If nobody in your business is paid to read security alerts, buy a managed service. That is the whole decision in one sentence. Antivirus stops the malware it recognises, endpoint detection and response records what happened and raises an alert, and managed detection and response puts somebody else’s analysts on the end of that alert at three in the morning. The tool matters less than whether a human will act on what it finds.

The short answer
Three rules of thumb cover most situations. Under about ten devices with no IT staff, a current operating system, automatic updates, multi-factor authentication and the antivirus already built into your platform will carry you a long way. Between roughly ten and fifty devices, add EDR, because you need the recording even if you cannot watch it continuously. Above that, or in any regulated or high-value business, buy MDR, because an alert nobody reads is a line item rather than a control.
That is not a sales position. Two of the three options in this article cost less than a phone contract, and the most common mistake we see is not underspending but buying a capable platform and then leaving its console unopened for months.
What the three things actually are
The three categories overlap in marketing and differ sharply in what they ask of you.
- Antivirus, or next-generation antivirus. Prevention. It inspects files and behaviour and blocks what it judges malicious. Modern versions use behavioural models rather than signatures alone, and the good ones are genuinely effective at the commodity end of the threat spectrum.
- EDR, endpoint detection and response. Visibility plus a record. It logs process launches, network connections, credential access and file changes, correlates them into a timeline, and raises alerts. It also gives you the ability to isolate a machine and hunt backwards through history after the fact.
- MDR, managed detection and response. The same telemetry with a staffed security operations centre attached. Someone else triages the alerts, investigates the ambiguous ones, and in most offerings takes containment action under rules you agreed in advance.
The important difference is not the acronym but the obligation. EDR hands you an alert queue. If you have no rota to work that queue, you have bought a very good flight recorder for a crash nobody will notice. CISA made this point in its published lessons from an incident response engagement: among three findings, EDR alerts not being continuously reviewed sat alongside unpatched vulnerabilities and an untested incident response plan.
- Who looked at your security console yesterday? If the answer is nobody, EDR alone is the wrong purchase.
- If a laptop were compromised at 2 a.m. on a Sunday, who would isolate it, and how long would that take?
- Could you reconstruct what an attacker did last Tuesday? If not, you need the recording that EDR provides.
Why detection matters more than it did five years ago
Two pieces of recent research explain why prevention alone stopped being a complete answer. Mandiant’s M-Trends 2026 found that global median dwell time, the gap between an attacker getting in and being discovered, rose to 14 days from 11 the year before. At the same time, the median delay between an initial access broker gaining a foothold and handing it to a second group collapsed to 22 seconds, down from more than eight hours in 2022.
Read those three numbers together and the shape of the problem is clear. Attackers move in seconds and then wait. Organisations are getting better at finding them, with internal detection now accounting for 52% of cases against 43% the year before, but a fortnight is still a long time to be sharing your network with someone. Detection and response is what shortens that window; prevention alone cannot, because the thing you are looking for already got past it.
The money side has moved in the same direction. IBM’s 2026 Cost of a Data Breach Report puts the global average at USD 4.99 million, a 12% rise and a record for the study, and reframes that as roughly USD 1,100 for every hour an incident runs. The same report found AI-driven attacks up 56% year on year, with one in four malicious breaches AI-enabled and those averaging around USD 6 million.
One caveat on that average, since it gets quoted carelessly. It is drawn from organisations large enough to participate in the study, so it is not a prediction for a twenty-person business. Use it as a direction of travel and for the per-hour framing, not as your expected loss.

What they cost, using published prices
Published list prices make this comparison concrete. Everything below was on the vendor’s own pricing page in October 2026, and all three vendors publish rather than quote, which is itself worth something when you are a small buyer.
| Option | Category | List price | Who works the alerts | Notable limits |
|---|---|---|---|---|
| Microsoft Defender for Business | EDR with next-generation antivirus | USD 3.00 per user / month, annual | You, in the Microsoft 365 security console | Up to 300 users, five devices each; servers need the separate add-on |
| Microsoft 365 Business Premium | The above, bundled with identity and device management | USD 22.00 per user / month, annual | You | Up to 300 users; a version without Teams lists at USD 18.79 |
| CrowdStrike Falcon Go | Next-generation antivirus with device control | USD 7.99 per device / month, or USD 59.99 per device / year | You | Capped at 100 devices; self-service purchase |
| Huntress Managed EDR | Managed detection and response | USD 7.99 per endpoint / month in the published 100-endpoint example | Their security operations centre, 24/7 | Priced per endpoint; Huntress notes the wider EDR market spans USD 2.99 to USD 184 per endpoint per month |
The useful surprise in that table is how small the gap is. Managed detection in the published example costs the same per endpoint as unmanaged next-generation antivirus from a well-known vendor, and about five dollars a month more than Microsoft’s own EDR. For a forty-device office the difference between EDR you will not watch and MDR somebody else watches is roughly USD 200 a month. Set that against IBM’s per-hour framing of incident cost and the argument is short.
The expensive option is not MDR. It is the alert queue nobody opened.
Two caveats on price. First, most MDR vendors do not publish, and the band quoted around the market runs from single digits to well over thirty dollars per endpoint per month depending on coverage and response guarantees, so get two written quotes rather than trusting a round number. Second, bundles change the arithmetic: if you already pay for Microsoft 365 Business Premium, you already own Defender for Business, and the question becomes whether to add a managed service on top rather than whether to buy a platform.
The question that decides it
Strip away the product comparison and one question decides your answer. When an alert fires outside working hours, what happens next? There are only three honest answers, and each maps to a purchase.
- Nothing happens until Monday. Buy MDR. You are paying for coverage, not software.
- Someone gets a notification and will look if it seems serious. This is the most common answer and the most dangerous, because it feels like coverage. EDR plus a written escalation rota, or MDR if the rota is fiction.
- We have a rota, a runbook and someone who has used the isolation button. EDR is appropriate. Keep the rota honest and rehearse it twice a year.
Whatever you buy, agree the response authority in writing before you need it. The most common delay we see in real incidents is not detection; it is twenty minutes spent deciding who is allowed to disconnect a director’s laptop from the network. Decide that in advance and the tooling gets to do its job.
What to buy at ten, fifty and two hundred endpoints
Three concrete recommendations, assuming the basics in the next section are already in place.
| Size | What we would buy | Roughly what it costs at list price | Why |
|---|---|---|---|
| About 10 devices, no IT staff | Built-in platform antivirus plus Defender for Business at USD 3.00 per user / month | Around USD 30 a month | You get the recording cheaply. Accept that nobody is watching live, and compensate with aggressive patching and MFA |
| About 50 devices, one generalist IT person | Managed detection and response, around USD 8 per endpoint / month in published examples | Around USD 400 a month | Your IT person cannot be on call permanently. Buy the hours rather than the hope |
| About 200 devices, or regulated data | MDR with contracted response times, plus EDR coverage on servers | Low thousands a month, quoted | At this size an incident has legal and contractual consequences, and you need evidence and documented response |
Notice there is no tier where we recommend buying the most expensive platform and configuring it once. Capability you do not operate is the worst value in security, which is also why we tell clients to start with the cheapest controls that need no attention at all.

