Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

Antivirus, EDR or MDR: What a Small Security Team Really Needs

eToken PRO USB is a USB two factor authentication token based on Smart Card Technology
Photo: EToken PRO USB by Kharitonov, CC BY-SA 3.0, via Wikimedia Commons

If nobody in your business is paid to read security alerts, buy a managed service. That is the whole decision in one sentence. Antivirus stops the malware it recognises, endpoint detection and response records what happened and raises an alert, and managed detection and response puts somebody else’s analysts on the end of that alert at three in the morning. The tool matters less than whether a human will act on what it finds.

National Director of Fire and Aviation Management, Shawna Legarza provides leader's intent to the California Incident Management Teams. Each year the California inter-agency incide
The cheapest controls still come first. Detection is what you add once they are in place.Photo: 2019 IMT Meetings by Region 5 Photography, Public domain, via Wikimedia Commons

The short answer

Three rules of thumb cover most situations. Under about ten devices with no IT staff, a current operating system, automatic updates, multi-factor authentication and the antivirus already built into your platform will carry you a long way. Between roughly ten and fifty devices, add EDR, because you need the recording even if you cannot watch it continuously. Above that, or in any regulated or high-value business, buy MDR, because an alert nobody reads is a line item rather than a control.

That is not a sales position. Two of the three options in this article cost less than a phone contract, and the most common mistake we see is not underspending but buying a capable platform and then leaving its console unopened for months.

What the three things actually are

The three categories overlap in marketing and differ sharply in what they ask of you.

  • Antivirus, or next-generation antivirus. Prevention. It inspects files and behaviour and blocks what it judges malicious. Modern versions use behavioural models rather than signatures alone, and the good ones are genuinely effective at the commodity end of the threat spectrum.
  • EDR, endpoint detection and response. Visibility plus a record. It logs process launches, network connections, credential access and file changes, correlates them into a timeline, and raises alerts. It also gives you the ability to isolate a machine and hunt backwards through history after the fact.
  • MDR, managed detection and response. The same telemetry with a staffed security operations centre attached. Someone else triages the alerts, investigates the ambiguous ones, and in most offerings takes containment action under rules you agreed in advance.

The important difference is not the acronym but the obligation. EDR hands you an alert queue. If you have no rota to work that queue, you have bought a very good flight recorder for a crash nobody will notice. CISA made this point in its published lessons from an incident response engagement: among three findings, EDR alerts not being continuously reviewed sat alongside unpatched vulnerabilities and an untested incident response plan.

A quick self-test
  • Who looked at your security console yesterday? If the answer is nobody, EDR alone is the wrong purchase.
  • If a laptop were compromised at 2 a.m. on a Sunday, who would isolate it, and how long would that take?
  • Could you reconstruct what an attacker did last Tuesday? If not, you need the recording that EDR provides.

Why detection matters more than it did five years ago

Two pieces of recent research explain why prevention alone stopped being a complete answer. Mandiant’s M-Trends 2026 found that global median dwell time, the gap between an attacker getting in and being discovered, rose to 14 days from 11 the year before. At the same time, the median delay between an initial access broker gaining a foothold and handing it to a second group collapsed to 22 seconds, down from more than eight hours in 2022.

14
Days median dwell time, M-Trends 2026
22
Seconds median access handoff in 2025
52%
Intrusions first detected internally
Mandiant M-Trends 2026, published by Google Cloud. Internal detection rose from 43% of investigations in 2024 to 52% in 2025.

Read those three numbers together and the shape of the problem is clear. Attackers move in seconds and then wait. Organisations are getting better at finding them, with internal detection now accounting for 52% of cases against 43% the year before, but a fortnight is still a long time to be sharing your network with someone. Detection and response is what shortens that window; prevention alone cannot, because the thing you are looking for already got past it.

The money side has moved in the same direction. IBM’s 2026 Cost of a Data Breach Report puts the global average at USD 4.99 million, a 12% rise and a record for the study, and reframes that as roughly USD 1,100 for every hour an incident runs. The same report found AI-driven attacks up 56% year on year, with one in four malicious breaches AI-enabled and those averaging around USD 6 million.

One caveat on that average, since it gets quoted carelessly. It is drawn from organisations large enough to participate in the study, so it is not a prediction for a twenty-person business. Use it as a direction of travel and for the per-hour framing, not as your expected loss.

