You are currently viewing MDR vs EDR: Understanding the Difference

MDR vs EDR: Understanding the Difference

You already pay for an EDR agent. Every laptop has it, the dashboard glows green, and the invoice lands every month. So why does your cyber insurer, your auditor, or your biggest client keep asking whether you have MDR?

Fair question. The two products sound like the same thing wearing different letters, and vendor websites do very little to fix that.

Here is the plain version, from someone who quotes both every week.

Shopping for managed detection and response? Skip the vendor calls — we’ll get you real quotes from 3 vetted providers in 24 hours. Free, no obligation. Get my free shortlist → How we make money →

The Short Answer

MDR provides 24/7 monitoring and response by trained analysts, while EDR only detects threats and generates alerts that may go unaddressed. MDR costs $15 to $25 per device monthly, compared to EDR’s $8 to $15 range, but offers critical real-time action on alerts. For small businesses, MDR ensures alerts are seen and acted upon quickly, preventing potential breaches like ransomware attacks. Without MDR, alerts may sit unopened for days, allowing attackers to escalate incidents undetected.

MDR vs EDR: the short answer

Endpoint detection and response is a product you buy. Managed detection and response is that product plus a staffed team watching the console around the clock and acting on what they find. EDR spots the suspicious process. A human at an MDR provider decides what to do about it at 3am on a Sunday.

Both approaches put an agent on every laptop, server, and desktop you own. Each one watches behavior rather than matching a list of known virus signatures. The gap sits entirely in who reads the alerts, and how fast they move.

So if you already pay for an agent, the real question is not which acronym wins. Your question is whether anyone at your company will see the alert that matters, at the hour it lands. If the honest answer is no, you are paying for a smoke detector in an empty house.

The alert nobody reads at 2am

Here is how this fails in practice. Your EDR flags a credential dumping tool on a finance laptop at 2:14am Saturday. It fires an email into a shared inbox. Nobody opens that inbox until Monday at 9. By then the attacker has jumped to a file server, deleted your backups, and started encrypting.

Nothing in that story is a product failure. The tool did its job. It saw the behavior, wrote the alert, and told someone. Then a person failed to read the message for 55 hours.

Attackers plan around this. Ransomware crews fire on Friday nights, long weekends, and holidays for exactly that reason. Small companies do not staff a night shift, and the criminals price that gap into their timing.

MDR solves one narrow problem: it puts a trained human on the other end of that 2:14am alert. That is what the extra money buys. Everything else in the pitch deck is secondary.

Side by side: what each one actually covers

This table is roughly how I lay it out on a first call.

  EDR MDR
Who watches the console Your IT person, or nobody The provider’s SOC analysts
Coverage hours Business hours at best 24/7/365, holidays included
What happens on a real alert An email and a dashboard flag A human triages, then calls you or acts
Containment You isolate the host, if you are awake The analyst isolates it, often in minutes
False positive tuning Yours to do, forever The provider’s job, written into the contract
Threat hunting Rare Usually monthly or quarterly
Reporting A raw console you have to interpret A written summary for auditors and insurers
Typical small business price $8 to $15 per device per month $15 to $25 per device per month
Best fit You employ someone who watches security daily You do not

What “response” means in your contract

Response is the word vendors stretch the furthest. Three very different versions show up in real contracts, and the price tag rarely tells you which one you signed.

Notify only. The provider emails or phones you with a finding and a recommendation. You do the actual work. Plenty of cheap plans stop right here and still market themselves as MDR.

Remote containment. An analyst pulls the machine off the network, kills the malicious process, quarantines the file, and disables the compromised account. Most buyers assume this is what they bought. Roughly half of them are wrong.

Full incident response. Containment plus forensics, root cause, help with insurer and regulator notifications, and a rebuild plan. Some providers include a block of retainer hours. Others charge emergency rates on the one day you cannot walk away and shop around.

Ask which tier you are buying before you sign anything. Then ask the follow-up that really matters: who authorizes an analyst to yank the CEO’s laptop off the network at 2am, and does that authorization already exist in writing? A team that has to wait for your callback is a team that waits for hours.

Want to skip the line? Browse vetted managed detection and response services and order on your terms. Self-Order in the Marketplace →

The 24/7 staffing math for a small business

Run the numbers on doing this in house. A week holds 168 hours. One analyst covers about 40 of them. Genuine round the clock coverage therefore needs four to five trained people, before you count vacation, sick days, certifications, and turnover.

Now compare that to a quote. Fifty devices at $20 per device per month works out to $12,000 a year. That will not hire one junior analyst, let alone five, and the single analyst you could afford cannot work nights alone forever.

Which is why the category exists at all. Renting a slice of someone else’s SOC is the only realistic path to 3am coverage for a 50 person company. I almost never tell a business under 200 people to build the function internally.

Where XDR fits in all this

XDR stretches the same idea past the endpoint. Instead of watching only laptops and servers, it pulls signals from email, identity, cloud apps, and the network into one timeline, so an odd login in Microsoft 365 and a strange process on a laptop add up to one story instead of two ignored alerts.

Here is the part the marketing blurs. XDR is a product, exactly like EDR. MDR is a service. Managed XDR just means a provider watching a wider set of signals for you, and most of the market has drifted that way. We break the components down further on our managed detection and response page.

