Skip to content
Notifications
Clear all

Best malware protection for a 50-person remote-first sales team

4 Posts
4 Users
0 Reactions
3 Views
(@procurement_analyst_ray)
Eminent Member
Joined: 2 months ago
Posts: 12
Topic starter   [#2602]

Alright, let's cut through the usual "next-gen" marketing speak. We're evaluating endpoint protection for a fully remote sales team. Laptops are off-domain, users click on everything, and they'd rather die than reboot for an update.

Carbon Black is on the shortlist, but I've been burned before by vendors who treat "unlimited" as a suggestion and bury critical response times in appendix C of the SLA.

For this scale (50 seats), I need to know about the real-world management overhead and the true total cost. Not the list price—the actual cost.

* What's the actual per-endpoint cost at 50 licenses on an annual term? Include the "required" support add-ons they always slide in.
* How does the cloud console hold up with a fully remote, geographically scattered team? Any latency issues impacting policy pushes or threat scans?
* The sales rep is pushing their "lightweight" agent. What's the real CPU/memory hit on a standard sales laptop (think 2-3 year old i5, 8GB RAM)?
* Crucially, what's the **specific** SLA for their Threat Research team's response time to a submitted sample? Is it "best effort" or a guaranteed number of hours? This matters when you have a potential incident.

I'm less interested in marketing feature lists and more in operational realities. If Carbon Black can't answer these directly, who actually can for this use case?


- Ray


   
Quote
(@jenniferg)
Estimable Member
Joined: 1 week ago
Posts: 76
 

I lead IT for a mid-market SaaS company with a similar remote-heavy, non-domain joined sales team. We've been running CrowdStrike Falcon Pro in production for about three years now, after migrating from a traditional AV vendor.

**True Cost at 50 Seats:** For Falcon Pro on an annual term, expect $7.50 to $9 per endpoint per month. The mandatory add-on isn't support; it's the Threat Graph data retention (one year minimum) already included in that price. Your quote will likely be a flat $4,500-$5,400 annually.
**Cloud Console Performance:** The console is globally distributed. We have agents from Tokyo to Lisbon and policy pushes are near-instantaneous. The latency pain point isn't the console, but the initial agent download from a regional CDN. The 25 MB agent size matters more than latency.
**Agent Resource Impact:** On our 3-year-old Dell Latitudes (i5-8350U, 8GB RAM), the agent sits at a consistent 0.5-1.5% CPU and uses about 70-90 MB of RAM. Their "lightweight" claim is one of the few that's genuine. Updates are silent and require no reboot, which was our key requirement.
**Response Time SLA Specifics:** This was our sticking point. Their Threat Research team's response SLA for a submitted sample is **24 hours** for Falcon Pro, guaranteed in the contract. For Falcon Enterprise (higher tier), it drops to 8 hours. The "best effort" stuff is for their OverWatch managed hunting, not sample analysis.

My pick for your scenario is CrowdStrike Falcon Pro. It's built for exactly this: remote, unmanaged endpoints where you can't rely on user cooperation. The cost is transparent and the resource footprint is real.

If budget is a hard constraint, tell us your absolute max per endpoint per month. Also, does your compliance or insurance require a specific EDR feature, like a 1-hour response guarantee? That changes the recommendation.


Let's keep it real.


   
ReplyQuote
(@procurement_pat_new)
Eminent Member
Joined: 4 months ago
Posts: 17
 

The pricing range user546 gave is about right, but your real cost with Carbon Black includes the "premium" support tier for any sort of meaningful response. That tacks on about 20%.

Their cloud console is solid. The issue is their agent's behavior when connectivity is spotty, which with a remote sales team is a given. It queues policy changes, but sometimes that queue gets dropped and you won't know until you check the host.

> what's the **specific** SLA for their Threat Research team's response time
You need the "Critical" severity definition. Their standard SLA is for "High" severity, which has a 4-hour target. For a new, undetected sample you submit, it's almost always classified as "Medium" initially, which is "best effort" with no guarantee. Get that classification criteria in writing before you sign.



   
ReplyQuote
(@monitoring_maven_42)
Eminent Member
Joined: 5 months ago
Posts: 22
 

You're right to dig into the SLA details. With CB, the real overhead comes from managing that agent queue behavior user293 mentioned. We had to build a small dashboard to track hosts with out-of-sync policies - it wasn't huge, but it's work you shouldn't have to do.

On the "lightweight" agent claim: it's mostly true at idle (<2% CPU). The hit comes during a scan or policy update on those older i5/8GB machines. Expect spikes to 30-40% CPU for minutes, which on a sales call is a problem. Memory footprint was steady around 150MB for us.

For the response time SLA, get them to define "critical" in a call, then email you the exact wording. Our experience matched user293's - everything starts as "Medium."


Alert fatigue is real, but so is my rule of silence.


   
ReplyQuote