Free 3-minute assessment to determine if your small business needs EDR, MDR, or basic antivirus. Get personalized recommendations and budget estimates.
Twelve questions about your organisation, and the tool tells you which tier of endpoint protection fits: next-gen antivirus, EDR, or MDR. Then it sizes the annual cost against a slider for your endpoint count and lists specific products in the recommended tier. The whole thing runs in your browser — no account, no scan, no agent to install — and your answers are encoded into the page URL so you can copy the link and send your result to whoever holds the budget.
EDR and MDR are not two grades of the same product. One is software; the other is software plus people.
That is why the assessment spends as many questions on your team as on your threat exposure. The question that most often flips a result is not about industry or data — it is “how would you handle a security alert at 2 AM?” If the honest answer is “wait until morning”, buying EDR buys you a very detailed record of an incident nobody was awake to stop.
| Category | Questions |
|---|---|
| Company profile | Employee count; level of in-house IT and security expertise |
| Risk profile | Industry; sensitivity of the data you handle; compliance and cyber-insurance requirements |
| Environment | Whether you use Microsoft 365 and which plan; share of the workforce that is remote |
| Current state | What endpoint security you run today; security incidents in the past two years |
| Operations | How a 2 AM alert would be handled; how security spending ranks against other IT priorities; whether you would prefer a managed service |
Every question has four options. Each option carries two independent signals: a score from 1 to 4, which measures scale and risk exposure, and a directional vote for basic, EDR or MDR. Both feed the result, and they do not always point the same way — a dedicated security team scores 4 (high capability) while voting for EDR, because a capable team is exactly who should run the tooling themselves.
With twelve questions at up to four points each, the maximum score is 48. The rules run in order:
Two consequences are worth understanding before you argue with your result. First, four MDR votes is a low bar out of twelve questions — being fully remote, handling regulated data, having had a ransomware incident and wanting to outsource is enough on its own, regardless of size. That is deliberate: those four facts describe an organisation that needs coverage, not tooling. Second, the percentage path means a large, well-resourced, security-mature organisation can be routed to MDR by scale alone even while every capability answer says it could run EDR itself. If that is you, read it as “you are big enough that 24/7 coverage is the real question” rather than as a verdict that you cannot operate a SOC.
The assessment is a rules engine over your twelve answers. It has no data about your environment, has not scanned anything, and cannot see whether the tooling you already own is configured. Treat the output as a structured starting position for a procurement conversation, not a finding.
One answer gets special handling all the way through the results. If you tell it you have Microsoft 365 Business Premium, the recommendation text changes to say plainly that Business Premium includes basic Microsoft Defender protection but not full EDR — and that getting real EDR means either the Defender add-on or a third-party product.
This matters because “we have Business Premium, so we have Defender, so we have EDR” is one of the most common and most expensive misunderstandings in SMB security. The bundled protection is NGAV-grade. The threat hunting, detailed timeline and advanced response capabilities that make EDR worth buying are a separate line item. The tool's budget range for a Business Premium customer recommended NGAV reads “$0 (basic protection included)” with the add-on cost called out beside it, so the gap is visible rather than assumed away.
The results page carries a slider for endpoint count, from 5 to 300 in steps of 5, defaulting to 50. Each listed product has an annual per-endpoint figure, and the slider multiplies through. Products are filtered by their own endpoint ceilings, so raising the slider past 100 drops CrowdStrike Falcon Go from the list, and past 300 drops Defender for Business — both have hard caps.
At 50 endpoints, the shipped figures produce roughly this spread:
| Tier | Product | Per endpoint / yr | 50 endpoints / yr |
|---|---|---|---|
| EDR | Microsoft Defender for Business | $36 | $1,800 |
| EDR | CrowdStrike Falcon Go | $60 | $3,000 |
| EDR | ThreatDown (Malwarebytes) | $69 | $3,450 |
| EDR | SentinelOne Singularity Core | $70 | $3,500 |
| MDR | Acronis Cyber Protect | $114 | $5,700 |
| MDR | Huntress Managed EDR | $120 | $6,000 |
| MDR | Check Point Harmony Endpoint | $132 | $6,600 |
| MDR | Sophos MDR | $144 | $7,200 |
| MDR | Arctic Wolf MDR | $168 | $8,400 |
| MDR | Microsoft Defender Experts | $204 | $10,200 |
The gap between the two blocks is the whole argument. At 50 endpoints, MDR runs roughly two to five times the licence cost of EDR — and that difference is buying analyst hours. The honest comparison is not “$3,000 of EDR versus $6,000 of MDR”; it is “$3,000 of EDR plus whatever it costs you to have someone competent watching it at 3 AM, versus $6,000 all in.” For an organisation with no security staff, the first option is not cheaper. It is unstaffed.
These prices are researched list figures shipped with the tool, not live quotes. Endpoint security pricing moves, is heavily discounted at volume, and is frequently bundled — verify with the vendor or a reseller before building a budget on any single number. The tool also lists them at a single per-endpoint rate; real quotes vary by term length, tier and commitment.
The list you see is filtered and ordered by simple rules, not by a market evaluation:
So ordering reflects fit rules and your answers, not a ranking of product quality. Two products adjacent in the list are not being compared on detection efficacy — nothing here tests that. Use the shortlist to narrow which vendors to actually evaluate, then evaluate them: independent detection testing, a proof of concept in your own environment, and a hard look at what the MDR provider will and will not do without calling you first.
If you want a second pair of eyes on the result, there is an optional form at the bottom of the results page that sends your answers and shortlist so someone can review them — that is the only point at which anything leaves your browser, and it only happens if you submit it.