Service), Threat Hunting, Incident Response, Managed Endpoint Protection, Vulnerability Management, Managed SIEM, UEBA, Threat Intelligence, and Application Control — delivered as co-managed or fully managed services. The company also provides a library of nearly 300 data source integrations supporting endpoints, networks, servers, cloud, and SaaS environments.
Differentiator
Problem solved
Functional benefit
Brands
- Open XDR Platform: Open Extended Detection and Response platform that unifies security telemetry across endpoints, networks, servers, cloud, and SaaS applications.
Products and services
- Open XDR Platform Vendor-agnostic, cloud-native Open XDR platform that ingests, normalizes, and correlates telemetry from hundreds of data sources and thousands of threat detections across endpoints, servers, networks, cloud, and SaaS applications. Built on a SIEM foundation with UEBA and MITRE ATT&CK mapping for mid-market organizations, MSPs, and regulated enterprises.
- Managed Detection and Response (MDR) Managed Detection and Response service combining Netsurion's Open XDR platform with 24x7 SOC monitoring, threat hunting, and incident response for continuous cybersecurity defense. Delivered as co-managed or fully managed service covering the full attack lifecycle from predict/prevent to detect/respond, for mid-market and enterprise customers.
- Security Operations Center (SOC) / SOC-as-a-Service 24x7 Security Operations Center providing around-the-clock security monitoring, threat detection, incident response support, vulnerability management, SIEM and XDR administration, proactive threat hunting, guided remediation, and custom reporting. Acts as an extension of the customer's team for mid-market and enterprise organizations.
- Threat Hunting Proactive threat hunting service led by human expert Threat Hunters who combine automation and MITRE ATT&CK framework alignment to identify advanced persistent threats and real-world attacker TTPs. Uses a five-stage Threat Hunting Loop: Hypothesis, Analysis, Deep Dive, Document, and Convert to automated response.
- Incident Response (IR) Incident response service combining automated response via the Open XDR platform with guided remediation by the 24x7 SOC. Includes automated triage (terminating unknown processes, monitoring malware propagation, suspending violating accounts), guided remediation with risk scoring, and an IR Playbook framework.
- Managed Endpoint Protection Managed endpoint security combining EDR platform integration (CrowdStrike, SentinelOne, Carbon Black, Microsoft Defender), built-in Application Control with deep learning AI (Deep Instinct), and 24x7 SOC human inspection of endpoint alerts. Protects endpoints from ransomware and sophisticated attacks.
- Vulnerability Management Managed vulnerability management service providing continuous vulnerability scanning, risk scoring, patch prioritization, asset discovery, configuration assessment, and remediation recommendations. Augments the customer's IT team by offloading repetitive scanning and triage tasks.
- Managed SIEM Managed Security Information & Event Management service built on Netsurion's Open XDR platform. Includes log aggregation, security analytics, threat detection, and compliance reporting for PCI DSS, HIPAA, ISO 27001, NIST 800-171, and other frameworks. Powered by the SOC for continuous monitoring and tuning.
- User & Entity Behavior Analytics (UEBA) Machine Learning-driven behavior analytics that establishes baselines for user and entity behavior, detects anomalous activity (unusual access times, locations, system access patterns), identifies insider threats and lateral movement, and triggers automated response. Embedded within the SIEM platform.
- Threat Intelligence (Netsurion Threat Center) Netsurion's proprietary threat intelligence platform that aggregates over 30 open-source intelligence (OSINT) feeds, community contributions, and internal SOC analyst insights. Uses STIX/TAXII framework for automated threat detection, analysis, and response. Correlates IoCs across customer environments for faster identification of Indicators of Attack.
- Application Control Built-in application control capability within the Open XDR platform that provides allow/block controls for applications on endpoints, reducing false positives and providing post-breach visibility and forensic data. Includes a lightweight endpoint agent, central server, and web-based management console.
- Data Source Integrations Library Continuously growing library of nearly 300 data source integrations covering endpoints, networks, servers, cloud, SaaS applications, vulnerability scanners, firewalls, identity systems, and more. Enables the Open XDR platform to ingest, normalize, and correlate telemetry from thousands of data sources.