One practical test: ask every bidder whether identity and email telemetry come with the base price or cost extra. Most small business breaches start with a stolen password, not a dropped file, so endpoint-only coverage leaves your front door unwatched. If compliance reporting drives your project more than endpoint coverage does, compare managed SOC providers as well, since their log retention and evidence packages tend to go deeper.

What a fair quote looks like

These are the bands I see on real small business quotes right now.

  • EDR: $8 to $15 per device per month, agent and console only.
  • MDR: $15 to $25 per device per month, agent plus 24/7 human monitoring and some level of containment.

A few things push a quote up or down. Seat minimums come first: many providers set a floor of 25 or 50 devices, so a 12 person shop pays the 25 seat rate anyway. Servers usually carry a higher per unit price than workstations. Log retention matters too, because 30 days costs far less than the 12 months an auditor or insurer may want to see.

Term length swings the number by a couple of dollars per device, and onboarding fees of $1,000 to $3,000 show up on maybe half of the quotes I review. Treat anything advertised as MDR under $12 per device with suspicion. At that price you are almost always buying notify-only alerting with a monthly PDF attached.

How to choose an MDR provider

Questions to ask on the first call

  • Who staffs the SOC at 2am, your own employees or a subcontracted third party?
  • Can an analyst isolate a host without waiting for my approval, and where is that permission documented?
  • What is your mean time to respond, in minutes, and will you put it in the agreement?
  • Does the price include email, identity, and cloud signals, or endpoint only?
  • Who owns the EDR licenses, me or you?
  • Is incident response included, capped at some number of hours, or billed separately?

What happens if you leave

Exit terms decide how trapped you feel in year two, and almost nobody asks about them in year one. Find out whether the EDR tenant belongs to you or to the provider. If the licenses sit under their account, your agents can go dark the day the contract ends, and you rebuild endpoint coverage from scratch during the transition.

Get three commitments in writing: your historical logs exported in a usable format, a defined retention window after termination, and 30 to 60 days of transition help. Also confirm how the provider removes its own admin access from your environment on the way out. A vendor that hesitates on any of those points is telling you something useful.

When plain EDR is enough

Sometimes the cheap option is the right option. Under roughly 15 devices, with no regulated data, no card payments, and no client contracts carrying security clauses, a good EDR plus enforced MFA and tested backups is a defensible position. MFA alone blocks about 99% of account compromise attacks, and backups you have actually restored beat any amount of monitoring you ignore.

That changes the moment you hold client data, process cards, or sign a customer agreement with breach notification terms. IBM puts the average breach at $4.4M globally across all company sizes, and notify-only alerting stops looking clever at that number.

We hold agreements with 78 providers that sell endpoint security, and I will say this plainly: we do not care which one you choose. Vendors pay us, you never do, so the incentive is a match that sticks rather than a logo we like. If you want a starting list of names, our MDR provider roundup covers the ones worth a call. Buyers driven here by an audit should also read how SOC 2 compliance treats monitoring evidence.

Frequently Asked Questions

Do I need MDR if I already have EDR?

Only if nobody watches your EDR console outside business hours. EDR without a monitor is a camera recording to a screen in an empty room. Companies with a dedicated security person can run EDR alone for a while. Everyone else is buying detection with no response attached, which is the half that stops a Saturday night ransomware run from becoming a Monday morning shutdown.

Is MDR the same thing as a managed SOC?

They overlap heavily but sell differently. MDR centers on endpoint and identity telemetry with containment built in, priced per device. A managed SOC centers on log collection across your whole environment, priced per user or per data volume, and it leans toward compliance evidence. Many providers now sell both under one contract, so compare the actual scope rather than the label.

Does MDR include incident response?

Sometimes, and the difference costs real money. Basic plans contain the threat and hand you a report. Full plans add forensics, root cause analysis, and support for insurer and regulator notifications, either bundled or as a retainer with set hours. Ask for the specific hour count and the hourly rate beyond it before you sign, not while your servers sit encrypted.

How fast should an MDR provider respond?

Look for triage inside 15 minutes and containment inside an hour for critical alerts, backed by a written commitment. Providers that will not commit to numbers usually have a reason. Also check whether the clock starts when the alert fires or when an analyst opens the ticket, because that wording can quietly turn a 15 minute promise into a 90 minute reality.

Can MDR replace my antivirus?

Yes, in almost every case. Modern EDR agents include the prevention layer that traditional antivirus provided, so running both wastes money and creates conflicts that slow machines down. Confirm the agent covers your operating systems, including Macs and any Linux servers, then retire the old product once the new one runs clean across every device.

Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].

Get a Tailored MDR Shortlist

3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.

Get a Quote →
Get It Right the First Time

Want help getting your endpoint protection right?

Defend My Business helps SMBs cut through the marketing and get their endpoint protection right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our managed detection & response or talk it through with an advisor.

Book a free call with a DMB advisor →

Russ Herman

Russ Herman is the founder of Defend My Business, a cybersecurity advisory for small and mid-sized businesses. He works with the DisruptionIO partner network of 400+ vetted providers across cybersecurity, connectivity, cloud, and disaster recovery to help SMB owners and IT leaders cut through vendor noise with plain-English guidance and 24-hour shortlists from a pre-vetted ecosystem.

Leave a Reply