WatchGuard ThreatSync+ NDR provides hybrid network defense security from the cloud. ThreatSync+ NDR uncovers risks and threats across network, cloud, user, VPN, and IoT threat surfaces. By combining AI, cross-event correlation, threat intelligence, and harmonized policy controls, ThreatSync+ NDR delivers a concise list of emerging risks and threats that pose the most significant risk and integrated remediation to mitigate them.
ThreatSync+ NDR has policy controls and reporting that covers NIST800-53, NIST 800-171, CMMC, ISO-27001, GDPR, DORA, NIS 2 and UK Cyber Essentials as part of our defense service. Security controls, dashboards, and reports enable continuous compliance with regulations and supply chain standards.
ThreatSync+ NDR is a 100% AWS cloud-native platform that requires no hardware, deploys in under an hour, and reduces the total cost of ownership by upwards of 66% over traditional hardware-based NDR tools and SIEMS. Affordable, highly effective, and easy to operate, ThreatSync+ NDR is explicitly designed for small and medium-sized organizations and enterprises with 30,000 employees or less.
Highlights
Threat detection and response for network, cloud, IoT, and User threat surfaces with enterprise AI-driven accuracy in detecting attacks
operating inside your network, including:
Ransomware
Supply Chain Attacks
Vulnerabilities
VPN Threats
Command & Control (C2)
Man-in-the-Middle
Unauthorized Web & DNS Activities
Masqueraders (Tunneling)
Credential Compromise
Rogue Behaviors
Insider Threats
Lateral Movement
Data Exfiltration
Integrated and automated compliance dashboards and reporting:
Out-of-the-box NIST and ISO policy-based, AI-powered
control frameworks support continuous compliance and
compliance reporting. Compliance posture is improved
through control effectiveness reports
and take practical remediation actions
with improvement guidance. Cost of compliance is reduced by
automating highly manual processes,
reducing workloads on IT teams.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Pricing splits into two products, each billed per user license. WatchGuard ThreatSync+ NDR detects and responds to network threats. WatchGuard Compliance Reporting automates control reporting for regulatory frameworks. You pick a term of either 1 year or 3 years. Within each term, price scales by license volume bands. NDR offers four bands: 1 to 50, 51 to 100, 101 to 250, and 251 or more. Compliance Reporting offers three bands: 1 to 50, 51 to 100, and 101 to 250. You choose the product, term, and band that fit your user count.
Top-of-mind questions for buyers
What counts as one license or user for billing?
Each license corresponds to one user in your organization. You count your total user base and pick the volume band that covers it. The same per-user model applies to both the NDR product and Compliance Reporting.
If my user count grows past my band, does the higher band apply to all users or just the extra ones?
Bands define which contract you buy based on total user count. Moving from one band to a higher one applies that band's rate to your whole license set, not only the added users. You select the band that fits your current user total.
How do the ThreatSync+ NDR and Compliance Reporting contracts combine on my bill?
The two products are billed independently. NDR detects and responds to network threats. Compliance Reporting automates control reporting for regulatory frameworks. You can buy each separately, or both. Each carries its own term and volume band, so charges appear as distinct line items.
www.watchguard.com+2
Helpful?
Vendor refund policy
For sales returns on licenses of ThreatSync+ NDR, please contact your WatchGuard Channel Partner. If you have an issue requiring troubleshooting, please feel free to open a support case via the WatchGuard Support Portal.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Online support is recommended for non-critical issues and lets you provide detailed updates on the status of your issue, as well as an option to upload troubleshooting documents to help resolve your case more quickly. Phone support is recommended for critical network failure situations, and for anyone who does not have access to the online support submittal page. Please have your WatchGuard serial number readily available when you call for support. +1 (877) 232-3531 OR support@watchguard.com.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
WatchGuard Firebox Cloud brings the protection of WatchGuard's leading Firebox UTM appliances to public cloud environments. Firebox Cloud enables organizations to extend their security perimeter to protect critical assets in AWS and can be deployed to protect a VPC from cyber-attack.