Quantifiable outcome
- Thousands of threat detections available for comprehensive threat coverage
- +1 more outcomes
Companies that use Netsurion
Customer profileNamed customers2 records
Segments6 records
Ideal customer profiles5 records
Netsurion technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration15 records
AI capability5 records
Feature3 records
Netsurion partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Deep InstinctcoreDeep Instinct is an endpoint protection partner for Netsurion. The partnership provides customers with advanced endpoint threat prevention capabilities integrated into Netsurion's managed detection and response services. Deep Instinct's ML-based endpoint protection complements Netsurion's SOC services and threat detection platform.
Scale indicators1 record
Recent moves6 records
Expansion highlights6 records
Netsurion competitors and assessment
Company assessmentEmerging players
- Huntress: Huntress delivers managed detection and response with a strong channel focus on MSPs serving SMBs, representing an emerging threat in Netsurion's core MSP-driven distribution channel.
Direct peers
- Red Canary: Red Canary provides managed detection and response built on an EDR-agnostic platform, directly comparable to Netsurion's Open XDR architecture and 24x7 SOC services.
- Expel: Expel delivers MDR and security operations as a service with a transparent, vendor-agnostic platform, offering the same mid-market co-managed model that Netsurion targets.
- Alert Logic: Alert Logic provides managed detection and response with SIEM/XDR-based coverage for hybrid environments, overlapping directly with Netsurion's Open XDR platform and managed SOC services.
- Arctic Wolf: Arctic Wolf is a managed detection and response provider delivering 24x7 SOC services through a channel of MSPs and resellers, directly competing with Netsurion for mid-market and SMB security operations customers.
- Proficio: Proficio is a managed security services provider focused on MDR and SOC-as-a-Service for mid-market and regulated customers, with a comparable service-led go-to-market to Netsurion.
- eSentire: eSentire is a pure-play MDR services vendor offering 24x7 threat hunting, investigation, and response with a multi-signal XDR platform, directly competing with Netsurion's managed SOC and XDR bundled offering.
Broad incumbents
- Secureworks: Secureworks is an established MSSP offering managed detection and response and XDR across Taegis and traditional SOC services, competing with Netsurion across both mid-market and enterprise segments.
- CrowdStrike (Falcon Complete MDR): CrowdStrike offers Falcon Complete as a fully managed MDR built on its own Falcon EDR platform, representing an incumbent EDR vendor who competes with Netsurion's vendor-agnostic XDR approach.
- Sophos Managed Detection and Response: Sophos bundles MDR with its broad endpoint and network security portfolio, competing with Netsurion as an incumbent that can offer managed services alongside its larger product suite.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks4 records
Key highlights6 records
Customer concentration
Netsurion social profiles
Digital presenceNetsurion compliance and trust
Trust signalCompliance12 records
Netsurion financial estimates
Financial estimateRevenue estimate
Valuation estimate
Netsurion leadership team
Management profileNumber of profiles
Profiles11 records
Netsurion funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Netsurion M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Netsurion
What does Netsurion do?
Netsurion delivers managed cybersecurity services built around its Open XDR platform, which ingests and correlates telemetry from nearly 300 data sources using SIEM, UEBA, and MITRE ATT&CK mapping. Layered on top of the platform are 24x7 SOC-as-a-Service operations providing Managed Detection and Response (MDR), Threat Hunting, Incident Response, Managed Endpoint Protection, and Vulnerability Management delivered as co-managed or fully managed services.
Is Netsurion a public or private company?
Netsurion is a private company. It is classified as corporate owned and is currently acquired.
When was Netsurion founded?
Netsurion was founded in 1989. It employs 251 to 500 people.
Where is Netsurion based?
Netsurion is headquartered in Fort Lauderdale, United States, in the North America region.
How does Netsurion make money?
Two revenue lines are on record. Managed Detection and Response (MDR) Services are the primary driver. The others are eventTracker Platform Subscription.
Who are Netsurion's main competitors?
Huntress is listed as an emerging player. Direct peers are Red Canary, Expel, Alert Logic, Arctic Wolf, Proficio and eSentire. Broad incumbents are Secureworks, CrowdStrike (Falcon Complete MDR) and Sophos Managed Detection and Response.
Does Netsurion have an API?
No public API is recorded for Netsurion.
What industry is Netsurion in?
Netsurion's product category is Managed Cybersecurity Services (XDR / MDR). Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services. Its NAICS code is 5415 and its SIC code is 7370.