Skip to main content
Cyber Resilience6 min readNew

EDR vs XDR vs MDR: What Small Businesses Actually Need

"Three acronyms, one practical question: which layer keeps a 10-person business safe without wasting the budget? What each one does, what you already own, and what is missing."

Author

Lior Refael

Published

Aug 5, 2026

Back to Articles

You started seeing EDR, XDR and MDR in every security vendor's pitch deck. Your IT provider mentioned one of them. A LinkedIn post said your business is at risk without all three. Nobody explained what any of them actually do.

The differences do matter. For a small business, the answer to which one you need is simpler than the marketing suggests - and if you are on Microsoft 365 Business Premium, you have already bought most of it.

What each one actually does

EDR (Endpoint Detection and Response) is technology. It sits on your laptops, desktops and servers and watches process behaviour rather than matching files against a signature list. When something looks wrong, it alerts, and it can isolate the device on its own[1]. The catch is that somebody has to read those alerts.

XDR (Extended Detection and Response) is also technology. It does what EDR does and correlates it with email, identity and cloud app signals, so the picture becomes "this mailbox received a phishing message, then this identity signed in from a new country, then this laptop tried to disable protection" instead of three unrelated alerts[2].

MDR (Managed Detection and Response) is a service, not a product. Someone else watches the alerts, investigates them and responds. MDR runs on EDR or XDR underneath; what you are buying is the human layer on top.

The distinction that matters: EDR and XDR are tools. MDR is someone using those tools for you.

What each layer actually does

Capability grid comparing EDR, XDR, MDR and SIEM across six capabilities. EDR and XDR cover detection and automated containment and are included with Business Premium; only MDR provides a person reviewing alerts out of hours; only SIEM provides long-term log retention.
CapabilityEDRXDRMDRSIEM
Detects suspicious behaviour on devicesIncludedIncludedIncludedLimited or extra cost
Correlates email, identity and endpoint signalsNot availableIncludedIncludedLimited or extra cost
Contains a device automaticallyIncludedIncludedIncludedNot available
A person reviews alerts outside business hoursThe gap in most small businessesNot availableNot availableIncludedNot available
Long-term log retention for auditNot availableLimited or extra costLimited or extra costIncluded
Included with Microsoft 365 Business PremiumIncludedIncludedNot availableNot available
  • Included
  • Limited or extra cost
  • Not available

The row that separates a tool from a service is the one about who reads the alert.

TechSuit view, based on small-business deployments

The honest baseline for a 10-person business

Most small businesses do not need to buy all three. Microsoft Defender for Business is included in Microsoft 365 Business Premium and provides endpoint detection, attack surface reduction and automated remediation across Windows, macOS, iOS and Android[1]. Business Premium is listed at USD 22 per user per month on annual commitment[3].

That is your EDR layer, and Defender XDR correlation across mail and identity comes with it. It is already running if your devices are enrolled through Intune - and "already running" is the part worth checking, because a licence that was never deployed protects nothing.

On detection quality, use the independent labs rather than any vendor's own claim. AV-TEST publishes recurring business endpoint results, and Microsoft's business endpoint product has sat at the top of that table for protection alongside the specialist vendors[4].

LayerWhat it isTypical monthly cost, 10 people
Microsoft Defender for BusinessEDR, included in M365 Business PremiumBundled in the M365 licence
Defender XDRCross-signal correlation across mail, identity, endpointIncluded with Business Premium
Standalone EDR (specialist vendor)Detection engine only, no monitoringEUR 50-90
Managed detection serviceSomeone watches and respondsEUR 70-250
SIEM (log aggregation)Compliance-grade log retentionEUR 200-400+

Ranges are from our own quoting work across small businesses in Israel and Europe, not a published price list. The licence lines are published; the service lines move with headcount and provider.

When to add MDR

MDR makes sense when nobody in the business is a security person. Most 10-person companies are exactly that. The question is not "do I need MDR" - it is "who reads the alert at 02:00 on a Sunday".

If the answer is "nobody", that is the gap. Detection without response is a smoke alarm in an empty house. NIST's small-business guidance puts detection and response together for this reason: the Respond and Recover functions are not optional extras on top of Detect[5]. CISA's performance goals are blunter still - they expect an organisation to have a named owner for security alerting and a documented response, not just a tool[6].

If your IT provider says MDR is included, verify it. Plenty of providers install an EDR agent and never look at the console again.

What about SIEM?

