Most businesses buy security tools in the wrong order. They add antivirus, then a backup, then a phishing filter, and only after an incident do they discover the gaps: no 24/7 response, no immutable copy of Microsoft 365, no DNS filtering for the laptops that never come back to the office. This free tool asks eight questions about your company size, endpoints, servers, locations and what you are looking for, then recommends a concrete stack (EDR, MDR, email security, DNS filtering, mobile security, cloud backup, SIEM, identity) from the vendors we provision and manage, with an indicative monthly budget. You can request a formal quotation at the end.
Skip the vendor sales cycle
ITSecOps partners with every industry-standard vendor. Instead of demos and discovery calls with each of them, get a cost-optimised, customised stack at partner pricing directly from our consultants. Use the tool below, or compare vendor prices side by side.
Tell us about your environment
What are you looking for?
Pick everything that applies. Not sure? Choose “Recommend for me” and we will derive it from your profile.
Budget posture and constraints
Your stack is ready. What next?
Both take one click: we already have your details.
Vendors we provision and manage
ITSecOps.cloud partners with every industry-standard security vendor below, so the recommendation is never limited to one product. Because we buy at partner pricing, you get the same licences cheaper than buying direct, and we deploy, tune and monitor them under one monthly price.
How the recommendation logic works
The tool does not sell you everything. It ranks controls by how often they stop real incidents in companies of your size, then fills gaps in this order:
- Endpoint detection first. Every profile gets EDR. If you have 50 or more endpoints, any regulated data, a cyber insurance requirement, or nobody watching alerts after 17:00, EDR becomes MDR (24/7 human-led response) because an unattended alert at 02:00 is how most ransomware cases start.
- Identity second. Phishing-resistant MFA and conditional access on Microsoft 365 or Google Workspace, because credential theft precedes most intrusions. The August 2026 Entra ID flaw is the reminder that identity is now the perimeter.
- Email and DNS third. The two delivery channels for almost every attack. Native Microsoft filtering is kept where it is good enough, and a dedicated layer (Proofpoint, Check Point Harmony Email, Mimecast) is added where the profile justifies it.
- Backups that survive the attacker. Immutable, off-tenant copies of Microsoft 365 or Google Workspace, plus server and endpoint backup with tested restores. Microsoft does not back up your tenant for you.
- Visibility and people. SIEM or a 24/7 SOC once you pass 100 endpoints or fall under NIS2, CMMC or HIPAA, and awareness training with phishing simulation once you pass 20 users.
Frequently asked questions
What is the difference between EDR and MDR?
EDR is software on each endpoint that detects and can contain suspicious behaviour. MDR is EDR plus a 24/7 team that investigates the alerts, hunts for threats and responds for you. Most SMBs under 50 endpoints can start with EDR if someone internal watches alerts; everyone else should buy MDR.
Do I still need antivirus if I have EDR?
No. Modern EDR products (Sophos Intercept X, Microsoft Defender for Business, SentinelOne, CrowdStrike, Bitdefender GravityZone) include next-generation antivirus. Running a separate legacy antivirus alongside EDR causes conflicts and slows machines.
Does Microsoft 365 include backup?
Microsoft keeps deleted items for a limited retention window, but it is not a backup and Microsoft’s own shared responsibility model says so. A third-party backup (Dropsuite, Acronis, Veeam, Datto SaaS Protection) gives you immutable, point-in-time restores of mailboxes, OneDrive, SharePoint and Teams.
Is DNS filtering the same as web protection?
They overlap. DNS filtering blocks connections to malicious or unwanted domains before a page loads, on any device and network. Web protection inside the endpoint agent inspects the traffic and downloads themselves. Most stacks use both: DNS filtering (Cisco Umbrella, DNSFilter, Cloudflare Gateway) for roaming laptops and the endpoint agent for content inspection.
How accurate is the indicative price?
The ranges are typical list prices per user, endpoint or server per month for the products shown. Your quotation will be lower for bundles and multi-year terms and will include our onboarding and monitoring. We send it within one business day.
Can you supply the licences without managing them?
Yes. Choose “We manage it” in step 3 and we quote licences plus a fixed onboarding fee. Most clients move to the fully managed option once they see the alert volume.
Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?
Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.
Bestill en konsultasjon