We have implemented ActiveWolf due to its more hands-off approach, suitable for our small IT team without dedicated security specialists.

Arctic Wolf Managed Detection and Response (MDR)
Arctic WolfExternal reviews
External reviews are not included in the AWS star rating for the product.
Hands-off approach works well with monthly security assistance for network
What is our primary use case?
What is most valuable?
The solution works well for our team as it offers a hands-off approach, which we need. The pricing is okay and comparable to other solutions. We value the hands-off approach as we don't have our own security team. We have monthly meetings with them, where they help us secure parts of our network, which is valuable to us.
What needs improvement?
The only frustrating aspect is the lack of support for Windows on ARM devices. We cannot fully secure these devices until they release an updated version of their agent software.
For how long have I used the solution?
I've used the solution for just over a year.
What do I think about the stability of the solution?
There is not much downtime, however, they are sometimes a bit slow in responding with more information when an issue is flagged.
How are customer service and support?
They are quite responsive overall. We have monthly meetings where they help us with network security. However, their response can be slow when we ask for more information.
How would you rate customer service and support?
Positive
How was the initial setup?
It took us about three to four weeks to bring it live as we had to ship the sensors to different sites. It probably took a month to be fully up to speed, but that was fine because we needed to onboard it anyway.
What's my experience with pricing, setup cost, and licensing?
The pricing is okay and comparable to other solutions, with competitive pricing obtained for most options. We value the ease of use and hands-off approach.
Which other solutions did I evaluate?
We looked at the Microsoft service and another solution, however, I can't remember the name of the latter.
What other advice do I have?
I rate the overall solution nine out of ten.
Real-time threat detection has improved with comprehensive asset scanning
What is our primary use case?
One of the things it excels at is flagging vulnerabilities. It scans assets, evaluates the vulnerabilities, and assesses risk scores, focusing on high-risk areas.
It helps to maintain compliance within thirty, sixty, and ninety days as well as, informs us when an asset is out of compliance and the number of days is has been out of compliance. We have agents installed that constantly report back to us from all our data centers. For instance, Log4j and the IBM vulnerability are some issues we've were able to quickly mitigate.
What is most valuable?
Their asset scanning features are a game changer. The entire solution, especially their advanced threat protection recently released, are very effective in helping to mitigate corporate risks. The concierge team is excellent. The Arctic Wolf agents, which are constantly performing scans help to produce almost real-time reporting.
Threat detection is remarkable. Security is everyone's responsibility and Arctic Wolf does an excellent job ensuring the company is trained, sending out timely videos about industry happenings. Their educational materials are invaluable. The content they release is timely, and employee engagement is notably high.
What needs improvement?
The threat intelligence feature is expected to be a significant advantage. However, a section for software inventory and real-time comparison with current CVEs would be beneficial.
One can review an inventory of assets being scanned, including a software inventory along with CVE updates based on a company's software subscriptions, would be a game changer.
For how long have I used the solution?
We have been using Arctic Wolf for a couple of years now.
How are customer service and support?
I would give customer service a ten out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was somewhat complex, once you set up your scanners and deploy the agents, there is mostly like additional configuration required. Labeling assets and identifying whether they are in production, test, or development is necessary, along with manual inputs. During onboarding, asset labeling tagging is crucial to avoid unknowns. We collaborated extensively with Arctic Wolf on configurations, many of which are integrated into recent product releases and updates to their dashboard. In the beginning we had ongoing meetings with the concierge team until we moved to a more scheduled cadence.
What was our ROI?
The services provided by Arctic Wolf are comprehensive. Their training materials and videos benefit the organization as a whole. While similar training is available from other companies, Arctic Wolf's offerings are timely and effective. Employee engagement is high, with a 96% viewing and participation rate for their training materials. The company has achieved strong cultural buy-in.
Which other solutions did I evaluate?
We have discussed their use of AI in learning modules; however, it is not yet heavily integrated into their decision-making processes. While AI may exist in the product to some extent, it does not perform the role of a security engineer.
What other advice do I have?
I highly recommend Arctic Wolf as they excel in ensuring the company is well-trained and updated on industry developments.
Overall, I rate them nine out of ten. Their security threat intelligence and timely security bulletins are excellent. They effectively promote a security-conscious culture, raising the bar for security and threat intelligence.
Offers AI features that help improve detection and response capabilities
What is our primary use case?
In my company, we have our own internal MDR as well. I am a salesperson, so I don't use the tool by myself.
I moved from telecom to IT earlier this year. I am very new to the tool, but it sounds great. For our company's clients, the tool increases visibility over the network. Arctic Wolf Managed Detection and Response plugs well into everything. Being able to have that sort of real-time, twenty-four-by-seven help desk that watches over your network and all your devices in case there is some attack or breach that it can contain is helpful.
