EDR Needs Assessment

Free 3-minute assessment to determine if your small business needs EDR, MDR, or basic antivirus. Get personalized recommendations and budget estimates.

Advertisement

Work out whether you need EDR, MDR, or just next-gen antivirus

Twelve questions about your organisation, and the tool tells you which tier of endpoint protection fits: next-gen antivirus, EDR, or MDR. Then it sizes the annual cost against a slider for your endpoint count and lists specific products in the recommended tier. The whole thing runs in your browser — no account, no scan, no agent to install — and your answers are encoded into the page URL so you can copy the link and send your result to whoever holds the budget.

The distinction the whole assessment turns on

EDR and MDR are not two grades of the same product. One is software; the other is software plus people.

  • NGAV stops known-bad things. It is preventive, largely autonomous, and produces few alerts a human needs to read.
  • EDR records what happened on the endpoint and surfaces suspicious behaviour for investigation. It generates alerts that someone must triage, and it gives that someone response actions — isolate the host, kill the process, hunt for the same indicator elsewhere. Buying EDR without staffing it produces an expensive log of your own breach.
  • MDR is EDR plus a staffed security operations centre doing the triage, the hunting and often the response on your behalf, around the clock. You are buying the analysts, not just the sensor.

That is why the assessment spends as many questions on your team as on your threat exposure. The question that most often flips a result is not about industry or data — it is “how would you handle a security alert at 2 AM?” If the honest answer is “wait until morning”, buying EDR buys you a very detailed record of an incident nobody was awake to stop.

What the twelve questions cover

CategoryQuestions
Company profileEmployee count; level of in-house IT and security expertise
Risk profileIndustry; sensitivity of the data you handle; compliance and cyber-insurance requirements
EnvironmentWhether you use Microsoft 365 and which plan; share of the workforce that is remote
Current stateWhat endpoint security you run today; security incidents in the past two years
OperationsHow a 2 AM alert would be handled; how security spending ranks against other IT priorities; whether you would prefer a managed service

Every question has four options. Each option carries two independent signals: a score from 1 to 4, which measures scale and risk exposure, and a directional vote for basic, EDR or MDR. Both feed the result, and they do not always point the same way — a dedicated security team scores 4 (high capability) while voting for EDR, because a capable team is exactly who should run the tooling themselves.

How the recommendation is decided

With twelve questions at up to four points each, the maximum score is 48. The rules run in order:

  1. MDR if at least four answers voted MDR, or the total score reaches 75% (36 of 48).
  2. EDR if at least four answers voted EDR, or the total score reaches 45% (22 of 48).
  3. NGAV otherwise.

Two consequences are worth understanding before you argue with your result. First, four MDR votes is a low bar out of twelve questions — being fully remote, handling regulated data, having had a ransomware incident and wanting to outsource is enough on its own, regardless of size. That is deliberate: those four facts describe an organisation that needs coverage, not tooling. Second, the percentage path means a large, well-resourced, security-mature organisation can be routed to MDR by scale alone even while every capability answer says it could run EDR itself. If that is you, read it as “you are big enough that 24/7 coverage is the real question” rather than as a verdict that you cannot operate a SOC.

The assessment is a rules engine over your twelve answers. It has no data about your environment, has not scanned anything, and cannot see whether the tooling you already own is configured. Treat the output as a structured starting position for a procurement conversation, not a finding.

The Microsoft 365 trap the tool is built to catch

One answer gets special handling all the way through the results. If you tell it you have Microsoft 365 Business Premium, the recommendation text changes to say plainly that Business Premium includes basic Microsoft Defender protection but not full EDR — and that getting real EDR means either the Defender add-on or a third-party product.

This matters because “we have Business Premium, so we have Defender, so we have EDR” is one of the most common and most expensive misunderstandings in SMB security. The bundled protection is NGAV-grade. The threat hunting, detailed timeline and advanced response capabilities that make EDR worth buying are a separate line item. The tool's budget range for a Business Premium customer recommended NGAV reads “$0 (basic protection included)” with the add-on cost called out beside it, so the gap is visible rather than assumed away.

