Introducing the Security Module: EDR, XDR & Firewall, Built In

A native EDR/XDR/firewall layer on the same agent and dashboard you already use — enrollment-gated, billed per device, no third-party console to reconcile.

T
The Plenix Team·17 September 2026·3 min read

Most MSP platforms make you bolt on a third security vendor, wire up an API integration, and hope the dashboards agree with each other. We decided that was the wrong default.

What shipped

The Security Module is a native EDR/XDR/firewall layer built directly into the same agent and dashboard you already use for monitoring, patching, and remote control. No separate console, no separate agent install, no reconciling two different device lists.

It's a genuinely new capability — not a rename of the existing third-party-vendor-mirror edr module some tenants already had, which continues to work exactly as before for anyone syncing an external EDR product's alerts into Plenix. The Security Module is Plenix's own detection and response layer, running on Plenix's own agent.

How it's enabled

Security isn't switched on by default for anyone — not even on plans that include it. It's an explicit, per-customer or per-device enrollment, handled by a dedicated SecurityEnrollmentService:

  1. Open a company or a device in Monitoring.
  2. Choose Enroll in Security.
  3. Coverage begins immediately for whatever scope you picked — a single device, or every device under a customer.

That deliberate friction is by design. Security tooling changes how a machine behaves — quarantine actions, firewall rule pushes, process termination — and we don't think that should ever happen because a plan happened to include the word "security" in its module list.

How it's priced

The module is sold as a per-device add-on, billed monthly with no proration:

  • Business plan: £1.50 per enrolled device, per month
  • Enterprise plan: £1.00 per enrolled device, per month — cheaper per seat, in line with Enterprise's better device-overage rates elsewhere

Billing runs on its own dedicated SecuritySeatBillingScheduler, separate from the general device-seat overage billing that already existed for RMM. Enroll ten devices mid-month, and you're billed for ten devices from the next cycle — no partial-month math to worry about, no surprise mid-cycle line items either.

Why now

Security has been the single most requested "can you also do X" from our own MSP clients for a while, and the honest answer used to be "connect your existing EDR vendor and we'll surface the alerts." That's still true for anyone who wants to keep their existing vendor relationship — the edr connector isn't going anywhere. But plenty of MSPs told us they'd rather have one throat to choke, one invoice, and one agent binary than a coalition of five different vendor tools glued together with API keys.

This module is the start of that: Plenix as a single place where monitoring, patching, remote access, and now protection all live on the same device record, the same audit trail, and the same bill.

What's next

Enrollment and per-device billing are live today. Deeper automated response playbooks (auto-quarantine on detection, policy-driven firewall rule rollout across a device group) are the next milestone — watch this space.