You started seeing EDR, XDR and MDR in every security vendor's pitch deck. Your IT provider mentioned one of them. A LinkedIn post said your business is at risk without all three. Nobody explained what any of them actually do.
The differences do matter. For a small business, the answer to which one you need is simpler than the marketing suggests - and if you are on Microsoft 365 Business Premium, you have already bought most of it.
What each one actually does
EDR (Endpoint Detection and Response) is technology. It sits on your laptops, desktops and servers and watches process behaviour rather than matching files against a signature list. When something looks wrong, it alerts, and it can isolate the device on its own[1]. The catch is that somebody has to read those alerts.
XDR (Extended Detection and Response) is also technology. It does what EDR does and correlates it with email, identity and cloud app signals, so the picture becomes "this mailbox received a phishing message, then this identity signed in from a new country, then this laptop tried to disable protection" instead of three unrelated alerts[2].
MDR (Managed Detection and Response) is a service, not a product. Someone else watches the alerts, investigates them and responds. MDR runs on EDR or XDR underneath; what you are buying is the human layer on top.
The distinction that matters: EDR and XDR are tools. MDR is someone using those tools for you.
The honest baseline for a 10-person business
Most small businesses do not need to buy all three. Microsoft Defender for Business is included in Microsoft 365 Business Premium and provides endpoint detection, attack surface reduction and automated remediation across Windows, macOS, iOS and Android[1]. Business Premium is listed at USD 22 per user per month on annual commitment[3].
That is your EDR layer, and Defender XDR correlation across mail and identity comes with it. It is already running if your devices are enrolled through Intune - and "already running" is the part worth checking, because a licence that was never deployed protects nothing.
On detection quality, use the independent labs rather than any vendor's own claim. AV-TEST publishes recurring business endpoint results, and Microsoft's business endpoint product has sat at the top of that table for protection alongside the specialist vendors[4].
| Layer | What it is | Typical monthly cost, 10 people |
|---|
| Microsoft Defender for Business | EDR, included in M365 Business Premium | Bundled in the M365 licence |
| Defender XDR | Cross-signal correlation across mail, identity, endpoint | Included with Business Premium |
| Standalone EDR (specialist vendor) | Detection engine only, no monitoring | EUR 50-90 |
| Managed detection service | Someone watches and responds | EUR 70-250 |
| SIEM (log aggregation) | Compliance-grade log retention | EUR 200-400+ |
Ranges are from our own quoting work across small businesses in Israel and Europe, not a published price list. The licence lines are published; the service lines move with headcount and provider.
When to add MDR
MDR makes sense when nobody in the business is a security person. Most 10-person companies are exactly that. The question is not "do I need MDR" - it is "who reads the alert at 02:00 on a Sunday".
If the answer is "nobody", that is the gap. Detection without response is a smoke alarm in an empty house. NIST's small-business guidance puts detection and response together for this reason: the Respond and Recover functions are not optional extras on top of Detect[5]. CISA's performance goals are blunter still - they expect an organisation to have a named owner for security alerting and a documented response, not just a tool[6].
If your IT provider says MDR is included, verify it. Plenty of providers install an EDR agent and never look at the console again.
What about SIEM?
A SIEM collects logs from everything and correlates them. It is powerful, and it is built for organisations with analysts. Microsoft Sentinel bills on data ingested and retained, so cost tracks log volume rather than headcount[7].
For a 10-person business a SIEM usually produces dashboards nobody opens. Unless an auditor specifically demands centralised log retention, that budget belongs on the response layer instead.
Scaling up: 25 people
At 25 people the maths shifts. More endpoints, more cloud apps, more identities - and threats that cross those boundaries, which is where correlation earns its keep. Credential abuse remains the most pervasive technique in breach chains, and it never shows up as a single suspicious file on a single laptop[8].
| Component | Monthly cost, 25 people |
|---|
| M365 Business Premium (Defender EDR + XDR + Intune) | EUR 500-550 |
| Managed detection add-on | EUR 200-250 |
| Total | EUR 700-800 |
At this size the monitoring layer stops being optional. Twenty-five endpoints generate more alerts than a non-security person will triage, and the ones that matter arrive at inconvenient hours.
What is not in these numbers
- 1Incident response. Some managed providers include it; some bill it separately at an hourly rate when you are least able to negotiate. Ask before you sign.
- 2Compliance evidence. Defender and Intune logs cover most of what a NIS2 or ISO 27001 auditor asks for. A SIEM is only needed when centralised retention is explicitly required.
- 3Configuration. A badly configured EDR is not much better than none. Attack surface reduction rules and automated investigation have to be turned on, not just licensed[1].
- 4Identity. Conditional access and MFA sit underneath all of this. Endpoint tooling does not stop a valid login with a stolen password[8].
Country notes
Israel. Defender for Business ships with the same Business Premium licence sold locally, and most Israeli providers use it as the base layer with a monitoring service on top. Portal and support coverage in Hebrew varies by MDR vendor - worth asking before you commit.
Europe. NIS2 does not name products. Article 21 requires incident handling and monitoring as risk management measures, which a managed detection service satisfies more cleanly than a detection tool nobody watches[9].
Spain. The national transposition tracks ENS control families, which are specific about endpoint protection and event monitoring - again, detection plus response, not detection alone.
What to do with this
- 1Confirm whether you have Microsoft 365 Business Premium. If you do, you own the EDR and XDR layers already.
- 2Open Intune and check devices actually report as compliant with Defender policies active. Licensed is not the same as deployed.
- 3Ask your provider, in writing: who reads our security alerts outside business hours, and what do they do next?
- 4Buy a SIEM only when a framework requires it. Otherwise spend that money on the response layer.