How has it helped my organization?
Having or hiring someone locally to do all those things that Active Wolf and their team does would cost so much more for businesses. The tool definitely saves money for our company's customers. I think the tool saves time because the customers do not do much work, like doing certain things manually and going through logs.
What is most valuable?
The solution's most valuable feature is the certainty that someone is watching it, and that is the one key thing that I love about the product. Apart from the tool's own local team, somebody is always watching the tool and reducing any risks. The awareness training and all that stuff are good because Arctic Wolf Managed Detection and Response does it all by building such areas.
What needs improvement?
I have heard that the tool doesn't go right to the endpoints. With CrowdStrike, I don't think that it is a bad thing anymore.
For how long have I used the solution?
I have years of experience with Arctic Wolf Managed Detection and Response. As a salesperson, I am meant to sell it.
How are customer service and support?
I think the technical support for the solution is pretty good. I think it is all about setting expectations with your customers. Arctic Wolf is a global company, so you have to make sure that the customer knows that support will take as per whatever is mentioned in the SLA, which can take three days or whatever. I haven't heard any complaints from my customers about the tool's support team, but nobody is perfect. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
What was our ROI?
Considering the number of activities that customers have to indulge in, especially with the increase in attacks in New Zealand, I can say that the tool helps save a time frame of seven days.
What other advice do I have?
Speaking about the product's integration capabilities, I feel that I am probably not experienced enough to talk about it. Arctic Wolf Managed Detection and Response is still quite immature compared to other providers in the market. The tool sort of integrates with a few products, but it doesn't integrate with everything.
The AI-driven tool helps improve detection and response capabilities, but human beings also manage it. You need the best of both worlds because AI can't do everything. One can still get false positives with the tool, so you need a human being. You also need AI to protect yourself against attacks.
I probably haven't had enough experience to give a proper opinion, but with my experience this year, I think it is pretty good for its current market. It plays in both corporate and medium-sized companies and corporate-level businesses. The tool is not meant for an enterprise-sized business since there are other tools like CrowdStrike and Splunk, along with more mature solutions.
I rate the tool an eight out of ten.
Provides visibility into the environment, responds to threats quickly, and the documentation is pretty good
What is our primary use case?
The solution helps monitor our endpoints and network traffic. It alerts us whenever something's going down. It has been pretty helpful.
How has it helped my organization?
The product helps with visibility.
What is most valuable?
The agents that are installed help detect threats. The agents give pretty good visibility into what is happening at the endpoint. The response to threats is pretty quick. Depending on the severity, the team sends an email or gives us a direct call. The weekly and monthly reports through the dashboard are helpful.
What needs improvement?
It will be helpful if the dashboard is more granular. The vendor must allow us to see what they see on their end.
For how long have I used the solution?
I have been using the solution for three months.
What do I think about the stability of the solution?
I rate the tool’s stability a nine out of ten. The product hasn’t gone down since we have had it.
What do I think about the scalability of the solution?
We have around 1000 users.
How are customer service and support?
We have 24/7 support. It’s like an extension of the department. The technical support is pretty helpful. Someone's always there to help us.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is pretty straightforward. The documentation is pretty good. I rate the ease of setup an eight out of ten. It is a SaaS solution. Two network engineers can deploy the product. We have network engineers and analysts on our team. We make sure the agents are not degraded. Most of the maintenance is done by the vendor.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty competitive.
What other advice do I have?
I will recommend the solution to others. It provides more visibility into the environment. If the staff is pretty short-handed, it helps out. Overall, I rate the product a nine out of ten.
An easy-to-implement solution for managed detection and response
What is our primary use case?
We use the tool for managed detection and response.
What is most valuable?
The tool's most valuable feature is its ease of implementation.
What needs improvement?
Arctic Wolf Managed Detection and Response's analysis and remediation parts could be improved. It's not bad, but it needs improvement.
For how long have I used the solution?
I have been working with the product for eight months.
What do I think about the stability of the solution?
I rate Arctic Wolf Managed Detection and Response's stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the tool's scalability a ten out of ten. My company has around 450 users who use it 24/7.
Which solution did I use previously and why did I switch?
We were using a product from a local Danish vendor. We switched to Arctic Wolf Managed Detection and Response for cost and capabilities. It offered more features and better support, including superior threat intelligence feeds.
How was the initial setup?