Sizing the cost

The results page carries a slider for endpoint count, from 5 to 300 in steps of 5, defaulting to 50. Each listed product has an annual per-endpoint figure, and the slider multiplies through. Products are filtered by their own endpoint ceilings, so raising the slider past 100 drops CrowdStrike Falcon Go from the list, and past 300 drops Defender for Business — both have hard caps.

At 50 endpoints, the shipped figures produce roughly this spread:

TierProductPer endpoint / yr50 endpoints / yr
EDRMicrosoft Defender for Business$36$1,800
EDRCrowdStrike Falcon Go$60$3,000
EDRThreatDown (Malwarebytes)$69$3,450
EDRSentinelOne Singularity Core$70$3,500
MDRAcronis Cyber Protect$114$5,700
MDRHuntress Managed EDR$120$6,000
MDRCheck Point Harmony Endpoint$132$6,600
MDRSophos MDR$144$7,200
MDRArctic Wolf MDR$168$8,400
MDRMicrosoft Defender Experts$204$10,200

The gap between the two blocks is the whole argument. At 50 endpoints, MDR runs roughly two to five times the licence cost of EDR — and that difference is buying analyst hours. The honest comparison is not “$3,000 of EDR versus $6,000 of MDR”; it is “$3,000 of EDR plus whatever it costs you to have someone competent watching it at 3 AM, versus $6,000 all in.” For an organisation with no security staff, the first option is not cheaper. It is unstaffed.

These prices are researched list figures shipped with the tool, not live quotes. Endpoint security pricing moves, is heavily discounted at volume, and is frequently bundled — verify with the vendor or a reseller before building a budget on any single number. The tool also lists them at a single per-endpoint rate; real quotes vary by term length, tier and commitment.

How products get shortlisted

The list you see is filtered and ordered by simple rules, not by a market evaluation:

  • An MDR result shows only MDR products; an EDR result shows only EDR products.
  • An NGAV result shows Microsoft products if you have Business Premium, otherwise the two cheapest EDR options as a growth path.
  • If you have Business Premium, Microsoft products are floated to the top of an EDR list — on integration grounds, not on merit.
  • If you are a small organisation, CrowdStrike Falcon Go is floated to the top, subject to its 100-endpoint cap.
  • Anything whose endpoint ceiling is below your slider value is removed entirely.

So ordering reflects fit rules and your answers, not a ranking of product quality. Two products adjacent in the list are not being compared on detection efficacy — nothing here tests that. Use the shortlist to narrow which vendors to actually evaluate, then evaluate them: independent detection testing, a proof of concept in your own environment, and a hard look at what the MDR provider will and will not do without calling you first.

Questions people ask about the results

  • Is anything uploaded? No. The twelve questions and all the scoring run locally. Your answers get written into the URL as a query string when you finish, which is what makes the share link work — so treat the link as containing your answers, and think before pasting it somewhere public.
  • Can I go back and change an answer? Yes, there is a back button through the question sequence, and restarting clears the URL along with the answers.
  • Why did a 10-person company get MDR? Almost always the capability questions: no dedicated IT staff, nobody to respond at 2 AM, and a preference for outsourcing are three MDR votes before risk is even considered. Small does not mean low-need; it usually means low-capacity, which is the case for a managed service rather than against it.
  • Why did a 500-person company get EDR? Because it has a security team, can respond quickly, and said it wants to run security itself. The tool takes that at face value.
  • Does it recommend one product? No. It recommends a tier, then lists the products in that tier that fit your endpoint count. Choosing among them is yours.
  • What about servers, cloud workloads and identity? Out of scope. This is an endpoint-tier assessment. Server protection, cloud posture and identity threat detection are separate purchases with separate sizing.

If you want a second pair of eyes on the result, there is an optional form at the bottom of the results page that sends your answers and shortlist so someone can review them — that is the only point at which anything leaves your browser, and it only happens if you submit it.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.