The 102d Strategic Signal Battalion (102d SSB), Network Enterprise Center (NEC) – Baumholder held a ribbon cutting ceremony on Smith Barracks, Oct. 17, to mark the successful compl
Response speed is the variable you can actually buy. Dwell time is the one it changes.Photo: 102d SSB completes NETMOD in Baumholder- Enhanced cybersecurity, network performance for DoD operations in USAG Rheinland-Pfalz’s footprint by U.S. Army USAG-RP by Linda Lambiotte, Public domain, via Wikimedia Commons

What they cost, using published prices

Published list prices make this comparison concrete. Everything below was on the vendor’s own pricing page in October 2026, and all three vendors publish rather than quote, which is itself worth something when you are a small buyer.

Endpoint security list price per endpoint per month (October 2026)
Microsoft 365 Business Premium (bundle)USD 22.00
CrowdStrike Falcon GoUSD 7.99
Huntress Managed EDR, 100-endpoint exampleUSD 7.99
Microsoft Defender for BusinessUSD 3.00
Sources: Microsoft Defender for Business pricing page (annual subscription), CrowdStrike Falcon Go pricing page (monthly billing), and the Huntress pricing page example for 100 endpoints. All accessed October 2026.
OptionCategoryList priceWho works the alertsNotable limits
Microsoft Defender for BusinessEDR with next-generation antivirusUSD 3.00 per user / month, annualYou, in the Microsoft 365 security consoleUp to 300 users, five devices each; servers need the separate add-on
Microsoft 365 Business PremiumThe above, bundled with identity and device managementUSD 22.00 per user / month, annualYouUp to 300 users; a version without Teams lists at USD 18.79
CrowdStrike Falcon GoNext-generation antivirus with device controlUSD 7.99 per device / month, or USD 59.99 per device / yearYouCapped at 100 devices; self-service purchase
Huntress Managed EDRManaged detection and responseUSD 7.99 per endpoint / month in the published 100-endpoint exampleTheir security operations centre, 24/7Priced per endpoint; Huntress notes the wider EDR market spans USD 2.99 to USD 184 per endpoint per month
List prices from each vendor’s own pricing page, accessed October 2026. Prices and packaging change frequently, so confirm before budgeting.

The useful surprise in that table is how small the gap is. Managed detection in the published example costs the same per endpoint as unmanaged next-generation antivirus from a well-known vendor, and about five dollars a month more than Microsoft’s own EDR. For a forty-device office the difference between EDR you will not watch and MDR somebody else watches is roughly USD 200 a month. Set that against IBM’s per-hour framing of incident cost and the argument is short.

The expensive option is not MDR. It is the alert queue nobody opened.

Two caveats on price. First, most MDR vendors do not publish, and the band quoted around the market runs from single digits to well over thirty dollars per endpoint per month depending on coverage and response guarantees, so get two written quotes rather than trusting a round number. Second, bundles change the arithmetic: if you already pay for Microsoft 365 Business Premium, you already own Defender for Business, and the question becomes whether to add a managed service on top rather than whether to buy a platform.

The question that decides it

Strip away the product comparison and one question decides your answer. When an alert fires outside working hours, what happens next? There are only three honest answers, and each maps to a purchase.

  1. Nothing happens until Monday. Buy MDR. You are paying for coverage, not software.
  2. Someone gets a notification and will look if it seems serious. This is the most common answer and the most dangerous, because it feels like coverage. EDR plus a written escalation rota, or MDR if the rota is fiction.
  3. We have a rota, a runbook and someone who has used the isolation button. EDR is appropriate. Keep the rota honest and rehearse it twice a year.

Whatever you buy, agree the response authority in writing before you need it. The most common delay we see in real incidents is not detection; it is twenty minutes spent deciding who is allowed to disconnect a director’s laptop from the network. Decide that in advance and the tooling gets to do its job.

What to buy at ten, fifty and two hundred endpoints

Three concrete recommendations, assuming the basics in the next section are already in place.

SizeWhat we would buyRoughly what it costs at list priceWhy
About 10 devices, no IT staffBuilt-in platform antivirus plus Defender for Business at USD 3.00 per user / monthAround USD 30 a monthYou get the recording cheaply. Accept that nobody is watching live, and compensate with aggressive patching and MFA
About 50 devices, one generalist IT personManaged detection and response, around USD 8 per endpoint / month in published examplesAround USD 400 a monthYour IT person cannot be on call permanently. Buy the hours rather than the hope
About 200 devices, or regulated dataMDR with contracted response times, plus EDR coverage on serversLow thousands a month, quotedAt this size an incident has legal and contractual consequences, and you need evidence and documented response
Indicative figures built from the published list prices above. Multi-year and volume terms usually improve them.

Notice there is no tier where we recommend buying the most expensive platform and configuring it once. Capability you do not operate is the worst value in security, which is also why we tell clients to start with the cheapest controls that need no attention at all.