I rate the tool's deployment an eight out of ten, which took nine weeks to complete with two resources. Operational maintenance is relatively minimal and very easy to manage. However, functional maintenance requires a skilled resource like me. The extent of personnel needed depends on the size of the organization. As the organization is not very large, I can handle it independently in my current role. However, I anticipate needing at least five or six people for maintenance tasks in a larger company, such as my previous role. The resource requirement aligns with the company's size.
What about the implementation team?
We did Arctic Wolf Managed Detection and Response's deployment in-house.
What's my experience with pricing, setup cost, and licensing?
I rate the tool's pricing a nine out of ten.
What other advice do I have?
Before choosing a security solution, it's crucial to conduct thorough due diligence. Consider factors such as the vendor's approach, strategy, and compliance with data protection regulations like GDPR. Assess the vendor's data centers, their capabilities for shifting data around in case of issues, and their approach to DLP (Data Loss Prevention) detection. Evaluate whether the services offered align with your company's strategy and needs.
Review the different agreements provided by the vendor, including Managed Detection and Response, vulnerability management, and incident response features. Check if your existing cyber insurance can be utilized to cover expenses in case of a breach. Consider whether your organization requires services like vulnerability management and incident response, and choose accordingly.
I rate the product a ten out of ten.
Helps eliminate the workload on security teams, but the implementation process could be a little more streamlined
What is our primary use case?
We use the solution for SOC and SIEM.
How has it helped my organization?
The product has helped me eliminate the workload on my security team.
What is most valuable?
The product provides integrations with several different SaaS applications.
What needs improvement?
The implementation process could be a little more streamlined.
For how long have I used the solution?
I have been using the solution for nine months. It is a SaaS-based service.
What do I think about the stability of the solution?
I rate the tool’s stability an eight or nine out of ten. I haven’t had any issues with the platform.
What do I think about the scalability of the solution?
I rate the tool’s scalability an eight or nine out of ten. It is pretty easy to scale it.
How are customer service and support?
The service team is responsive.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment process is not highly complex but could be more streamlined and transparent.
What was our ROI?
I am beginning to see the return on investment because the tool saves me resources. On average, we get a 50% return on investment. We can't completely do away with your SOC team. However, I don't have to hire more people as I scale up. The solution’s service runs 24/7. It definitely takes a load off of me. I do not need a team 24/7.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair. It is not necessarily the most cost-effective, but it is not the worst.
Which other solutions did I evaluate?
We evaluated Red Canary and Rapid7. We chose Arctic Wolf because of its pricing and capabilities.
What other advice do I have?
The industry chooses tools that have EDR. People should strongly consider buying the product. Overall, I rate the tool a seven out of ten.
Particularly valuable for smaller and mid-sized businesses without a dedicated cybersecurity team
What is our primary use case?
For anyone with an IT footprint in today's cybersecurity-aware landscape, considering solutions like Arctic Wolf (MDR is vital. It is not just for giants like banks; it is particularly valuable for smaller and mid-sized businesses without a dedicated cybersecurity team. When your IT environment surpasses about 50 users, that is when the real need for MDR arises. At that point, you start generating substantial security data, and MDR allows you to tap into expert skills to protect your organization effectively.
What is most valuable?
The most valuable aspect of this solution, both for me and my clients, is the managed detection and response component, which is a core feature of the service. However, what sets it apart is the "concierge security team" that provides customers with two dedicated resources for proactive security management. This personalized support, in addition to the 24/7 SOC service, is a significant added benefit.
What needs improvement?
In terms of areas for improvement, Arctic Wolf has been responsive to client feedback. They have addressed issues such as the lack of data exploration tools in the past by implementing solutions that enable clients to better understand the platform's actions. However, to further enhance the service, more integrations with various security tools to improve data ingestion would be beneficial. It is worth noting that I haven't received any negative feedback from clients, so there aren't any specific issues they are unhappy with at the moment.
For how long have I used the solution?
I have been a reseller of Arctic Wolf Managed Detection and Response for over a year.
What do I think about the stability of the solution?
The stability of this solution is robust. It is not a physical product but rather a service, so it doesn't have the potential to go down like a tool or device might. Agents and sensors deployed have failover mechanisms in place to ensure continuous monitoring. 24/7 services are reliable and uninterrupted. In that sense, it is highly stable, given its service-oriented nature.
What do I think about the scalability of the solution?
The scalability of this solution is great. It offers user-based licensing, so if there is an increase in the number of IT users, it can easily scale accordingly. In contrast to other solutions that base pricing on data ingestion, which can be challenging as data grows, user count tends to be more predictable, making this model highly scalable. Arctic Wolf is flexible and works with clients to ensure smooth scaling. Our clients for this solution come from a range of business sizes, primarily focusing on small and medium-sized enterprises. We generally don't cater to large enterprises, but instead, our clients typically fall within the medium-sized category, with user counts ranging from 50 to around 3,000.
