Saaskly

ThreatDown by Malwarebytes

Malwarebytes' business line, with the cheapest published MDR on this page: Core is £57.04 a device a year, Advanced with EDR £65.31, Elite with MDR £81.84, all bought online in pounds with ransomware rollback on every tier. What to know: the online store stops at 20 devices per line, servers are an add-on at every tier, Core has no EDR at all, the last independent business test was 2022, and Malwarebytes' own mailbox was breached by the SolarWinds-era attackers in 2021.

How we test
3.2/5
Saaskly score

ThreatDown is not a company but the business brand Malwarebytes Inc. launched on 7 November 2023 for what had been Malwarebytes for Business; the UK entity became ThreatDown UK Limited (Companies House 09987777) in April 2026. Malwarebytes was founded in 2008 by Marcin Kleczynski, who remains chief executive, is privately held with a $100 million investment from Vector Capital in 2022, and lists offices in Santa Clara, Florida, Cork, Tallinn, Italy, Lisbon, Bilbao and Tel Aviv. We found no Russian or Chinese link.

Prices are in pounds, read on 9 September 2026 at threatdown.com and in the Cleverbridge-run checkout with a UK address. Whether they include VAT is not stated; the checkout takes a VAT number, so we record them as ex VAT and flag it. The four bundles are Core (£57.04 a device a year), Advanced (£65.31) with EDR, Elite (£81.84) with MDR and Ultimate (£110.57) with MDR Plus, identity threat detection and Premium Support built in, with 20 per cent off for a three-year term. Core is the tier we score because it is the cheapest with a cloud console covering Windows, macOS and Linux; servers are an add-on at every tier, so a mixed estate costs more than the headline. The store sets a hard limit of 20 devices per line item: typing 25 snapped back to 20 every time, so our 25-device benchmark needs two lines or the partner route the pricing page also offers. Email security, DNS filtering, mobile security and Premium Support are unpriced add-ons. No trial or renewal terms were found on the pages we read.

The feature ladder is honest. Ransomware rollback (up to seven days of encrypted files), browser phishing protection, device control, vulnerability assessment and an application blocklist are on every tier; host firewall management, patch management and Windows disk encryption management start at Advanced; EDR at Advanced; MDR at Elite, with no MDR option at all on Core. The Nebula console is browser-based, with OneView for multi-tenant MSP use, generic installer and RMM deployment, and a long integration list: Syncro, SuperOps, ConnectWise Asio, Automate and Manage, Kaseya VSA and BMS, Datto RMM and Autotask, Atera; Splunk, Microsoft Sentinel and Google Chronicle for SIEM. NinjaOne and N-able are not on it. No MCP server was found.

The independent record is thin and dated. Malwarebytes was Approved in AV-Comparatives' August to November 2022 business test and has not appeared since; it is not in AV-TEST's June 2026 business round; we found no SE Labs or MITRE result; the "14 consecutive quarters" MRG Effitas claim is the vendor's. In January 2021 Malwarebytes disclosed that the SolarWinds-era attackers had read a subset of its internal email through a dormant Office 365 protection product, with no access to its source code or products. ThreatDown's own Trustpilot profile has one review; the 4.4 on 5,416 for malwarebytes.com is the consumer product. G2 gives it 4.6, by ThreatDown's own homepage badge. Not yet tested by Saaskly: assessed on published pricing, the independent test labs, vendor documentation and third-party reviews.

Cons

  • The online store caps each line at 20 devices, below our 25-device benchmark; servers are an add-on at every tier, so a mixed estate costs more
  • No EDR on Core and no MDR option on it at all; VAT basis not stated at checkout
  • No independent business test since 2022 and nothing at AV-TEST or MITRE; the 2021 breach of Malwarebytes' own email; ThreatDown's Trustpilot profile has one review

Pricing

Minimum commitment: £57.04 (£57.04/yr for the entry licence). The least you can spend before walking away; excludes numbers, minutes and add-ons.