Atlanta, Georgia, July 8, 2005 -- FEMA Region IV staff view information on the screens in the Regional Response Coordination Center (RRCC) during the evening shift change briefing.
Agree who may isolate a machine before you need the answer.Photo: FEMA – 13732 – Photograph by Mark Wolfe taken on 07-08-2005 in Georgia by Mark Wolfe, Public domain, via Wikimedia Commons

The unglamorous work that comes first

CISA’s guidance for small businesses puts the fundamentals first, and the 2026 DBIR data explains why. Vulnerability exploitation became the top entry point at 31% of breaches, overtaking stolen credentials for the first time in the report’s nineteen years, with credential abuse at 13% and the human element present in 62% of cases. No endpoint product fixes an unpatched application or a shared administrator password.

  1. Multi-factor authentication everywhere it is available, starting with email and remote access. Free on every major platform and still the single highest-value control. We cover the practical rollout in our MFA guide.
  2. Automatic updates on operating systems and applications, with a monthly check that they actually applied. This is the control that addresses the 31% figure directly.
  3. Backups you have restored from. Not backups that reported success. Keep one copy where a compromised administrator account cannot reach it.
  4. A written incident response plan, which CISA recommends the leadership team review. Two pages is enough: who decides, who calls whom, what gets disconnected, where the backups are.
  5. Phishing resistance for your people, because social engineering still accounts for 16% of breaches. How to stop phishing attacks on your business covers what works and what merely annoys staff.

Those five cost almost nothing and remove most of the cheap attacks. Detection tooling then handles what gets through, which is the right division of labour and the right order of spending. If ransomware is your specific worry, our ransomware guide goes through the recovery side in more detail.

How we help

Eudora Technology works remotely with clients in several countries, and endpoint security is almost entirely remote work. Our cybersecurity service covers the decision in this article honestly: we will tell you when the free platform antivirus plus disciplined patching is enough, help you deploy and tune EDR when it is not, and sit alongside you while you evaluate managed providers. We do not resell a single vendor’s stack, so the recommendation follows your rota rather than our margin.

For businesses that also need on-site support in Sri Lanka, our local sister operation at eudora.lk handles that side. Everything described here, from deployment to the written escalation plan, we deliver without being in the building.

Frequently asked questions

Is built-in antivirus good enough on its own?

For a very small business with current operating systems, automatic updates, multi-factor authentication and tested backups, it is a defensible starting point. What it does not give you is a record. If you need to know what an attacker touched, or to isolate a machine remotely, you need EDR. Microsoft’s own EDR product lists at USD 3.00 per user per month, so the step up is small.

What is the real difference between EDR and MDR?

The telemetry is similar. The difference is who works the alerts. EDR gives you a console and a queue; MDR gives you analysts who triage, investigate and usually contain under pre-agreed rules. In published pricing the gap is often only a few dollars per endpoint per month, which is why the answer usually comes down to whether you have an out-of-hours rota.

How much should a 50-person business budget for endpoint security?

Using published list prices in October 2026, EDR at Microsoft’s USD 3.00 per user per month is around USD 150 a month, and managed detection at roughly USD 8 per endpoint per month in Huntress’s own 100-endpoint example is around USD 400. Add the cost of someone’s time to run the EDR option, and the two land closer together than the invoices suggest.

Will EDR or MDR stop ransomware?

They substantially improve your odds by catching the activity that precedes encryption, and modern platforms will isolate a host automatically. They are not a guarantee. Immutable backups you have restored from, prompt patching and multi-factor authentication on remote access remain the controls that decide how bad a ransomware incident gets.

Do we still need antivirus if we have EDR?

You have it already. Every serious EDR product includes prevention, usually described as next-generation antivirus, so you are not running two products. What you should avoid is layering two prevention agents from different vendors on the same machine, which causes conflicts and slows the device without improving detection.

Not sure whether you need EDR, MDR or just better patching? We will look at your estate and your out-of-hours cover and give you a straight recommendation. Get in touch with Eudora Technology to talk about your project.

Sources

  1. Cost of a Data Breach Report 2026 IBM · July 2026
  2. AI-powered adversaries and the enterprise risk challenge IBM · July 2026
  3. Software vulnerabilities are now the top breach entry point, 2026 DBIR finds Verizon · 19 May 2026
  4. M-Trends 2026: data, insights and strategies from the frontlines Google Cloud / Mandiant · 2026
  5. Microsoft Defender for Business pricing Microsoft · accessed October 2026
  6. CrowdStrike Falcon Go pricing CrowdStrike · accessed October 2026
  7. Huntress pricing Huntress · accessed October 2026
  8. Cyber guidance for small businesses CISA · accessed October 2026
Keep reading

Related insights