EDR and MDR are often discussed as if they're alternatives. They're not. EDR is the tool. MDR is the service that makes the tool useful at 3am on a Sunday.
EDR — Endpoint Detection and Response
Software that sits on each laptop, desktop and server. It records what's happening, detects malicious behaviour and can automatically isolate a compromised machine. Modern EDR replaces legacy antivirus and is the single biggest endpoint security upgrade most SMEs can make.
- What you get: telemetry, detection, response actions, forensics.
- What you don't get: anyone watching the alerts on your behalf.
MDR — Managed Detection and Response
A 24/7 service operated by an external security team. They monitor your EDR (and often more — email, identity, cloud), investigate alerts, respond on your behalf and brief you in plain English.
- What you get: trained analysts, 24/7 coverage, investigation, containment.
- What you don't get: someone else managing your business decisions during an incident.
Side by side
- Tool only (EDR): cheap, but only as good as the person checking the console.
- Tool + in-house SOC: powerful, but typically £300k+/year of fully loaded cost.
- Tool + MDR: 24/7 coverage at a fraction of in-house cost. The default for UK SMEs.
Which do SMEs actually need?
For nearly every UK SME under 250 staff, the answer is EDR delivered as part of an MDR service. Buying EDR alone almost always results in unread alerts, missed detections, and a false sense of security.
Next step
Book a free 30-minute review and we'll show you what EDR + MDR would look like for your environment, with realistic costs.

