← All posts

Open Source Security for Enterprises: Costs & Stack

An enterprise open-source security stack is a set of mature, openly licensed tools — run with the same rigour as commercial products — covering the five core layers of a security programme: SIEM (detection and log analysis), DFIR (forensics and incident response), vulnerability scanning, IAM (identity and single sign-on), and PAM (privileged access). The tools are free to license; what you pay for is infrastructure plus the expertise to deploy, tune, and monitor them — either in-house or through a managed service.

The economics are the headline: commercial stacks commonly run well into six figures annually at mid-market scale; a managed open-source equivalent typically lands at a fraction of that — request a quote for your environment.

Here’s the stack, layer by layer, with honest cost context and an equally honest section on where commercial tools still win.

The stack, layer by layer

SIEM and XDR: Wazuh

Wazuh handles log aggregation, real-time threat detection, file integrity monitoring, and compliance reporting, with alerts mapped to MITRE ATT&CK. It’s the open-source counterpart to Splunk Enterprise Security or Microsoft Sentinel — platforms that commonly run $150K–$500K+ per year at typical mid-market ingest volumes (industry-reported; Splunk doesn’t publish list pricing and has moved to workload-based SVC pricing, so confirm against your quote). Because Wazuh isn’t licensed per gigabyte, log growth doesn’t grow the bill. See managed Wazuh, or the deeper Wazuh vs Splunk cost comparison.

DFIR: Velociraptor

Velociraptor is a digital forensics and incident response platform: endpoint visibility, artifact collection, threat hunting at scale. It’s the investigative complement to EDR suites like CrowdStrike Falcon, which industry reporting commonly places in the tens to low hundreds of dollars per endpoint per year depending on modules. One honest caveat: Velociraptor is a hunting and forensics tool, not a real-time prevention agent — more on that below. ThinSky runs it as managed Velociraptor.

Vulnerability scanning: OpenVAS / Greenbone

For enterprise open-source security scanning, OpenVAS (maintained by Greenbone) is the established answer. It draws on one of the largest open vulnerability-test feeds in the industry, updated daily, and covers authenticated and unauthenticated scanning across servers, network gear, and web infrastructure. Commercial comparators — Qualys, Tenable/Nessus at enterprise scale — commonly run tens of thousands of dollars per year at mid-market asset counts (industry-reported; confirm against your quote). Commercial scanners do ship larger proprietary check libraries; for most environments the practical coverage difference matters far less than whether scans actually run on schedule and findings actually get remediated — which is the part managed OpenVAS handles.

IAM and SSO: Keycloak

Keycloak provides single sign-on, multi-factor authentication, user federation (LDAP/AD), and fine-grained authorisation — the territory of Okta and Microsoft Entra ID, which are licensed per user per month and commonly reach tens of thousands of dollars annually at a few hundred users (industry-reported; confirm against your renewal). Keycloak has no per-user licence, so headcount growth is free. See managed Keycloak. For the full breakdown of how Okta’s per-user meter compounds past $100K/yr at mid-market headcount, see Okta pricing in 2026.

PAM: Teleport

Teleport secures privileged access to servers, Kubernetes, databases, and internal apps with short-lived certificates, session recording, and audit trails — the problem space CyberArk occupies at six-figure annual price points in many enterprise deployments (industry-reported; CyberArk doesn’t publish enterprise list pricing). See managed Teleport.

Cost comparison: commercial vs managed open source

All commercial figures are industry-reported ranges at the time of writing — none of these vendors publish firm list prices, so confirm everything against your own quotes.

LayerCommercial tool (hedged annual range)Open-source equivalent, managed by ThinSky
SIEM/XDRSplunk — commonly $150K–$500K/yr at typical mid-market ingest volumes, industry-reportedWazuh — flat annual pricing, request a quote
DFIR/EDRCrowdStrike Falcon — commonly tens to low hundreds of $/endpoint/yr depending on modules, industry-reportedVelociraptor — flat annual pricing, request a quote
Vulnerability managementQualys / Tenable — commonly $20K–$60K+/yr at mid-market asset counts, industry-reportedOpenVAS — flat annual pricing, request a quote
IAM/SSOOkta — commonly $3–$15+/user/month depending on products, industry-reportedKeycloak — flat annual pricing, request a quote
PAMCyberArk — commonly six figures annually in enterprise deployments, industry-reportedTeleport — flat annual pricing, request a quote

The pattern is consistent: commercial pricing scales with your growth (data volume, endpoints, users), while open-source licensing costs nothing and the managed-service fee stays flat. That’s why the gap widens every year you grow.

Why quality reached parity

The “open source means hobby project” era is over, and the evidence is in the tools themselves:

  • Wazuh ships 3,000+ out-of-the-box detection rules (its published count) — coverage many commercial SIEMs charge extra to match — plus XDR, file integrity monitoring, and vulnerability detection included rather than sold as add-ons.
  • OpenVAS maintains a daily-updated vulnerability-test feed that’s been in continuous development for over two decades.
  • Keycloak supports more authentication protocols and federation options than many commercial IAM products, and it’s the upstream of Red Hat’s commercial identity offering.
  • Velociraptor was built by veteran DFIR practitioners and is now stewarded by Rapid7 — it’s what many professional IR teams actually deploy on engagements.