The unglamorous work that comes first
CISA’s guidance for small businesses puts the fundamentals first, and the 2026 DBIR data explains why. Vulnerability exploitation became the top entry point at 31% of breaches, overtaking stolen credentials for the first time in the report’s nineteen years, with credential abuse at 13% and the human element present in 62% of cases. No endpoint product fixes an unpatched application or a shared administrator password.
- Multi-factor authentication everywhere it is available, starting with email and remote access. Free on every major platform and still the single highest-value control. We cover the practical rollout in our MFA guide.
- Automatic updates on operating systems and applications, with a monthly check that they actually applied. This is the control that addresses the 31% figure directly.
- Backups you have restored from. Not backups that reported success. Keep one copy where a compromised administrator account cannot reach it.
- A written incident response plan, which CISA recommends the leadership team review. Two pages is enough: who decides, who calls whom, what gets disconnected, where the backups are.
- Phishing resistance for your people, because social engineering still accounts for 16% of breaches. How to stop phishing attacks on your business covers what works and what merely annoys staff.
Those five cost almost nothing and remove most of the cheap attacks. Detection tooling then handles what gets through, which is the right division of labour and the right order of spending. If ransomware is your specific worry, our ransomware guide goes through the recovery side in more detail.
How we help
Eudora Technology works remotely with clients in several countries, and endpoint security is almost entirely remote work. Our cybersecurity service covers the decision in this article honestly: we will tell you when the free platform antivirus plus disciplined patching is enough, help you deploy and tune EDR when it is not, and sit alongside you while you evaluate managed providers. We do not resell a single vendor’s stack, so the recommendation follows your rota rather than our margin.
For businesses that also need on-site support in Sri Lanka, our local sister operation at eudora.lk handles that side. Everything described here, from deployment to the written escalation plan, we deliver without being in the building.
Frequently asked questions
Is built-in antivirus good enough on its own?
For a very small business with current operating systems, automatic updates, multi-factor authentication and tested backups, it is a defensible starting point. What it does not give you is a record. If you need to know what an attacker touched, or to isolate a machine remotely, you need EDR. Microsoft’s own EDR product lists at USD 3.00 per user per month, so the step up is small.
What is the real difference between EDR and MDR?
The telemetry is similar. The difference is who works the alerts. EDR gives you a console and a queue; MDR gives you analysts who triage, investigate and usually contain under pre-agreed rules. In published pricing the gap is often only a few dollars per endpoint per month, which is why the answer usually comes down to whether you have an out-of-hours rota.
How much should a 50-person business budget for endpoint security?
Using published list prices in October 2026, EDR at Microsoft’s USD 3.00 per user per month is around USD 150 a month, and managed detection at roughly USD 8 per endpoint per month in Huntress’s own 100-endpoint example is around USD 400. Add the cost of someone’s time to run the EDR option, and the two land closer together than the invoices suggest.
Will EDR or MDR stop ransomware?
They substantially improve your odds by catching the activity that precedes encryption, and modern platforms will isolate a host automatically. They are not a guarantee. Immutable backups you have restored from, prompt patching and multi-factor authentication on remote access remain the controls that decide how bad a ransomware incident gets.
Do we still need antivirus if we have EDR?
You have it already. Every serious EDR product includes prevention, usually described as next-generation antivirus, so you are not running two products. What you should avoid is layering two prevention agents from different vendors on the same machine, which causes conflicts and slows the device without improving detection.
Not sure whether you need EDR, MDR or just better patching? We will look at your estate and your out-of-hours cover and give you a straight recommendation. Get in touch with Eudora Technology to talk about your project.
Sources
- Cost of a Data Breach Report 2026
- AI-powered adversaries and the enterprise risk challenge
- Software vulnerabilities are now the top breach entry point, 2026 DBIR finds
- M-Trends 2026: data, insights and strategies from the frontlines
- Microsoft Defender for Business pricing
- CrowdStrike Falcon Go pricing
- Huntress pricing
- Cyber guidance for small businesses