Core

£57.04/yr · annual commitment

Month-to-month: not published

  • £57.04 per device per year, GBP, VAT basis not stated (checkout takes a VAT number), read 9 Sep 2026. Next-gen AV, ransomware rollback, browser phishing protection, device control, vulnerability assessment. No EDR and no MDR option. Online store capped at 20 devices per line; partner route above. 20% off a 3-year term.

Advanced (EDR) / Elite (MDR)

£65.31/yr · annual commitment

Month-to-month: not published

  • Advanced £65.31 per device per year adds EDR, firewall management, patch management and Windows drive encryption management. Elite £81.84 adds MDR; Ultimate £110.57 adds MDR Plus, identity threat detection and Premium Support. Servers, email security, DNS filtering and mobile security are add-ons at every tier.

Specifications

Rating
3.2
Scored tier*£57.04/device/yr (Core)
Monthly billingAnnual only
Entry planScored tier is the entry plan
SeatsUp to 20
ServersSeparate SKU
EDRNext tier up
MDRAdd-on, £81.84/device/yr
Buy online
Self-service portal
AV-ComparativesBusiness Security Test Aug to Nov 2022: Approved; not tested since
AV-TESTNot in the June 2026 business round
SE LabsNot found
MITRE evaluatedNo
Ransomware rollback
Web filtering
Email securityPaid add-on
PatchingPaid add-on
Device control
PlatformsWindows · Mac · Linux
Cloud console
RMM integrationsSyncro, SuperOps, ConnectWise Asio, Automate and Manage, Kaseya VSA and BMS, Datto RMM and Autotask, Atera
API
MCP serverNo
Owned in**US-owned
Russian or Chinese linkNone found
Phone supportNo
Trustpilot (reviews)3.7 (1)
Scored tier nameCore
VAT basisExcluding VAT
Top plan£110.57/device/yr (Ultimate)
EDR tier or add-onAdvanced, £65.31 per device per year
Monthly billing availableNo
How you buyCleverbridge checkout at store.threatdown.com (card or PayPal), 20 devices per line; partner or MSP route via the pricing page
Free trial (days)0
Price changes20% off for a three-year term; no dated UK price change found
Test record noteMRG Effitas claims are vendor-repeated and unverified
Behavioural detection
Exploit preventionNo
Firewall managementNo
Disk encryption managementNo
Vulnerability scanning
Application control
Mobile threat defenceNo
iOSNo
AndroidNo
Platform notesServers via the Server Protection add-on at every tier; mobile (iOS, Android, ChromeOS) via the Mobile Security add-on; firewall, patching and drive encryption management from Advanced
On-premises console optionNo
Console data locationNot stated
DeploymentGeneric installer, RMM push
SIEM export
Multi-tenant console
SSO into consoleNo
HQUnited States
OwnerMalwarebytes Inc. (Vector Capital investor)
Engineering locationsUS, Ireland, Estonia, Italy, Portugal, Spain, Israel
Link evidenceNone found
SOC 2No
ISO 27001No
Cyber EssentialsNo
Major incident on record
Incident noteJanuary 2021: SolarWinds-era nation-state actor read a subset of Malwarebytes internal email via a dormant Office 365 protection product; no product or source-code access
Live chat
UK support hoursConsole and live chat; phone for Severity 1 only; 24/7 phone is Premium Support (included on Ultimate)
Paid support tierPremium Support add-on, quote
Support channelsConsole tickets, Live chat, Phone (Severity 1)

*Scored tier: the business tier the score is set on (the cheapest plan with a cloud console covering Windows, macOS and Windows Server), per device per year on a one-year term at about 25 devices, then per device per month where monthly billing exists, in the currency the vendor shows a UK visitor on the research date; see each profile for the VAT basis, the seat band and what the tier above adds.

**Owned in: where the company that owns the vendor answers to. A US-owned vendor is subject to US law (including the CLOUD Act) wherever the console data sits. "Russian or Chinese link" records ownership, management or engineering links found on the research date, with the evidence on the profile; Saaskly marks these down in the score by editorial rule and says so.

Researched and drafted with AI assistance; reviewed and approved by Tim Meredith. How we use AI

Work at ThreatDown by Malwarebytes? Something not look right? Register in the vendor portal to see what we publish and send corrections.