MDR vs. EDR for Small Business: Who Operates It
EDR is endpoint security technology. MDR is a managed service that investigates and responds around it. The real question is who watches the alerts at 3 a.m.
Endpoint detection and response (EDR) is software that watches laptops, desktops, and servers for signs of an attack and can contain a threat on the device. Managed detection and response (MDR) is a service in which a provider's analysts monitor, investigate, and respond to threats across your environment, usually using EDR as one of its data sources.
That makes this less a product comparison than an ownership question. EDR gives you detection and containment tools. MDR gives you people and a process around those tools. If you want the basics of each first, read what EDR is and how MDR works for small businesses.
MDR vs. EDR at a glance
| Decision area | EDR | MDR |
|---|---|---|
| What it is | Endpoint security technology | A managed security operations service |
| Primary job | Collect endpoint activity, detect suspicious behaviour, contain devices | Monitor, investigate, escalate, and respond |
| Scope | Devices with the agent installed | Endpoints plus other covered sources, such as email, identity, and cloud apps |
| Who reads the alerts | Your team | The provider's analysts, within the contracted scope |
| After-hours coverage | Only if you staff it | Defined in the service terms |
| Response | Tool capability, run by you | Defined actions taken or coordinated by the provider |
| Typical cost driver | Per-device licensing plus staff time | Service fee, usually tied to coverage scope |
What EDR does well, and where it stops
An EDR agent records process activity, file changes, network connections, and logins on each device. It flags behaviour that looks like an attack and can isolate a machine from the network. The NIST glossary definition of EDR describes the same core functions: recording endpoint activity, detecting suspicious behaviour, and supporting investigation and response.
EDR is a strong control when someone runs it. The limits are operational, not technical:
- Alerts need a reader. A tool that raises an alert at 2 a.m. has not protected anything until a person looks at it. The post on EDR alert fatigue explains how quickly unreviewed alerts pile up.
- Triage takes skill. Deciding whether an alert is a false positive or the start of an intrusion takes practice and context.
- Coverage stops at the device. EDR sees the endpoints it is installed on. It does not see a hijacked Microsoft 365 mailbox or a malicious sign-in from another country unless other sources feed it.
- Response needs authority. Someone must be allowed to isolate a laptop, disable an account, or wake the owner.
What MDR adds
MDR is the operating layer. A provider's analysts review alerts around the clock, investigate what the alert means, decide whether it is real, and carry out or coordinate the response agreed in the contract. MDR also typically brings in sources beyond the endpoint, so an attack that starts with a phishing email and a stolen password is visible as one story, not three separate alerts.
Definitions vary by vendor. Some MDR services run on the customer's existing EDR. Others bring their own. Some include a SIEM. The label tells you less than the scope in the contract, which is why the MDR vs. SIEM comparison and the full MDR guide both push buyers toward asking about sources, response actions, and data access.
Managed EDR sits in the middle
Many providers sell "managed EDR": they run the endpoint tool and watch its alerts, but investigation beyond the endpoint may be limited. MDR usually widens the scope to identity, email, and cloud sources and commits to defined response work. The managed EDR vs. in-house EDR comparison covers that boundary in detail, and the managed EDR SLA checklist lists what to confirm in writing. Ask any provider which of the two you are actually buying.
A 3 a.m. alert, step by step
This is a generic illustration, not a client case. Suppose a user's laptop starts running an unfamiliar script at 3 a.m.
With EDR only. The agent flags the behaviour and may block it automatically. The alert waits in a console. If nobody on your team is watching, the first human review happens when someone logs in the next morning. If the activity was an intrusion, the attacker has had hours.
With MDR. An analyst sees the alert within minutes, checks whether the same account signed in from an unusual place, looks for the same behaviour on other devices, and isolates the laptop if the evidence supports it. The provider then contacts you with what happened and what was done. Which of those steps happen automatically, and which need your approval, should be set in advance.
What you still own with MDR
MDR does not remove every internal duty. Settle these before you sign:
| Duty | Questions to settle |
|---|---|
| Agent deployment and health | Who installs and updates agents, and who is told when a device stops reporting? |
| Response approval | Which actions can the provider take on its own, and which need your sign-off? |
| After-hours contact | Who answers when the provider calls, and what is the escalation order? |
| Business context | How does the provider learn which systems and people are critical? |
| Remediation | Who rebuilds a device, resets credentials, and fixes the root cause? |
For the escalation and recovery side, see MDR and business continuity.
How to choose
Choose EDR you run yourself when you have a security person or IT team who can review alerts daily, respond at night and on weekends, and keep detections tuned. The product alone is not enough; the staffing is the cost.
Choose MDR when the gap is continuous analyst coverage, alert investigation, and accountable response, and you do not have a team to provide them. This is the common position for businesses without an internal security operations function.
Choose both only if the roles are clear: for example, you keep your own endpoint tool for policy reasons and add an MDR provider that works from it. Confirm that the provider can operate on the tool you already own, and who pays for what.
If your question is about replacing an older endpoint product instead, EDR vs. antivirus and EDR vs. EPP vs. XDR cover that decision.
Questions to ask before you buy
Ask an EDR vendor:
- Who reviews alerts outside business hours?
- Which response actions can run automatically, and which need a person?
- What does the agent not see?
Ask an MDR provider:
- Does the service run on our existing EDR, or does it require its own?
- Which sources are covered beyond endpoints, and who sets up the integrations?
- What response actions are included, and what is the escalation path?
- What happens to our data and detection content if we leave?
QuantM MDR is a managed service covering endpoint, email, Microsoft 365 identity, and SaaS monitoring, with QuantM operating the monitoring and response. See the MDR service page, or start with a Microsoft 365 posture review to see where your current coverage has gaps. To talk it through, contact the QuantM team.
FAQ
Is MDR better than EDR?
They do different jobs. EDR is the endpoint technology. MDR is the service that operates detection and response, often on top of EDR. The better fit depends on whether you have people to run the tool.
Does MDR include EDR?
Often, but not always. Some MDR services bundle an endpoint agent, others work from the EDR you already own. Confirm which model applies and what happens to the agent if you cancel.
Can a small business run EDR without MDR?
Yes, if someone reviews alerts every day and can respond after hours. Without that owner, alerts go unread, which is the main reason small teams add a managed service.
What is the difference between MDR and managed EDR?
Managed EDR usually means a provider operates the endpoint tool and its alerts. MDR usually adds sources beyond the endpoint, such as identity and email, and a defined investigation and response commitment. Providers use the two labels inconsistently, so read the scope.
Do I need both MDR and EDR?
You need endpoint detection and containment capability and someone operating it. MDR can supply both, or supply the operating layer on top of an EDR tool you keep.