Mdr Security

EDR vs MDR for Small Business: Which One You Actually Need (2026)

The EDR vs MDR decision is a staffing question, not a technology question. With verified 2026 pricing from CrowdStrike, Huntress, Microsoft and SentinelOne, and the rota maths that actually decides it.

By InventiveHQ Team

Most EDR-versus-MDR guides frame this as a technology comparison. It is not. The detection engines are frequently the same software. The real question is whether an alert raised at 3am on a Sunday reaches a human who is awake, competent and permitted to act.

If the answer is no, then EDR is not a cheaper version of MDR. It is a dashboard nobody reads, and the money is wasted regardless of which vendor's logo is on it.

This guide walks the decision the way it actually works, with pricing verified against vendor sites on 12 August 2026 rather than the unsourced ranges that circulate in this category.

Start Here: The Assessment

If you would rather answer questions than read tables, our free three-minute EDR Needs Assessment works through risk profile, IT capability and compliance obligations and returns a recommendation. If you already know you need managed coverage, skip ahead to the MDR Vendor Selector.

What the Data Says About SMB Risk

Verizon's 2025 Data Breach Investigations Report analysed 22,052 security incidents and 12,195 confirmed breaches. Two findings matter here:

  • Ransomware was involved in 88% of breaches at small and medium businesses, against 39% at large organisations.
  • Ransomware featured in 44% of all breaches in the reporting period.

The usual explanation is not that attackers prefer small businesses, but that small businesses have less network segmentation, fewer layered controls and weaker recovery readiness — so an intrusion that a large enterprise contains becomes an encryption event at an SMB.

A note on a statistic we removed. Earlier versions of this page cited "43% of data breaches involve small businesses" from the 2019 DBIR. That figure is six years old and has been superseded by the 2025 report's much sharper finding. We also removed an unsourced "175% first-year ROI" claim, an unsourced average breach cost range, and a claim that antivirus misses a specific percentage of threats. None had a traceable primary source. Model your own exposure with the data breach cost calculator instead of inheriting someone else's average.

EDR vs MDR: What You Are Actually Buying

EDRMDR
What it isDetection and response softwareThe same software plus a staffed SOC
Who triages alertsYouThe provider
Who decides severityYouThe provider
Who takes containment actionYouThe provider, within limits you set
Coverage hoursWhatever your team covers24/7/365
Expertise requiredReal. Someone must interpret behavioural alertsMinimal on your side
Cost modelPer device or per user licencePer endpoint, quoted on your environment
Fails whenNobody reads the consoleResponse authority is too narrow to act

The last row deserves attention because it is the failure mode buyers do not anticipate. An MDR contract where the provider must phone and wait for approval before isolating a host has quietly reintroduced the same 3am problem you paid to remove. Ask every provider, in writing: which actions can you take without my approval, and at what hour?

Verified Pricing, 12 August 2026

All figures read from the vendor's own pricing page on the date shown.

Self-managed EDR

ProductPriceUnitConstraintsSource
Microsoft Defender for Business$3.00/user/mo (annual)Per user≤300 users, 5 devices per usermicrosoft.com
Microsoft 365 Business Premium$22.00/user/moPer userBundles Defender for Business with M365 apps, identity, device managementSame
CrowdStrike Falcon Go$7.99/device/mo or $59.99/yrPer deviceMax 100 devices; 15-day free trial, no cardcrowdstrike.com
CrowdStrike Falcon Pro$14.99/device/mo or $99.99/yrPer deviceSame
CrowdStrike Falcon Enterprise$19.99/device/mo or $184.99/yrPer deviceSame
SentinelOne Singularity Complete$179.99/endpoint/yrPer endpointPrice shown for 5-100 workstations; purchases go through an authorised partner and listed prices are not finalsentinelone.com

