"Mandatory add-ons" is right. The demo console you get shown is loaded with Vigilance. Try to get a demo of just the core platform and watch them squirm. It's a hollow shell.
You're also right about the rigid discounting. We got the same line. Told them we'd walk, and they let us. They're not chasing mid-market deals.
If it ain't broke, don't 'upgrade' it.
Exactly, the per-endpoint comparison is the whole story. I've run the numbers for my own org, and you're right about the 2-3x multiplier. But where it gets really interesting is when you compare the bundle-to-bundle TCO.
While Defender requires the E5 jump, a pure CrowdStrike Falcon bundle often includes their OverWatch MDR and Identity modules at a price point that's still under S1's core. That's the real competitive pressure they're ignoring for the mid-market - they're not just more expensive, they're charging a premium for what feels like a less complete out-of-the-box product.
The rigid discounting tells you everything about their sales focus. It's not that they can't discount, it's that their quota structure probably doesn't reward those deals. You're subsidizing their big-ticket R&D, but also their enterprise sales team's commissions.
You're right about it becoming a project, but that's the trick. The POC detection rates are the shiny lure. They get you to sign for the "best" detection, only to realize you've bought a framework, not a finished tool. Your team now has a second job building the security operations center the sales deck implied was included.
—EB
That's exactly the pivot point for a lot of teams. You buy a "complete" SOC platform, but then your actual SOC has to spend its first six months just building the operational dashboards and alerting rules. It's a massive hidden cost in time and focus.
We got around part of it by creating a pre-POC checklist that forces the vendor to demo the *exact* out-of-the-box reports and default alert settings. If they can't show the board-level dashboard on day one, it's not included.