A SIEM collects logs from everything and correlates them. It is powerful, and it is built for organisations with analysts. Microsoft Sentinel bills on data ingested and retained, so cost tracks log volume rather than headcount[7].

For a 10-person business a SIEM usually produces dashboards nobody opens. Unless an auditor specifically demands centralised log retention, that budget belongs on the response layer instead.

Scaling up: 25 people

At 25 people the maths shifts. More endpoints, more cloud apps, more identities - and threats that cross those boundaries, which is where correlation earns its keep. Credential abuse remains the most pervasive technique in breach chains, and it never shows up as a single suspicious file on a single laptop[8].

ComponentMonthly cost, 25 people
M365 Business Premium (Defender EDR + XDR + Intune)EUR 500-550
Managed detection add-onEUR 200-250
TotalEUR 700-800

At this size the monitoring layer stops being optional. Twenty-five endpoints generate more alerts than a non-security person will triage, and the ones that matter arrive at inconvenient hours.

What is not in these numbers

  1. Incident response. Some managed providers include it; some bill it separately at an hourly rate when you are least able to negotiate. Ask before you sign.
  2. Compliance evidence. Defender and Intune logs cover most of what a NIS2 or ISO 27001 auditor asks for. A SIEM is only needed when centralised retention is explicitly required.
  3. Configuration. A badly configured EDR is not much better than none. Attack surface reduction rules and automated investigation have to be turned on, not just licensed[1].
  4. Identity. Conditional access and MFA sit underneath all of this. Endpoint tooling does not stop a valid login with a stolen password[8].

Country notes

Israel. Defender for Business ships with the same Business Premium licence sold locally, and most Israeli providers use it as the base layer with a monitoring service on top. Portal and support coverage in Hebrew varies by MDR vendor - worth asking before you commit.

Europe. NIS2 does not name products. Article 21 requires incident handling and monitoring as risk management measures, which a managed detection service satisfies more cleanly than a detection tool nobody watches[9].

Spain. The national transposition tracks ENS control families, which are specific about endpoint protection and event monitoring - again, detection plus response, not detection alone.

What to do with this

  1. Confirm whether you have Microsoft 365 Business Premium. If you do, you own the EDR and XDR layers already.
  2. Open Intune and check devices actually report as compliant with Defender policies active. Licensed is not the same as deployed.
  3. Ask your provider, in writing: who reads our security alerts outside business hours, and what do they do next?
  4. Buy a SIEM only when a framework requires it. Otherwise spend that money on the response layer.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. What is Microsoft Defender for Business? (opens in a new tab)

    Microsoft Learn · 2026

    What the included EDR layer covers: behavioural detection, attack surface reduction, automated investigation and remediation across Windows, macOS and mobile.

  2. Microsoft Defender XDR overview (opens in a new tab)

    Microsoft Learn · 2026

    How XDR correlates endpoint, email, identity and cloud app signals into a single incident rather than separate alerts.

  3. Compare All Microsoft 365 Business Plans (opens in a new tab)

    Microsoft · 2026

    Published Business Premium list price on annual commitment, the licence that carries Defender for Business.

  4. Business Windows Client test results (opens in a new tab)

    AV-TEST Institute · 2026

    Independent recurring protection scores for business endpoint products, used instead of any vendor's own detection claim.

  5. NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide (SP 1300) (opens in a new tab)

    NIST · 2024

    Detect, Respond and Recover treated as one set of functions for a small business, not detection as a standalone control.

  6. Cross-Sector Cybersecurity Performance Goals (opens in a new tab)

    CISA · 2026

    Baseline expectation of a named owner for security alerting and a documented response process, not just a deployed tool.

  7. Plan costs and understand Microsoft Sentinel pricing and billing (opens in a new tab)

    Microsoft Learn · 2026

    Sentinel bills on data ingested and retained, so SIEM cost tracks log volume rather than headcount.

  8. 2026 Data Breach Investigations Report (opens in a new tab)

    Verizon Business · 2026

    Credential abuse remains the most pervasive technique across breach chains, which endpoint tooling alone does not address.

  9. Directive (EU) 2022/2555 (NIS2) (opens in a new tab)

    EUR-Lex · 2022

    Article 21 risk management measures covering incident handling and monitoring, without naming specific products.

Figures last checked 5 August 2026

When did you last test your endpoint security?

Book a 30-minute call. We will review what is installed, what is actually monitored, and where the gaps are - no jargon, no sales pressure.