Deep Dive · Risk & Outcomes

Security that reports in verbs, not noise.

A board does not want to hear that you processed three billion events last week. They want to hear that the four incidents that mattered were contained, eradicated, and recovered, with the relevant times and evidence available for review. Edg3 is designed to keep those operational outcomes attached to the investigation.

The Outcome Framework

Track the response state, not just the alert count.

Traditional SIEM reports often stop at events ingested, alerts triggered and rules tuned. Edg3 also retains investigation and response state so teams can distinguish detection from containment, eradication work and recovery. Completion still requires an analyst or operator to record the real-world outcome.

Contained.

The blast radius stops growing.

For a qualifying ransomware verdict, the agent can isolate the host locally. Other response actions remain approval-gated and depend on configured provider integrations. The case can retain the isolation and approval timeline for review.

Eradicated.

The adversary's foothold is removed.

Eradication is recorded after the responsible team verifies that the relevant footholds, credentials and artefacts have been addressed. Edg3 preserves the investigation history and available provider results; it does not infer completion from an alert closure alone.

Recovered.

Business function is fully restored.

Recovery is an operational decision: services return, users are restored and monitoring confirms the expected state. The case record can retain that outcome and its timing when the team records it.

Time-to-Outcome

Lifecycle timings grounded in recorded case events.

Detection, containment and recovery measure different points. Edg3 can derive lifecycle timings when those points are represented by recorded events or operator decisions. Missing stages remain missing rather than being estimated as complete.

MTTD
Mean time to detect
MTTC
Mean time to contain
MTTE
Mean time to eradicate
MTTR
Mean time to recover

These measures can be grouped for operational reporting where the underlying records have the required timestamps. Teams should validate the source and coverage before using them for external assurance.

The board-ready one-pager

Edg3 reports can combine case status, available timings and evidence references. A human owner should review the result before it enters a board, insurer or regulatory pack.

External Review

Exportable evidence with its coverage stated.

Reviewers need to understand what was observed, what was not collected and what action was taken. Edg3 keeps case history and supports reports and exports, but the contents depend on the telemetry, collection workflow and provider actions enabled for that tenant.

What the case package contains

External evidence still needs an owner

An export can shorten evidence gathering, but it does not determine materiality, satisfy a notification obligation or guarantee an insurance outcome. The accountable owner must validate the record and its coverage before external use.

Compliance Evidence

Mapped checks without implied certification.

The current policy library maps evaluated endpoint checks to relevant framework controls. A mapping shows why a check may support a control; it is not a certification and does not turn unassessed controls into passes.

CIS BenchmarksConfiguration baselines
Supported Windows, Ubuntu and macOS checks are grouped into platform-specific policy packs. A result describes the state observed on the evaluated host.
NIST 800-53Control mapping
Relevant policy checks carry NIST control annotations so teams can link observed host posture to an evidence-gathering workflow. Applicability remains the customer’s decision.
SOC 2 TSCTrust Services Criteria
TSC annotations help organise technical evidence. They do not constitute an auditor’s opinion or show that non-technical criteria have been assessed.
HIPAA 164.312Technical safeguards
Selected checks are annotated where they may support technical-safeguard evidence. Legal applicability, completeness and risk analysis remain outside the platform score.
PCI DSSPayment security controls
Relevant technical checks carry PCI DSS annotations. The view shows evaluated posture and coverage gaps, not a PCI compliance determination.
CoverageWhat was not assessed
Framework reporting should state the number of applicable, evaluated and unavailable controls. Missing telemetry or unsupported checks remain unscored.
The Economic Case

Endpoint-tier pricing with no per-GB ingestion fee.

Edg3 plans use an endpoint allowance and retention period rather than an ingestion-volume fee. Annual prices below are the current plan catalog; month-to-month is also available. Self-service checkout is temporarily paused, so Sales should confirm availability and scope.

Edition Annual billing Month-to-month
Starter · up to 150 endpoints $5,748/year $579/month
Professional · up to 500 endpoints $11,388/year $1,149/month
Enterprise · up to 1,500 endpoints $22,788/year $2,299/month
Enterprise Plus+ Contact Sales Contact Sales

Annual figures correspond to effective monthly rates of $479, $949 and $1,899. Edition features, retention and configured providers should be confirmed in the order scope rather than inferred from a headline price.

Compare like with like

A valid comparison needs endpoint count, retention, hosting, enabled integrations, support and migration effort. Edg3’s no-per-GB model is clear; competitor savings should not be quoted without a documented customer baseline.