How are customer service and support?
Our experience with technical support from Arctic Wolf is mostly handled by the Octopus technical team, who manage support as the reseller. As a result, our role in providing technical support is limited. The concierge security team, a part of the managed detection and response solution, actively engages with clients to offer technical support, identify vulnerabilities, and conduct proactive threat hunting. This means we are less involved in the technical support aspects of the solution. I would rate Arctic Wolf's technical support as a nine out of ten. Their 24/7 availability of highly skilled security engineers who are responsive to phone calls and emails is a significant strength, with room for minor improvements but very effective overall.
How would you rate customer service and support?
Positive
How was the initial setup?
In terms of the initial setup, our involvement is limited as Octopus Deploy handles it directly with the client for compliance and confidentiality reasons. However, the feedback we have received about the setup process has been remarkably positive. It is described as a quick and relatively painless process, typically taking around 30 to 40 days. Even for clients in South Africa, the shipment of sensors and equipment arrives within a month, which speaks to the efficiency of the setup. The choice between cloud or on-premises deployment depends on the client's preference. The solution offers virtual and on-premises sensor deployment options. The setup process is streamlined, with an off-site team collaborating with the client's team. The Security Operations Center is in Germany and works closely with clients for efficient implementation. Clients often install the sensors themselves, and the process is straightforward, making implementation easy.
What's my experience with pricing, setup cost, and licensing?
Arctic Wolf's pricing seems reasonable for the value it offers, and I would rate it at a six out of ten. It is not a low-cost solution, but it provides good value for the investment.
What other advice do I have?
Given the absence of complaints from our customers regarding the solution, I would rate Arctic Wolf MDR very highly, perhaps a ten out of ten. It seems to meet our clients' needs effectively.
Which deployment model are you using for this solution?
Very good support, excellent visibility, and useful security bulletins
What is our primary use case?
We partnered with Arctic Wolf to provide us with 24/7 monitoring of our mixed environment organization.
Arctic Wolf provides coverage for our cloud servers and services, and remote workforce endpoints.
As a relatively small organization with a lean IT staff, we do not have the bandwidth to dedicate ourselves to security 24/7. While our team is security aware, it is not the daily responsibility of any of our team members. We realized we needed a partner that could provide SOC services for our wide-ranging data sources.
How has it helped my organization?
Arctic Wolf's insight into our environment and notification when something needs our review are key. The Security Concierge Team (along with the rest of the AW team) truly are teammates and allow us to be more security conscious without the expense of adding more internal staff.
Our prior security vendor added little to no value to our organization. The extent of the relationship was monthly reports that we emailed and tended to be inaccurate. Arctic Wolf absolutely provides value on a regular basis with useful reports and actionable recommendations.
What is most valuable?
The visibility into our endpoints is huge.
The data collected is provided in a view that is understandable and approachable.
The quarterly review with our account manager and Concierge Security Team provides good information and also provides a nice overview of the Arctic Wolf roadmap.
The Security Bulletins that Arctic Wolf provides when there is a new threat or zero-day vulnerability are extremely helpful. They explain the issue and provide understandable recommendations with actionable steps.
What needs improvement?
While it isn't a regular occurrence, there have been some gaps in response to some support questions. Questions get answered, yet there are times it takes longer than I'm comfortable with. Having worked in growing organizations, I realize this is likely to staff training/onboarding. Ultimately, my issues are addressed and resolved. Regarding additional features, I'd like to see further refinement of the dashboards. We subscribe to additional services, and the look and feel vary amongst the solutions.
For how long have I used the solution?
I've used the solution 3+ years.
What do I think about the stability of the solution?
We have had very few outages or issues related to stability in the time we've been a customer.
What do I think about the scalability of the solution?
Our footprint is relatively small, however, it appears to scale well.
How are customer service and support?
Technical support is very good trending towards excellent.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We switched from Alert Logic. We didn't find value in the service provided.
How was the initial setup?
Onboarding was straightforward, and the support team was able to address any questions or issues with had during the process in a timely fashion.
What about the implementation team?
We handled the initial setup in-house.
What was our ROI?
Our ROI is good and certainly better than with our prior vendor.
What's my experience with pricing, setup cost, and licensing?
Costs are relatively transparent. Setup/onboarding is project-driven and the team responsible for that is good. The account management/sales team understands the licensing model well and provides good recommendations for your needs.
Which other solutions did I evaluate?
We evaluated Alert Logic's new offering and decided against it based on the cost and prior experience.