Managed detection and response

ProductPriceUnitConstraintsSource
Huntress Managed EDR$8.99/endpoint/moPer endpoint (50-99 tier)50-seat minimum direct, 12-month term; 24/7 SOC included; "no separate setup or onboarding fees"huntress.com/pricing
Huntress Managed SIEM$4.00/source/moPer log sourceSame
Huntress Managed ITDR$4.80/identity/moPer licensed identitySame
CrowdStrike Falcon Complete"Contact sales"No published pricecrowdstrike.com
Arctic Wolf MDRNot published"Request a Demo"arcticwolf.com
Expel MDRNot publishedIntegrations / data sourcesexpel.com
eSentire (Atlas Essentials / Advanced / Complete)Not publishedPer endpoint>5,000 endpoints = custom packageesentire.com
Rapid7 Managed Threat CompleteNot publishedEndpoints + servers + networks"custom quoted for your specific environment size"rapid7.com
Sophos MDRNot published"Get Pricing"sophos.com

The headline finding for a small business: Huntress is the only major MDR provider you can budget for from a web page. Everyone else quotes. We break down exactly what drives those quotes in our verified MDR pricing guide.

Advertisement

The Rota Maths That Actually Decides This

Here is the arithmetic that people skip, and it is the whole decision.

Continuous 24/7/365 coverage of a single seat requires roughly 4 to 5 analysts once you account for three shifts, weekends, annual leave, sickness and attrition. One person cannot cover a 168-hour week; three barely can with no slack.

At typical loaded costs for security analysts, that is somewhere in the region of $600,000 to $1.25 million per year in payroll alone, before tooling, training, certification renewals, management overhead or the recruitment cost of replacing anyone who leaves.

(A note on our own arithmetic: an earlier version of a related page on this site cited "$2.5M+ in annual SOC staffing costs" from the same 4-5 analyst assumption. That figure does not follow from those inputs and we have corrected it here and there.)

Set that against MDR at, say, $8.99 per endpoint per month. A 200-endpoint business pays roughly $21,600 a year for a staffed 24/7 rota it could not otherwise buy at any price it could afford. That is the real argument for MDR at SMB scale, and it does not depend on any breach-cost estimate or ROI multiple.

Run your own numbers with the cybersecurity budget calculator.

Choose EDR If…

  • You have someone who will genuinely watch it. An internal admin with security aptitude, or an MSP with a contractual obligation to triage alerts — not "we'll check it weekly."
  • Your risk tolerance matches your coverage hours. A firm that shuts on Friday and reopens Monday with no remote access has a different exposure profile from one running 24-hour operations.
  • You are on Microsoft 365 and under 300 users. Defender for Business at $3.00 per user per month is an efficient floor, especially if Business Premium at $22.00 was already on the table for other reasons.
  • You want a low-commitment starting point. Falcon Go at $7.99 per device with a 15-day no-card trial lets you learn what your own alert volume actually looks like before committing to a service.

Choose MDR If…

  • You have no security staff and no plan to hire any. This is the majority of small businesses and it is the clear-cut case.
  • You need documented 24/7 coverage for insurance, a customer security questionnaire, or a compliance framework. MDR gives you an answer with a contract behind it.
  • Your team already ignores security alerts. Adding a more sophisticated alert source to an inbox nobody reads makes the problem worse, not better. Be honest about this one.
  • You are recovering from an incident. Sustained expert monitoring while you rebuild is worth paying for, and the reporting output matters to customers and insurers.
  • Your risk sits in identity and SaaS, not just laptops. Endpoint-only tooling misses this. Providers with breadth across identity, cloud and SaaS — Expel is the clearest example — address it directly.

Choose Both, Staged, If…

You want to build internal capability but cannot cover nights yet. Start with EDR under an MSP, add MDR at a defined trigger — a headcount threshold, a compliance deadline, a customer requirement. Set the date now. The failure mode of the staged path is that the review never happens and the alerts go unread for two years.

What to Ask Every Provider

  1. Which containment actions can you take without my approval, and at what hour?
  2. Is remediation included, or does the service end at notification?
  3. What is the billing unit — endpoints only, or endpoints plus servers plus log sources plus identities?
  4. What log volume is included and what is the overage rate?
  5. How long is telemetry retained and searchable?
  6. Does the price include the endpoint licence, or do I buy that separately?
  7. What are the minimum seats and the minimum term?
  8. What happens at renewal if my endpoint count grows 40%?

