Most EDR-versus-MDR guides frame this as a technology comparison. It is not. The detection engines are frequently the same software. The real question is whether an alert raised at 3am on a Sunday reaches a human who is awake, competent and permitted to act.
If the answer is no, then EDR is not a cheaper version of MDR. It is a dashboard nobody reads, and the money is wasted regardless of which vendor's logo is on it.
This guide walks the decision the way it actually works, with pricing verified against vendor sites on 12 August 2026 rather than the unsourced ranges that circulate in this category.
Start Here: The Assessment
If you would rather answer questions than read tables, our free three-minute EDR Needs Assessment works through risk profile, IT capability and compliance obligations and returns a recommendation. If you already know you need managed coverage, skip ahead to the MDR Vendor Selector.
What the Data Says About SMB Risk
Verizon's 2025 Data Breach Investigations Report analysed 22,052 security incidents and 12,195 confirmed breaches. Two findings matter here:
- Ransomware was involved in 88% of breaches at small and medium businesses, against 39% at large organisations.
- Ransomware featured in 44% of all breaches in the reporting period.
The usual explanation is not that attackers prefer small businesses, but that small businesses have less network segmentation, fewer layered controls and weaker recovery readiness — so an intrusion that a large enterprise contains becomes an encryption event at an SMB.
A note on a statistic we removed. Earlier versions of this page cited "43% of data breaches involve small businesses" from the 2019 DBIR. That figure is six years old and has been superseded by the 2025 report's much sharper finding. We also removed an unsourced "175% first-year ROI" claim, an unsourced average breach cost range, and a claim that antivirus misses a specific percentage of threats. None had a traceable primary source. Model your own exposure with the data breach cost calculator instead of inheriting someone else's average.
EDR vs MDR: What You Are Actually Buying
| EDR | MDR | |
|---|---|---|
| What it is | Detection and response software | The same software plus a staffed SOC |
| Who triages alerts | You | The provider |
| Who decides severity | You | The provider |
| Who takes containment action | You | The provider, within limits you set |
| Coverage hours | Whatever your team covers | 24/7/365 |
| Expertise required | Real. Someone must interpret behavioural alerts | Minimal on your side |
| Cost model | Per device or per user licence | Per endpoint, quoted on your environment |
| Fails when | Nobody reads the console | Response authority is too narrow to act |
The last row deserves attention because it is the failure mode buyers do not anticipate. An MDR contract where the provider must phone and wait for approval before isolating a host has quietly reintroduced the same 3am problem you paid to remove. Ask every provider, in writing: which actions can you take without my approval, and at what hour?
Verified Pricing, 12 August 2026
All figures read from the vendor's own pricing page on the date shown.
Self-managed EDR
| Product | Price | Unit | Constraints | Source |
|---|---|---|---|---|
| Microsoft Defender for Business | $3.00/user/mo (annual) | Per user | ≤300 users, 5 devices per user | microsoft.com |
| Microsoft 365 Business Premium | $22.00/user/mo | Per user | Bundles Defender for Business with M365 apps, identity, device management | Same |
| CrowdStrike Falcon Go | $7.99/device/mo or $59.99/yr | Per device | Max 100 devices; 15-day free trial, no card | crowdstrike.com |
| CrowdStrike Falcon Pro | $14.99/device/mo or $99.99/yr | Per device | — | Same |
| CrowdStrike Falcon Enterprise | $19.99/device/mo or $184.99/yr | Per device | — | Same |
| SentinelOne Singularity Complete | $179.99/endpoint/yr | Per endpoint | Price shown for 5-100 workstations; purchases go through an authorised partner and listed prices are not final | sentinelone.com |
Managed detection and response
| Product | Price | Unit | Constraints | Source |
|---|---|---|---|---|
| Huntress Managed EDR | $8.99/endpoint/mo | Per endpoint (50-99 tier) | 50-seat minimum direct, 12-month term; 24/7 SOC included; "no separate setup or onboarding fees" | huntress.com/pricing |
| Huntress Managed SIEM | $4.00/source/mo | Per log source | — | Same |
| Huntress Managed ITDR | $4.80/identity/mo | Per licensed identity | — | Same |
| CrowdStrike Falcon Complete | "Contact sales" | — | No published price | crowdstrike.com |
| Arctic Wolf MDR | Not published | — | "Request a Demo" | arcticwolf.com |
| Expel MDR | Not published | Integrations / data sources | — | expel.com |
| eSentire (Atlas Essentials / Advanced / Complete) | Not published | Per endpoint | >5,000 endpoints = custom package | esentire.com |
| Rapid7 Managed Threat Complete | Not published | Endpoints + servers + networks | "custom quoted for your specific environment size" | rapid7.com |
| Sophos MDR | Not published | — | "Get Pricing" | sophos.com |
The headline finding for a small business: Huntress is the only major MDR provider you can budget for from a web page. Everyone else quotes. We break down exactly what drives those quotes in our verified MDR pricing guide.
