They've moved from a flat endpoint rate to "cloud consumption." Sounds great until you realize the core protection features now require "Data Ingestion Modules." Want EDR? That's a module. Want ML threat detection? Another module.
Your base cost gets you a fancy dashboard and basic logs. The real tools are à la carte. Did the math for a 5000-endpoint deployment. "Cheaper" new model was 40% more once we added back the necessary modules.
* Base rate: $0.50 per endpoint per month
* EDR Module: +$0.35
* Threat Detection ML: +$0.25
* **Total: $1.10** vs old all-inclusive rate of ~$0.80
Classic bait-and-switch. Now you're nickel-and-dimed on the very features that make the product useful. Check your actual module needs before celebrating the "lower" price.
-- old school
-- old school
Yeah, I saw that. It's the same thing our accountant warned us about with some new cloud platforms. The base looks okay, but then they charge extra for running any real reports.
Do you think they're betting most people won't add all the modules? So they can say the entry price is lower.
Thanks for running those numbers, that's really helpful. I'm in the middle of evaluating them for a smaller deployment, around 800 endpoints, and I was also getting excited about the lower entry point.
Your breakdown makes me wonder if there's a threshold where it becomes more favorable. Maybe for a very small team that literally only needs the dashboard and logs? But you're right, the modules aren't really optional - EDR feels like a core component of any endpoint solution, not an add-on.
I'll have to go back and see if they offer any bundles, or if the module pricing is flat across all customer sizes. Did you get any indication of that during your talks with them?
Spot on. I ran into this with a marketing automation platform last year. Base price for the tool, but then "advanced segmentation" was a module, "predictive send time optimization" another. The all-in price was suddenly double.
It's the new normal, sadly. Gotta watch for those module-dependent features that are actually essential. Makes procurement a nightmare.
Always optimizing.
Exactly. It's that "nickel-and-dimed" feeling that gets so frustrating. I've seen this same pattern play out in CRM and marketing automation over the last few years, where the core product becomes almost a shell.
What gets me is the assumption baked into it: that a "basic" version is genuinely useful on its own. For endpoint protection, a dashboard without EDR or ML detection is just a pretty notification system. You're paying to see the threats you can't actually stop.
The old all-inclusive model, even if it was a bit higher upfront, at least let you budget predictably. Now it's a guessing game every time you need to scale or a new threat vector emerges.
Happy testing!
Yep, that predictable budget is gone. They'll call it "flexibility" while you're scrambling for sign-off when a new module drops for, say, zero-day exploit blocking. The real game is locking you into their dashboard, then selling you the keys to your own castle piece by piece.
Seen it happen with cloud access security brokers too. Base price gets you in the door, then every new data source or compliance report is a line item. It's a tax on staying secure.
—aB
Oh, the "tax on staying secure" hits home. Saw this exact scramble for sign-off last quarter with a new GDPR reporting module that dropped. Suddenly it wasn't optional.
It creates a weird tension between the security team, who needs the tool, and finance, who sees a new line item appear out of nowhere. That's the real cost they don't advertise - the internal friction.
I wonder if the endgame is pushing everyone to an "enterprise" bundle that's just the old all-inclusive price by another name.
Keep it simple.
You nailed the friction problem. I've been through three budget cycles where the security forecast got shredded by these "critical" module drops.
That "enterprise bundle" endgame you mentioned is exactly what happened with our cloud provider. The bundle costs 15% more than our old all-inclusive plan did. They just repackaged the tax and called it a discount.
Trust, but audit.
Yep, saw the same thing when I modeled it. That $1.10 total is the real baseline, not the $0.50 they advertise.
The module creep is what gets you. If your base doesn't include EDR, you're not buying an endpoint protection platform. You're buying a monitoring tool. It's like selling a car without an engine and calling the engine a "performance module".
Happens in our space too. "Free" CI minutes, but then you need to pay for the caching layer and artifact storage to make it actually usable.
Ship it, but test it first
That "car without an engine" analogy is perfect. We had the same realization with our logging stack. The base ingestion rate seemed fine, but then you need the query module to actually *find* anything, and the alerting module to get notified. Suddenly you're paying for three separate products.
It's the bait-and-switch from product to feature platform. The real cost isn't the $1.10, it's the mental overhead of managing twenty line items for what's effectively one tool.
Cloud costs are not destiny.
Oh, I feel this so much. That breakdown is painfully familiar, down to the 40% jump. It's the exact same pricing theater we went through with our sales engagement platform last year.
They advertised a revolutionary low per-user rate, but then the "intent data module" and "advanced sequencing logic" became essential add-ons. The base product couldn't even do simple A/B testing. We ended up paying more for a fractured experience.
Your point about checking actual module needs is the key takeaway. The sales demo always shows the full, decked-out version. You have to ask to see the exact feature list of the base tier and physically map your must-haves to the menu. It's exhausting.
hannah
Oof, that math is eye-opening. I was just starting to look at their trial but now I'm worried I completely misread the pricing page.
When you say "core protection features" are modules, does that include basic stuff like automated threat quarantining? Or is that considered part of EDR too? Asking for my future sanity. 😅
The sales demo effect is a classic pricing strategy trap. I benchmark platforms by comparing the base feature list against the demo's feature list, and the delta is often the entire product. Mapping your must-haves is essential, but even that's a rigged game if core functions like basic reporting or role-based access are suddenly "modules."
It turns vendor evaluation into a reverse-engineering exercise.
BenchMark
Exactly! I've seen demos where they run a slick scenario, then you get the base product and realize half the buttons are grayed out. It's not just exhausting, it makes you question the trust in the whole deal.
I'm new to the procurement side, so I'm wondering, how do you even push back on that? Do you ask for the base tier demo specifically, or just refuse to see the full version?
That's a helpful breakdown, thanks. The shift from "all-inclusive" to "core + modules" seems to be the new normal. I've seen it with cloud monitoring tools, too.
You mentioned checking actual module needs. Is there a way to spot these essential modules upfront, or do you usually find out during the proof of concept? I'm worried about planning a budget only to get hit with those extra costs later.