Prepare your side of the conversation with the incident response playbook generator and, if ransomware is your main concern, the ransomware resilience assessment.


Verification note. Every price and quoted phrase above was read from the named vendor's own website on 12 August 2026 and is linked to source. Statistics we could not trace to a primary source were removed rather than repeated, and the Verizon figures are cited to the 2025 DBIR. Vendors change pricing without notice; confirm against the linked source before budgeting.

Frequently Asked Questions

What is the actual difference between EDR and MDR?

EDR is software you operate. MDR is EDR plus the people who operate it. The technology underneath is frequently identical — Huntress Managed EDR, CrowdStrike Falcon Complete and Expel all run detection engines you could in principle license and run yourself. What you are buying with MDR is a staffed rota that receives the alert at 3am on a Sunday and is contractually permitted to act on it. If nobody on your side would answer that alert, EDR and MDR are not two options at different price points; they are one real option and one dashboard.

How much does EDR cost for a small business in 2026?

Verified from vendor pricing pages on 12 August 2026: Microsoft Defender for Business is $3.00 per user per month on an annual subscription, covering up to 300 users at five devices each. CrowdStrike Falcon Go is $7.99 per device per month or $59.99 annually, capped at 100 devices. CrowdStrike Falcon Pro is $14.99 per device per month. SentinelOne Singularity Complete is $179.99 per endpoint per year, though SentinelOne notes all purchases go through an authorised partner and listed prices are not final.

How much does MDR cost for a small business?

Only one major vendor publishes a real managed-service price. Huntress lists Managed EDR at $8.99 per endpoint per month at the 50-99 endpoint tier, with the 24/7 SOC included and no separate setup or onboarding fees, subject to a 50-seat minimum for direct purchase on a 12-month term. Every other major MDR provider we checked — CrowdStrike Falcon Complete, Arctic Wolf, Expel, Rapid7, eSentire, Sophos, Red Canary, Blackpoint — publishes no price and routes buyers to a quote.

Is Microsoft Defender enough for a small business?

Microsoft Defender for Business at $3.00 per user per month is a genuinely capable endpoint detection product, not a token one — it includes vulnerability management, next-generation antivirus, endpoint detection and response, and automated investigation and remediation. Its limits are eligibility and operation: up to 300 users, five devices per user, and someone still has to watch the console. If you are already on Microsoft 365 and you have an internal admin or an MSP who will act on alerts, it is often the correct answer. If nobody will watch it, the price is irrelevant.

At what size does a small business need MDR rather than EDR?

It is set by your rota, not your headcount. Genuine 24/7 coverage needs four to five analysts to staff the shifts, holidays and attrition. At typical loaded salaries that is roughly $600,000 to $1.25 million per year in payroll alone before tooling, which almost no organisation under a few thousand seats can justify. If you have zero security staff, MDR makes sense at almost any size. If you have one or two people working business hours, MDR is usually cheaper than the third and fourth hires needed to cover nights and weekends.

Do small businesses actually get attacked?

Verizon's 2025 Data Breach Investigations Report, which analysed 22,052 security incidents and 12,195 confirmed breaches, found that ransomware was involved in 88% of breaches at small and medium businesses, against 39% at large organisations. Ransomware featured in 44% of all breaches in the reporting period. The gap is generally attributed to SMBs having less segmentation, fewer layered defences and weaker recovery readiness rather than to attackers preferring them.

Does cyber insurance require EDR or MDR?

Increasingly insurers ask about endpoint detection controls in underwriting, and answers can affect both eligibility and premium. But requirements vary substantially by carrier and are changing year to year, so the only reliable source is your own broker and your own policy wording. Ask your broker directly which controls your carrier requires and which attract a credit, before you buy on the assumption that it will pay for itself in premium.

Can I start with EDR and move to MDR later?

Usually yes, and it is often the sensible sequence. CrowdStrike, for example, lets you start on Falcon Go or Falcon Pro and move to Falcon Complete MDR without changing the agent. The risk is drift: teams buy EDR intending to add the human layer next year, and the alerts quietly go unread in the meantime. If you take the staged path, set a date and a trigger for the review rather than leaving it open.