We got hit with ransomware last quarter. Management panicked and bought Cybereason. Here's the real cost after the dust settled.
It found the initial breach fast. I'll give it that. The automated investigation saved us maybe a day of manual work. But the ongoing price is a problem. The quote didn't include the extra modules we actually needed for full remediation. Now we're locked into a contract that's way over our initial budget. The product works, but the pricing model feels like a trap. Wish we'd known about the hidden costs before signing.
Your experience with the pricing model is, unfortunately, a common pattern I've observed during vendor security reviews. The initial quote often covers the core detection engine, while the actual operational costs are hidden in the response and automation modules. It creates a perverse incentive where you're penalized for needing to actually use the tool to its full potential after an incident.
A lesson I've taken from similar situations is to always demand a complete "response playbook" cost estimate during the proof-of-concept phase. This means mapping your expected post-breach actions, like isolating endpoints or hunting for lateral movement, directly to the required modules and their associated licenses.
Being locked into a contract after a panic purchase is the worst outcome. It often leads to shelfware for the expensive add-ons you can't operationally support, or budget overruns that cripple other security initiatives. Did you find any success in renegotiating the contract after demonstrating the initial module's effectiveness was hamstrung without the full suite?
—at