" /> What Security Does My Business Need? Free EDR, MDR, Backup Recommender
Veiledning

Security Stack Recommender: What EDR, MDR, Email Security and Backup Does Your Business Need?

Answer eight questions about your company size, endpoints, servers and locations. Get a recommended EDR, MDR, email security, DNS filtering, mobile security, cloud backup and SIEM stack from the vendors we provision, with an indicative monthly budget and a quotation within one business day.

Oppdatert · sep 2026 By ITSECOPS Gratis · Ingen påmelding

Most businesses buy security tools in the wrong order. They add antivirus, then a backup, then a phishing filter, and only after an incident do they discover the gaps: no 24/7 response, no immutable copy of Microsoft 365, no DNS filtering for the laptops that never come back to the office. This free tool asks eight questions about your company size, endpoints, servers, locations and what you are looking for, then recommends a concrete stack (EDR, MDR, email security, DNS filtering, mobile security, cloud backup, SIEM, identity) from the vendors we provision and manage, with an indicative monthly budget. You can request a formal quotation at the end.

Why now: in August 2026 the Medusa ransomware operation passed 500 victims and was seen exploiting newly disclosed vulnerabilities within 24 hours, and Microsoft patched a maximum-severity Entra ID flaw (CVE-2026-69836) that allowed unauthenticated remote code execution. Both hit companies that had “an antivirus” but no detection and response, no tested backups and no identity hardening. The recommendation below is built to close exactly those three gaps first.

Skip the vendor sales cycle

ITSecOps partners with every industry-standard vendor. Instead of demos and discovery calls with each of them, get a cost-optimised, customised stack at partner pricing directly from our consultants. Use the tool below, or compare vendor prices side by side.

1. Your company2. What you need3. Constraints4. Your stack

Tell us about your environment

Vendors we provision and manage

ITSecOps.cloud partners with every industry-standard security vendor below, so the recommendation is never limited to one product. Because we buy at partner pricing, you get the same licences cheaper than buying direct, and we deploy, tune and monitor them under one monthly price.

How the recommendation logic works

The tool does not sell you everything. It ranks controls by how often they stop real incidents in companies of your size, then fills gaps in this order:

  1. Endpoint detection first. Every profile gets EDR. If you have 50 or more endpoints, any regulated data, a cyber insurance requirement, or nobody watching alerts after 17:00, EDR becomes MDR (24/7 human-led response) because an unattended alert at 02:00 is how most ransomware cases start.
  2. Identity second. Phishing-resistant MFA and conditional access on Microsoft 365 or Google Workspace, because credential theft precedes most intrusions. The August 2026 Entra ID flaw is the reminder that identity is now the perimeter.
  3. Email and DNS third. The two delivery channels for almost every attack. Native Microsoft filtering is kept where it is good enough, and a dedicated layer (Proofpoint, Check Point Harmony Email, Mimecast) is added where the profile justifies it.
  4. Backups that survive the attacker. Immutable, off-tenant copies of Microsoft 365 or Google Workspace, plus server and endpoint backup with tested restores. Microsoft does not back up your tenant for you.
  5. Visibility and people. SIEM or a 24/7 SOC once you pass 100 endpoints or fall under NIS2, CMMC or HIPAA, and awareness training with phishing simulation once you pass 20 users.

Frequently asked questions

What is the difference between EDR and MDR?

EDR is software on each endpoint that detects and can contain suspicious behaviour. MDR is EDR plus a 24/7 team that investigates the alerts, hunts for threats and responds for you. Most SMBs under 50 endpoints can start with EDR if someone internal watches alerts; everyone else should buy MDR.

Do I still need antivirus if I have EDR?

No. Modern EDR products (Sophos Intercept X, Microsoft Defender for Business, SentinelOne, CrowdStrike, Bitdefender GravityZone) include next-generation antivirus. Running a separate legacy antivirus alongside EDR causes conflicts and slows machines.

Does Microsoft 365 include backup?

Microsoft keeps deleted items for a limited retention window, but it is not a backup and Microsoft’s own shared responsibility model says so. A third-party backup (Dropsuite, Acronis, Veeam, Datto SaaS Protection) gives you immutable, point-in-time restores of mailboxes, OneDrive, SharePoint and Teams.

Is DNS filtering the same as web protection?

They overlap. DNS filtering blocks connections to malicious or unwanted domains before a page loads, on any device and network. Web protection inside the endpoint agent inspects the traffic and downloads themselves. Most stacks use both: DNS filtering (Cisco Umbrella, DNSFilter, Cloudflare Gateway) for roaming laptops and the endpoint agent for content inspection.

How accurate is the indicative price?

The ranges are typical list prices per user, endpoint or server per month for the products shown. Your quotation will be lower for bundles and multi-year terms and will include our onboarding and monitoring. We send it within one business day.

Can you supply the licences without managing them?

Yes. Choose “We manage it” in step 3 and we quote licences plus a fixed onboarding fee. Most clients move to the fully managed option once they see the alert volume.

Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?

Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.

Bestill en konsultasjon