These projects are developed in the open, audited by researchers worldwide, and patched transparently. The big vendors know it: plenty of commercial security products are built on the same open-source components they’re charging six figures to wrap.

Where commercial still wins

Honesty matters here, because the answer isn’t “open source for everything, always”:

  • Real-time endpoint prevention. CrowdStrike-class EDR blocks malware execution in real time with ML-driven prevention. Velociraptor is a superb investigation and hunting platform, but it is not a prevention agent. If pre-execution blocking is a hard requirement, you’ll pair the open stack with an EDR or rely on hardened OS-native controls.
  • Advanced analytics at extreme scale. Splunk’s ad-hoc search and risk-based alerting across petabyte-scale data remains genuinely hard to replicate.
  • Ecosystem breadth. Okta’s catalogue of thousands of pre-built app integrations means some long-tail SaaS apps connect in minutes; with Keycloak, an unusual integration occasionally needs engineering work.
  • Single-vendor accountability. Some boards and insurers simply want one large vendor’s name on the contract. That’s a governance preference, not a technical one — but it’s real.

A managed open-source stack covers the core 80–90% of what mid-market organisations actually use commercial suites for. Knowing where your remaining 10–20% lives is exactly the kind of question to settle before migrating.

Illustrative cost model: a 2,000-employee healthcare organisation

This is a hypothetical model, not a client engagement. Take a 2,000-employee healthcare organisation running a typical commercial stack — SIEM, EDR, vulnerability management, IAM, and PAM. At industry-reported mid-market ranges, that stack plausibly totals $300K–$600K per year before professional services.

The managed open-source equivalent — Wazuh, Velociraptor, OpenVAS, Keycloak, and Teleport, deployed and monitored by ThinSky — is priced flat per year and typically lands at a fraction of that range. The compliance-relevant capabilities (HIPAA-mapped monitoring dashboards, audit evidence collection, access logging) are part of the stack itself. We won’t publish a fake before/after number here: every environment is different, which is why the model ends with request a quote rather than a savings guarantee.

The migration path

Nobody should rip out their security stack over a weekend. The pattern that works:

  1. Audit what you have. Inventory current tools, renewal dates, and what each one actually costs per year — including add-ons and services.
  2. Pick one layer. Choose the tool with the most painful renewal or the least vendor entanglement — vulnerability scanning and SIEM are common first moves.
  3. Run in parallel. Deploy the open-source equivalent alongside the incumbent and compare detections, coverage, and noise for 60–90 days.
  4. Cut over with evidence. Migrate when the parallel run proves parity for your environment — not when a sales deck says so.
  5. Repeat at each renewal. Each contract expiry is a free exit ramp. Start by seeing what an outsider sees: a free external security audit gives you a baseline before you change anything.

FAQ

Is open-source security software safe for enterprises?

Yes, when it’s run properly. Mature projects like Wazuh, Keycloak, and OpenVAS are publicly auditable, actively maintained, and patched transparently — and they back commercial products from vendors like Red Hat and Rapid7. The real risk isn’t the licence model; it’s unmanaged deployment. An untuned SIEM is unsafe whether it cost $0 or $300K.

How much does an open-source security stack cost compared to commercial tools?

The software licences are free; the costs are infrastructure and operations. Commercial stacks covering SIEM, EDR, vulnerability management, IAM, and PAM commonly run well into six figures annually at mid-market scale (industry-reported ranges — confirm against your own quotes). A managed open-source equivalent is typically a fraction of that, priced flat per year. Request a quote for a number specific to your environment.

What open-source tools replace Splunk, CrowdStrike, and Okta?

Wazuh covers the core Splunk SIEM/XDR use cases; Velociraptor covers CrowdStrike’s forensics and threat-hunting territory (though not its real-time prevention agent); Keycloak covers Okta’s SSO, MFA, and federation use cases. Each replacement covers the core capabilities most organisations use — see the “where commercial still wins” section for the honest exceptions.

Is there an enterprise-grade open-source vulnerability scanner?

Yes — OpenVAS, maintained by Greenbone, is the established enterprise open-source scanner. It runs authenticated and unauthenticated scans across servers, network devices, and web infrastructure from a daily-updated vulnerability feed. Commercial scanners ship larger proprietary check libraries, but for most environments scheduled, managed scanning with real remediation follow-through matters more than raw check counts.

Who provides support for open-source security tools?

Three options: the projects themselves (several, including Wazuh and Greenbone, sell professional support), the community (forums, documentation, shared rule sets), and managed service providers. ThinSky’s model is the third: we deploy, tune, monitor, and support the full stack under one flat annual agreement, so you get commercial-grade accountability on open-source economics.


If your next renewal quote made you wince, that’s the signal. Start with a free external security audit to see your attack surface the way an outsider does, then talk to us about a managed open-source stack — email sales@thinsky.com or request a quote and we’ll map your current spend against a flat-priced equivalent.