WatchGuard Firebox Cloud brings the protection of WatchGuard's leading Firebox UTM appliances to public cloud environments. Firebox Cloud enables organizations to extend their security perimeter to protect critical assets in AWS and can be deployed to protect a VPC from cyber-attack.
WatchGuard Firebox Cloud brings the protection of WatchGuard's leading Firebox UTM appliances to public cloud environments. Firebox Cloud enables organizations to extend their security perimeter to protect critical assets in AWS and can be deployed to protect a VPC from cyber-attack.
WatchGuard FireCloud Internet Access delivers Cloud-native security for the hybrid workforce. As a core component of our Unified Security Platform architecture, it embodies our security, performance, and simplicity tenets. FireCloud provides robust protection against web-based threats, simplifies management, and optimizes connectivity for users everywhere, ensuring secure and productive access to their needed resources.
WatchGuard Endpoint Security Cloud-native solutions protect businesses of any kind from present and future cyber-attacks. They combine next-generation antivirus protection, endpoint detection and response (EDR), along with enhanced features for incident investigation and response. All this through a single Cloud-based management console and using a single lightweight agent.
Has improved threat detection and reduced manual workload through real-time cloud insights
Reviewed on Oct 23, 2025
Review provided by PeerSpot
What is our primary use case?
We use ThreatSync+ NDR for both network monitoring and detection and response.
What is most valuable?
ThreatSync+ NDR's most valuable features include its easy setup process, and WatchGuard was available at all times to assist with setup if we encountered any issues.
ThreatSync+ NDR's real-time cloud threat detection in our Azure workloads has been very effective. While we haven't encountered any major threats, it has detected and immediately stopped smaller security concerns.
Implementing ThreatSync+ NDR has influenced our business significantly as it provides enhanced security and saves several hours daily by eliminating manual log reviews.
What needs improvement?
After using ThreatSync+ NDR for about a year, areas for improvement include the ability to pull logs from other vendors using an API.
You can use Netflow which gets around this in some cases.
For how long have I used the solution?
I've been using ThreatSync+ NDR as part of a combined trial and purchase for approximately a year.
What do I think about the stability of the solution?
The stability deserves a perfect rating of 10, as we have experienced no issues thus far.
What do I think about the scalability of the solution?
The scalability merits a rating of 10.
How are customer service and support?
Our experience with our partner has been positive. We primarily used the partner to purchase the product, as most support comes directly from WatchGuard.
The vendor support deserves a rating of nine.
Which solution did I use previously and why did I switch?
Prior to ThreatSync+ NDR, we relied entirely on manual work for our security operations.
How was the initial setup?
ThreatSync+ NDR implementation was straightforward, becoming operational within hours. The initial information collection and additional setup required only a few more hours.
The easy setup process and vendor support are the most appreciated aspects.
The solution is simple to maintain due to its cloud-based nature, with most maintenance handled by the vendor.
What was our ROI?
The return on investment is approximately 40% because we monitor more than just the UK office, given our global presence.
Which other solutions did I evaluate?
WatchGuard suits our needs better because we have WatchGuard firewalls. The initial integration was seamless compared to other vendors we considered, such as CrowdStrike, which cannot properly support our firewall logs.
What other advice do I have?
ThreatSync+ NDR has helped identify potential security gaps in my network, and we are currently working on resolving them.
The impact on incident response time varies. During daytime operations, it reacts instantly with a notification delay of 10 to 20 minutes, while nighttime notifications can have up to eight hours delay.
ThreatSync+ NDR has enhanced our ability to proactively manage network risks by enabling us to implement extra measures at a lower level based on its findings.
The compliance reporting tools are comprehensive and meet our requirements. Though we haven't conducted official compliance reporting yet, we anticipate it will save approximately one day of work in report compilation.
Regarding pricing, WatchGuard rates a nine out of ten.
We maintain 1,001 licenses for ThreatSync+ NDR, serving approximately 1,000 users, with about 300 local users in the UK.
ThreatSync+ NDR's effectiveness in identifying weaknesses before exploitation is excellent and very quick.
I recommend ThreatSync+ NDR to other users based on its rapid deployment and immediate value delivery.