EDR is software that watches each endpoint. MDR is that software plus a 24/7 team that investigates and responds for you. XDR is detection that correlates endpoints with identity, email, cloud and network. For a company under 50 endpoints with someone who owns alerts, EDR is enough. For everyone else, and for anyone under NIS2, CMMC, HIPAA or a cyber-insurance questionnaire, MDR (which today includes XDR telemetry) is the right buy. Here is how to decide, with 2026 prices.
Updated September 4, 2026. Two things changed the calculation this summer. Medusa ransomware passed 500 victims in August and now exploits new CVEs within a day of publication, which leaves no time for a weekly alert review. And research published the same month found around 80 percent of ATT&CK techniques in current malware are designed to evade or disable endpoint tools. Software alone is being targeted; a human response layer is the difference.
EDR vs MDR vs XDR at a glance
| EDR | XDR | MDR | |
|---|---|---|---|
| What it is | Agent on endpoints and servers recording behaviour, with detection and containment actions | EDR plus identity, email, cloud and network telemetry correlated in one console | EDR or XDR operated by a 24/7 security team that investigates, hunts and responds |
| Who watches it | You | You | The provider, around the clock |
| Response | Manual, when someone sees the alert | Manual or automated playbooks you build | Human-led within minutes, under agreed rules of engagement |
| Typical products | Microsoft Defender for Business, Sophos Intercept X, SentinelOne Singularity, CrowdStrike Falcon, Bitdefender GravityZone | Sophos XDR, Microsoft Defender XDR, SentinelOne Singularity XDR, CrowdStrike Falcon Insight XDR | Sophos MDR, Huntress, Blackpoint, SentinelOne Vigilance, CrowdStrike Falcon Complete, ITSecOps MDR |
| 2026 list price per device / month | $3 to $10 | $5 to $15 | $8 to $22 |
| Best for | Under 50 endpoints with an internal owner | Internal security team wanting one console | Everyone without a 24/7 team; regulated and insured businesses |
When EDR alone is enough
- Fewer than about 50 endpoints and no servers holding regulated data.
- A named person who checks the console daily and can isolate a device the same day.
- No cyber-insurance or compliance requirement for 24/7 monitoring.
- Microsoft 365 Business Premium already in place, so Defender for Business costs nothing extra.
In that case deploy EDR properly (tamper protection, attack surface reduction, removal of legacy antivirus) and revisit MDR when you grow. Our EDR service covers deployment at partner pricing.
When you need MDR
- 50 or more endpoints, or any servers holding customer, financial or health data.
- NIS2, CMMC, HIPAA, ISO 27001 or SOC 2 obligations that expect continuous monitoring.
- A cyber-insurance renewal asking for EDR “with 24/7 monitoring and response”.
- No one available at 02:00 on a Sunday, which is when encryption is scheduled.
- An incident in the last two years where you learned about it from a customer or a ransom note.
See what ITSecOps MDR includes and compare providers in Top MDR providers for SMBs and MSPs.
Where XDR fits
XDR is not a third choice between EDR and MDR; it describes what the detection covers. Since credential theft precedes most intrusions, any serious service in 2026 correlates endpoint events with identity sign-ins, email and firewall logs. Sophos, Microsoft, SentinelOne and CrowdStrike all sell XDR tiers, and ITSecOps MDR ingests those sources by default. If you have an internal security engineer and want the console yourself, buy XDR. If you want the outcome without the headcount, buy MDR.
What about a SIEM?
A SIEM adds long-term retention and compliance reporting across every system, which matters once you pass roughly 100 endpoints or fall under NIS2 or CMMC. It does not replace MDR; it feeds it. See SIEM as a Service pricing.
Price comparison
List prices for each product are in the cybersecurity price comparison. Because ITSecOps partners with every vendor above, the quote you get from us is at partner pricing, below the vendor website, and includes deployment. The Security Stack Recommender gives you the EDR-or-MDR decision and an indicative budget in two minutes.
Frequently asked questions
Is MDR worth it for a small business?
Above about 25 endpoints, yes. A 50-endpoint company pays roughly $500 to $800 per month for MDR; the average ransomware outage for an SMB costs far more in downtime alone, before any ransom.
Can I upgrade from EDR to MDR later?
Yes, and on the same agent. Sophos, Microsoft, SentinelOne and CrowdStrike all offer MDR on top of their EDR licence, so nothing is reinstalled.
Does MDR replace my antivirus?
Yes. Every MDR service includes next-generation antivirus in the agent. Running a separate antivirus alongside it causes conflicts.
Is XDR the same as SIEM?
No. XDR correlates security telemetry for detection with short retention; a SIEM stores all logs for retention, search and compliance reporting.
What does cyber insurance actually require?
Most 2026 questionnaires ask for EDR on all endpoints, MFA on email and remote access, offline or immutable backups, and increasingly “24/7 monitoring and response”, which is MDR.