The Rota Maths That Actually Decides This
Here is the arithmetic that people skip, and it is the whole decision.
Continuous 24/7/365 coverage of a single seat requires roughly 4 to 5 analysts once you account for three shifts, weekends, annual leave, sickness and attrition. One person cannot cover a 168-hour week; three barely can with no slack.
At typical loaded costs for security analysts, that is somewhere in the region of $600,000 to $1.25 million per year in payroll alone, before tooling, training, certification renewals, management overhead or the recruitment cost of replacing anyone who leaves.
(A note on our own arithmetic: an earlier version of a related page on this site cited "$2.5M+ in annual SOC staffing costs" from the same 4-5 analyst assumption. That figure does not follow from those inputs and we have corrected it here and there.)
Set that against MDR at, say, $8.99 per endpoint per month. A 200-endpoint business pays roughly $21,600 a year for a staffed 24/7 rota it could not otherwise buy at any price it could afford. That is the real argument for MDR at SMB scale, and it does not depend on any breach-cost estimate or ROI multiple.
Run your own numbers with the cybersecurity budget calculator.
Choose EDR If…
- You have someone who will genuinely watch it. An internal admin with security aptitude, or an MSP with a contractual obligation to triage alerts — not "we'll check it weekly."
- Your risk tolerance matches your coverage hours. A firm that shuts on Friday and reopens Monday with no remote access has a different exposure profile from one running 24-hour operations.
- You are on Microsoft 365 and under 300 users. Defender for Business at $3.00 per user per month is an efficient floor, especially if Business Premium at $22.00 was already on the table for other reasons.
- You want a low-commitment starting point. Falcon Go at $7.99 per device with a 15-day no-card trial lets you learn what your own alert volume actually looks like before committing to a service.
Choose MDR If…
- You have no security staff and no plan to hire any. This is the majority of small businesses and it is the clear-cut case.
- You need documented 24/7 coverage for insurance, a customer security questionnaire, or a compliance framework. MDR gives you an answer with a contract behind it.
- Your team already ignores security alerts. Adding a more sophisticated alert source to an inbox nobody reads makes the problem worse, not better. Be honest about this one.
- You are recovering from an incident. Sustained expert monitoring while you rebuild is worth paying for, and the reporting output matters to customers and insurers.
- Your risk sits in identity and SaaS, not just laptops. Endpoint-only tooling misses this. Providers with breadth across identity, cloud and SaaS — Expel is the clearest example — address it directly.
Choose Both, Staged, If…
You want to build internal capability but cannot cover nights yet. Start with EDR under an MSP, add MDR at a defined trigger — a headcount threshold, a compliance deadline, a customer requirement. Set the date now. The failure mode of the staged path is that the review never happens and the alerts go unread for two years.
What to Ask Every Provider
- Which containment actions can you take without my approval, and at what hour?
- Is remediation included, or does the service end at notification?
- What is the billing unit — endpoints only, or endpoints plus servers plus log sources plus identities?
- What log volume is included and what is the overage rate?
- How long is telemetry retained and searchable?
- Does the price include the endpoint licence, or do I buy that separately?
- What are the minimum seats and the minimum term?
- What happens at renewal if my endpoint count grows 40%?
Prepare your side of the conversation with the incident response playbook generator and, if ransomware is your main concern, the ransomware resilience assessment.
Related Reading
- MDR pricing 2026: what 12 vendors actually publish
- CrowdStrike Falcon Complete: pricing, features and trade-offs
- CrowdStrike vs Arctic Wolf: platform versus partnership
- CrowdStrike vs Expel: what the published response times mean
- Choosing between MDR, EDR, MSSP, XDR and SOC
Verification note. Every price and quoted phrase above was read from the named vendor's own website on 12 August 2026 and is linked to source. Statistics we could not trace to a primary source were removed rather than repeated, and the Verizon figures are cited to the 2025 DBIR. Vendors change pricing without notice; confirm against the linked source before budgeting.