Skip to main content
MDR for small business

EDR is the software.
MDR is somebody answering.

If your endpoint tool fires at 2am on a Sunday and the honest answer is that it waits until Monday, the tool is working. The gap is operational, and that is what MDR is for.

The short answer

EDR is the detection software running on your laptops and servers. MDR is that software plus the people who investigate what it finds and act on it.

For a company with no security team the distinction is the entire purchase. EDR that nobody watches produces alerts nobody reads, which is a license cost rather than a defense.

The complication is that "managed" is sold by everyone and means at least three different things: installed for you, watched for you, or operated for you. Only the third one answers at 3am. Ask which one you are being quoted, because the price difference between them is smaller than the outcome difference.

The word that hides things

Three things vendors mean
by managed.

01

Managed as in installed

A reseller deploys the agent, sets a policy, and hands you the console. Genuinely useful, and it is what many small companies actually have. But nobody is watching, so at 3am it behaves exactly like unmanaged software.

02

Managed as in monitored

Somebody watches the console and forwards you what looks important, usually with a severity label attached. Better. But the decision and the action are still yours, at whatever hour the alert arrives.

03

Managed as in operated

Analysts investigate what fired, decide whether it is real, and contain it: isolating the host, disabling the account, revoking the token. You are told what happened and what was done. This is the one worth paying for, and it is what ThreatDefend™ is.

None of the three is dishonest. They are different products at different prices, and the first two are the right answer for some buyers. The problem is that all three are sold using the same word, so a quote comparison frequently is not comparing the same thing at all.

The part most entry tiers skip

Identity is how
you actually get hit.

Endpoint coverage is table stakes and most packages have it. Identity coverage is the thing that is quietly missing at the entry tier, and it is where smaller organizations are most often compromised: a password reused somewhere else, a session token stolen, an MFA prompt approved at the wrong moment because it was the fourth one that hour.

None of that trips an endpoint sensor. The attacker never installs anything. They log in, which is why the detection has to be watching accounts rather than processes.

ThreatDefend™ includes full ITDR from Essential: dark web exposure, impossible travel, MFA fatigue, business email compromise, OAuth abuse and lateral movement across Active Directory, Entra ID and Microsoft 365. When you compare quotes, check which tier the other one puts identity in. Frequently it is the one above the one you were shown.

Sequence

What to buy
and in what order.

First, endpoint detection that somebody operates. Not software plus hope. If you buy one thing, buy the one where a human answers.

Then identity. Or ideally at the same time, since it is included at the entry tier here rather than being a later upgrade.

A SIEM later, and only if you need one. Compliance or a genuinely multi-system estate makes it necessary. Otherwise it is an expense that buys a dashboard, and we will say so. The honest version of that question is on its own page.

Start with evidence

A domain is all we need to begin.

ThreatAssess™ is a free external attack surface assessment. No agent, no credit card. See what an attacker sees today, and price the conversation against what is actually there.

Free · no credit card

Start your free assessment

All we need is a domain. No agent to install.

// work email required · no credit card · results within one business day

Questions

The ones people
actually ask.

What is the difference between EDR and MDR for a small business?

EDR is the software on your endpoints that detects and can act. MDR is EDR plus the people who watch it and respond. For a company with no security team the distinction is the entire purchase: EDR without somebody operating it produces alerts nobody reads, which is a license cost rather than a defense.

Do we need MDR if we already have antivirus or EDR?

It depends on what happens when your EDR fires at 2am on a Sunday. If the honest answer is that it waits until Monday, the tool is doing its job and the gap is operational rather than technical. That gap is what MDR is for.

Does MDR replace our IT provider?

No. Most companies we protect have an MSP, and the cleanest arrangement is usually that they keep the relationship while we run the SOC behind them. We never compete with our partners for their clients. If you have no provider, we can work with you directly.

What should MDR include for a company of 25 to 250 people?

Endpoint detection deployed and tuned, identity coverage across Active Directory, Entra ID and Microsoft 365, and analysts who contain rather than escalate. Identity matters more than most entry-tier packages admit: a stolen session token does not trip an endpoint sensor, and accounts are how smaller organizations are most often compromised.

Is MDR worth it for a small business, or is it enterprise overkill?

It is worth it when you cannot staff the hours. Covering every hour of a year takes five or more analysts, which no 150-person company solves by hiring. What is genuinely overkill for an SMB is buying a platform and no operator, which is the more common mistake.