CrowdStrike for small business:
the part nobody sells you.
You can buy CrowdStrike Falcon in an afternoon. Operating it is the other purchase, and it is the one that decides whether the platform ever stops a breach.
CrowdStrike sells Falcon to small businesses directly and the pricing is public. What is not included at any price is a person: someone who sees the 2am detection, decides what it means, and acts on it before Monday.
Falcon Go is capped at 100 devices, so a 140-person company cannot buy the small-business product at all. It buys Falcon Pro or Enterprise, per device, and it buys a console.
ThreatDefend™ is Vijilan's stack and Vijilan's SOC. We bring CrowdStrike Falcon, deploy it against your environment, and run it 24/7/365 with Tier 1 through Tier 3 analysts on every alert. When something is real the SOC acts: host isolation, account disable, token revoke, process kill. Every containment decision is authorized by a trained human analyst, never by an algorithm acting alone.
What you can
actually buy today.
CrowdStrike sells Falcon to small businesses directly, and the pricing is public. Falcon Go runs $7.99 per device per month or $59.99 per device per year. Falcon Pro is $14.99 / $99.99. Falcon Enterprise is $19.99 / $184.99.
There is one constraint worth knowing before you plan around it: Falcon Go purchases are limited to a maximum of 100 devices. If you are a 140-person company, the small-business product does not fit you. You are buying Pro or Enterprise, per device, and you are buying a console.
That is the honest shape of the market. The platform is excellent and it is available. What is not included at any of those prices is a person.
CrowdStrike list pricing and the Falcon Go device limit, crowdstrike.com, checked 21 September 2026. Vendor list pricing moves; confirm with CrowdStrike or your distributor before budgeting against it.
The question
that decides everything.
Falcon detects something at 2:14am on a Sunday. What happens next?
At a 2,000-person company a Tier 2 analyst picks it up inside a few minutes. At a 140-person company it sits in a console, and possibly in an email nobody has configured a phone alert for, until Monday. The detection was perfect. The outcome was a weekend of dwell time.
This is not a CrowdStrike problem. It is an operating problem, and it is the reason managed security exists as a category at all.
CrowdStrike said this
out loud.
On 13 August 2026 CrowdStrike extended Project QuiltWorks, its industry coalition for frontier AI risk, to small and medium businesses through Arrow Electronics, Ignition Technology, Nord Security, Pax8, TD SYNNEX, Westcon-Comstor and Zip Security.
“Most SMBs lack the resources and expertise to access and operationalize these capabilities on their own.”
“The channel is how QuiltWorks can reach every organization, regardless of size, sector, or geography.”
A platform vendor does not route an offering through distributors, marketplaces and MSP networks unless the operating layer is the hard part. It is.
Read what Project QuiltWorks actually means for a company your sizeNot a dashboard you log into.
An operator who answers.
ThreatDefend™ is our stack and our SOC. We bring CrowdStrike Falcon, deploy it against your environment, and run it 24/7/365.
Tier 1 through Tier 3 analysts on every alert. Praxis AI™ investigates, enriches and triages before a human sees it, so the analyst starts with context instead of a raw detection. And when something is real, the SOC acts: host isolation, account disable, token revoke, process kill, rather than forwarding you an alert with a severity label on it.
Every containment decision is authorized by a trained human analyst informed by Praxis, not by an algorithm acting alone. Never autonomous-only.
What is included
at Essential.
Most entry-tier managed security is endpoint-only and advisory. ThreatDefend Essential is neither.
Falcon EDR and NGAV, managed
Deployed, tuned and operated by Vijilan rather than handed over with a login.
Full ITDR
Dark web exposure, impossible travel, MFA fatigue, business email compromise, OAuth abuse, lateral movement.
Active Directory, Entra ID and Microsoft 365 monitoring
The identity surface, watched as one thing rather than three consoles.
ThreatLog™ SIEM
Index-free, so log volume does not turn into a surprise invoice.
The SOC acts
Host isolation and account disable from day one, not from the tier above.
Identity is how small companies actually get breached. A stolen session token does not trip an endpoint sensor. Including ITDR at the entry tier is the difference between covering the attack you imagine and the attack you get.
See all four ThreatDefend tiersIs this
you?
ThreatDefend fits companies of roughly 25 to 250 people, and it fits hardest between 100 and 250, where you are past the Falcon Go device cap but nowhere near the headcount that justifies hiring three analysts to cover three shifts.
The conversations that usually start this:
- Your cyber-insurance renewal now asks for EDR with 24/7 monitoring
- A customer sent a security questionnaire you cannot answer honestly
- You had a near miss and found out afterwards
- Your one security-literate person just left
- HIPAA, PCI or CMMC Level 2 arrived with a date attached
Give us a domain. See what an attacker sees.
ThreatAssess™ is a free external attack surface scan powered by CrowdStrike. No agent to install, no credit card, no obligation. Then we price against what the scan actually finds, rather than against a guess.
The ones people
actually ask.
We already bought CrowdStrike. Is this a replacement?
No, it is the other half. We operate the Falcon you own, or we bring licensing as part of ThreatDefend, whichever is cleaner commercially. Nothing gets ripped out.
How is this different from Falcon Complete?
Falcon Complete is CrowdStrike's own managed service and it is very good at what it does: responding on the endpoint. ThreatDefend adds identity coverage from the entry tier, and our NextDefend™ Operate service extends containment past the endpoint into cloud, SaaS and network. They solve overlapping but different problems.
Full comparisonWe are too small for a SOC.
You are too small to staff one. Three analysts, three shifts, 365 days, plus holidays and attrition, is a headcount problem no 150-person company solves. That is exactly why it is bought as a service.
We already have an IT provider.
So do most of the companies we protect. We run the SOC behind them, and we never compete with our partners for their clients. If you would like, we will talk to your provider directly.
Does AI make the containment decisions?
No. Praxis AI™ investigates, correlates, enriches and triages. A trained human analyst authorizes every consequential action.
What does it cost?
Per endpoint and per user, across four tiers, quoted against your actual estate. Start with the free ThreatAssess™ scan and we will price against real findings rather than a guess.
ISO/IEC 27001 Certified · SOC 2 Type II Audited · CrowdStrike Powered Service Provider (CPSP)
SOC 2 Type II independently audited annually. HIPAA, PCI and CMMC L2 evidence packs available on request.
Related reading
- Falcon Complete vs ThreatDefendBoth are managed CrowdStrike. What is genuinely comparable, and what to ask CrowdStrike directly.Read
- MDR for small businessEDR is the software. MDR is somebody answering.Read
- ThreatDefendThe four tiers, and what the SOC does at each one.Read
- QuiltWorks for SMBs, explainedWhat CrowdStrike routing its coalition through the channel changes for you.Read
- CrowdStrike alternatives, comparedHow Falcon sits against the platforms buyers weigh it against.Read
- Already on Falcon Complete?Who does what, and where a partner actually fits.Read
- For MSPs and MSSPsRun the SOC behind your brand. We never compete for your clients.Read