
Overview
Deepwatch Managed Security Services
Sold by: Deepwatch Deepwatch operates as an extension of your cybersecurity team, providing comprehensive security management, 24x7x365 monitoring, and precise threat response. Deepwatch experts understand AWS security, allowing you to utilize existing security tools to improve visibility across your attack surface, and help organizations become more cyber resilient.
Highlights Human-led extension to customer security teams: high-touch squad delivery model that embeds resources within the customer organization Curated industry-leading SOC technologies: achieving rapid time-to-value around AWS, Splunk, and other foundational SOC tools with the Deepwatch Security Center Proactively drive SecOps program maturity: the Deepwatch proprietary Security Index includes quantitative analysis and industry benchmarking to drive ongoing security posture improvements
Product Overview Deepwatch partners with your team to deliver the cyber resilience your organization needs in todays global threat environment. Our dedicated team of security experts is on watch 24/7/365, and our technology provides the visibility and precision response required to overcome todays growing threats. Deepwatch builds and secures AWS environments and delivers unrivaled human-led security expertise, unparalleled visibility across your attack surface, precision response to threats, and the best return on security investments.
Benefits of Deepwatch include:
- More value from existing tools including AWS
- Access to Deepwatch Experts with real-time collaboration 24/7/365
- Deepwatch Platform of technology, people, and processes to improve cyber resilience
- Proprietary Security Index for managing security program growth
- Proactive Threat Hunting
- Precision response to threats
- Improved security posture
Deepwatch offerings include: Managed Detection & Response (MDR) Managed Endpoint Detection & Response (MEDR) Managed Vulnerability Management (VM) Managed Firewall (FW)
For more information and/or custom scoping and quote via Private Offer, reach out to Deepwatch at sales@deepwatch.com .
Highlights
- Human-led extension to customer security teams: high-touch squad delivery model that embeds resources within the customer organization
- Curated industry-leading SOC technologies: achieving rapid time-to-value around AWS, Splunk, and other foundational SOC tools with the Deepwatch Security Center
- Proactively drive SecOps program maturity: the Deepwatch proprietary Security Index includes quantitative analysis and industry benchmarking to drive ongoing security posture improvements
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(1)

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
MDR | deepwatch MDR - dw-provided Splunk licensing 50gb per day | $245,198.00 |
MEDR | deepwatch MEDR - up to 1001 endpoints - dw-provided EDR licensing | $98,369.00 |
VM | deepwatch VM Essential - up to 2500 IPs - dw-provided VM licensing | $192,251.00 |
FW | deepwatch FW - up to 10 FW - BYOL Palo Alto, Check Point, or Fortinet | $50,160.00 |
Vendor refund policy
All orders are non-refundable unless otherwise dictated in the MSA.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Support Information Deepwatch Managed Security Platform Deepwatch Experts Customers are assigned a designated squad of Deepwatch experts including a delivery team, customer success managers, analysts, detection engineers, firewall engineers, threat hunters, and threat responders. Customers will have specific direct communication points with their supporting squad members. Time Sensitive/Critical Issues: 1-844-477-8762, Option #1 Refund Policy All orders are non-refundable unless otherwise dictated in the MSA.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Continuous monitoring has improved threat detection and reduces incident response time
What is our primary use case?
Deepwatch is my main platform for managed detection and response across cloud and hybrid environments, providing 24/7 SOC monitoring. It helps with real-time threat detection, incident response, and log analysis, improving security posture and reducing response time in operations.
For example, using Deepwatch , we detected suspicious login attempts in a cloud workload via real-time log analysis. The platform triggered alerts and guided response actions, allowing us to quickly isolate the account, enforce MFA, and prevent a potential breach, reducing response time significantly.
Additionally, with Deepwatch, we use it for continuous monitoring of cloud logs, such as AWS CloudTrail and Azure Monitor , to detect anomalous activity and policy violations. It also helps in incident correlation and automated response playbooks, improving SOC efficiency and reducing mean time to detect or respond.
How has it helped my organization?
Deepwatch has positively impacted my organization by improving security posture and response efficiency through providing continuous monitoring and faster incident detection. It has also reduced SOC overload, workload, and alert fatigue, allowing teams to focus on critical threats instead of manual log analysis, improving overall operational efficiency.
With Deepwatch, I have seen a 40 to 50% reduction in MTTR due to faster detection and guided response playbooks. False positives have also dropped significantly by 40 to 50% through better correlation and risk scoring, which significantly reduced SOC workload and improved analyst efficiency.
What is most valuable?
Some of the best features of Deepwatch include 24/7 MDR plus with AI plus human expertise, providing continuous threat detection, investigation, and response across cloud and hybrid environments.
The most valuable feature for us in Deepwatch is its 24/7 managed detection and response with AI plus human expertise. This ensures us continuous monitoring, proactive threat hunting, and rapid incident response, significantly reducing the MTTR and alert noise while improving detection accuracy.
One additional outstanding feature in Deepwatch is its context-driven alerting and risk scoring with prioritized real threats instead of generating alert noise.
What needs improvement?
Deepwatch could improve with more granular customization of detection rules and alert tuning to better fit specific cloud workloads and use cases. Additionally, it can be improved by enhancing the dashboarding.
It should also support deeper cloud-native integrations such as AWS , Azure , and GCP, which would further improve operational efficiency and control.
Regarding the support, I would say that the support team should be more responsive because ideally, the response time of the support is quite long, which is sometimes frustrating. However, I do agree that for easy issues, they respond within the expected time, but for complex issues, they do take time to respond.
For how long have I used the solution?
I have been using Deepwatch for three years.
What do I think about the stability of the solution?
Deepwatch is stable.
What do I think about the scalability of the solution?
Deepwatch is scalable from smaller enterprise to large enterprise without any challenges.
How are customer service and support?
The customer support is good, and the response time is still not good but can be improved.
Which solution did I use previously and why did I switch?
We previously used traditional SIEM setups like Splunk with an in-house SOC operation. We switched to Deepwatch for managed detection and response to reduce operational overhead, improve threat detection accuracy, and get 24/7 expert-driven monitoring without scaling internal teams.
How was the initial setup?
Overall, the pricing for Deepwatch is premium, but it provides high value, especially for organizations replacing or augmenting an in-house SOC. The setup cost generally is low to moderate, and the onboarding can be as quick as less than one hour. However, tuning and integration add more effort.
What was our ROI?
There is a clear ROI observed with Deepwatch, both in operational and cost savings. In the operational part, we have seen a 40 to 50% reduction in incident response time and a significant reduction in analyst workload due to automation and expert-led triage. We have also seen an 86% reduction in event response cost and savings equivalent to multi-FTEs.
Which other solutions did I evaluate?
We evaluated several other options before selecting Deepwatch.
What other advice do I have?
I would recommend going for this product, and I would suggest asking the sales team for discounts because they do provide discounts. It is necessary to ask them and get the best deal out of it. My review rating for this product is 8.