Real people quote it, order it, install it and stay on your account.

IT RavenIT RavenStoreQuote list

Trustwave

Available through IT Raven

  • Cybersecurity
  • Industry and Growth

Trustwave is a cybersecurity company that watches its clients' security tools around the clock and also tests their defenses by attacking them. It describes itself as a pure-play security provider with more than 25 years in the business, protecting clients in over 86 countries.

Two things define it. Its research, threat hunting and testing are done in-house by a team called SpiderLabs, and the company says that team's findings feed every service it sells. And much of its current work is built around Microsoft's security products, where it helps customers get value from licenses they already own.

Best for

  • Organizations that hold Microsoft E5 or similar security licensing, including Sentinel and Defender, and want a partner to run it and tune it.
  • Security teams that want to keep and own their monitoring platform, often Splunk, and add round-the-clock eyes and tuning instead of outsourcing the whole thing.
  • Buyers with a mixed set of security tools who need a provider willing to work with what is already in place.
  • Government agencies and operators of critical infrastructure with many dispersed sites.
  • Buyers who want attack and defense from one company: the people who run penetration tests and red teams also run detection and response.
  • Procurement and vendor risk teams that have more suppliers to assess than staff to assess them.

What they offer

Trustwave is listed here under Managed Security, and its range runs wider than that one heading.

Monitoring and response. Managed Detection and Response puts Trustwave analysts on your existing tools around the clock, on a platform it calls Trustwave Fusion. Co-Managed SOC supports a security operation you keep running yourself. Managed SIEM for Microsoft Sentinel and MXDR for Microsoft do the same work inside the Microsoft stack, where Trustwave can take response actions directly.

Microsoft services. Assessments for Defender, Sentinel and Security Copilot, migrations from other tools onto Microsoft security, and a data security review of your Microsoft 365 content.

Testing and incident response. SpiderLabs performs penetration testing, red team and purple team exercises, and digital forensics when a breach has happened.

Risk and products. Managed Vendor Risk Assessment takes on third-party security reviews as a subscription. MailMarshal is an email security gateway that runs beside Microsoft 365. AppDetectivePRO and DbProtect scan and monitor databases for weaknesses and excessive access.

Proof

Trustwave's 2025 research report states that SpiderLabs performs over 200,000 hours of penetration testing a year and discovers over 30,000 vulnerabilities annually. Its red team works from hubs in the United Kingdom, Australia, Singapore and the United States, with a pool of more than 140 testers, researchers and incident responders.

The company is CREST certified for vulnerability assessment and penetration testing, is a Microsoft Verified MXDR Partner, and reports being named a Top 10 MSSP by MSSP Alert for six years running. For managed detection and response it states a mean time to respond of less than 30 minutes.

Two published accounts withhold the client's name.

A government agency protecting research tied to national security. It needed round-the-clock monitoring for almost a dozen research centers spread across the country, had found gaps on evenings and weekends, and wanted to keep its existing security tools. Its contract with the firm running its security operations center was ending within a year.

A health system in the United States. SpiderLabs red team testers escaped a locked-down virtual desktop session and escalated their access, which showed the client a weakness in how its clinical applications were delivered.

These figures and accounts are Trustwave's own.

Good to know

  • Trustwave tells new detection and response customers to expect onboarding in less than 10 days.
  • Managed Vendor Risk Assessment has a floor. Packages start at 10 vendor assessments.
  • The base data security review covers standard Microsoft 365 content such as email and documents. On-site data stores, Windows devices and AI usage are add-ons.
  • MailMarshal can run in the cloud or on your premises. The on-premises version needs a Windows server and a SQL database.
  • DbProtect can be run by your own staff or handed to Trustwave as a managed service.
  • Some scale figures differ between Trustwave documents of different years. Ask for current numbers if one of them matters to your decision.

Similar companies

They offer some of the same services. Add two or more and we quote them against each other.

    • Cybersecurity
    • Cloud and Infrastructure
    • Backup and Continuity
    • Industry and Growth
    • Cybersecurity
    • Cybersecurity
    • Cloud and Infrastructure
    • Data Center and Colocation
    • Backup and Continuity
    • +1 more
    • Cybersecurity

How buying works

The store is the easy part. Staying on the account is the job.

Anyone can show you logos. The reason to buy here is what happens on install night, and on the ticket you open nine months later.

  1. 01

    Build your quote list

    Add services and companies as you shop. No form stands between you and the shelf.

  2. 02

    We bring back real options

    A person shops the bench against your addresses, then walks you through what fits and what does not.

  3. 03

    We handle the order and install

    Paperwork, site survey, install dates, cutover night. You get one thread, not five vendors.

  4. 04

    We stay on your account

    Same team for moves, adds, tickets and the next renewal. That is the part everyone else drops.