If suspicious activity appears at 3 AM, who sees it? Who decides whether it is a real threat? Who takes action?
Those questions are a good place to start.
The short answer
EDR is technology that detects and responds to suspicious activity on endpoints such as laptops, desktops and servers.
MDR adds people who monitor security activity, investigate threats and help respond to them as a managed service.
So the buying question is not simply:
EDR or MDR?
A better question is:
Do we have the people, time and coverage to operate endpoint security ourselves?
If you do, running EDR internally may make sense.
If you do not, MDR may fill a gap that buying more security software will not solve.
Start with the 3 AM question
Imagine one of your laptops begins showing suspicious activity at 3 AM on Sunday.
Your EDR may detect it.
Then what?
Someone still needs to decide whether the activity is dangerous and what should happen next.
Ask four questions:
- Who watches the alerts?
- Who investigates them?
- Who is available nights and weekends?
- Who is allowed to act?
A service that sends your team an alert is different from one that investigates the alert and can take agreed action for you.
Know which one you are buying.
What real buying decisions show
We reviewed documented buying decisions from organizations using EDR and MDR.
These examples do not prove that MDR is right for every company. Most were published by the vendor or service provider involved, so they are not independent product tests.
But they do show why these organizations said they wanted outside help.
RAFTRx: 600 endpoints, two people in IT
RAFTRx had about 600 protected endpoints and a two-person IT department. The company was also growing through acquisitions.
It chose Huntress Managed EDR and other managed security services.
The important part is the staffing situation: two people were responsible for IT while the company continued to grow.
Question for a buyer: If you have hundreds of endpoints but only a few people responsible for IT and security, who handles security when they are unavailable?
Source: Huntress customer story. Vendor-published.
The Third Floor: 1,100 endpoints and 250 servers
The Third Floor had a small IT and security staff protecting 1,100 endpoints and 250 servers.
Its previous setup used SentinelOne through an outside provider. The company said false positives were creating investigations and manual work for its internal team.
It moved to CrowdStrike Falcon and Falcon Complete MDR.
This case shows that simply having a managed provider does not automatically remove the burden from your team.
Question for a buyer: What will the provider handle, and what work will still come back to your people?
Source: CrowdStrike customer story. Vendor-published.
International business-services provider: more than 1,600 endpoints
An international business-services company had 400 employees and more than 1,600 endpoints.
The company reported gaps in security staffing and expertise. It selected Cybereason EDR with MDR.
The useful point is not that Cybereason was necessarily the best product. The source cannot establish that.
The useful point is that the company treated MDR partly as a staffing decision.
Question for a buyer: Are you shopping for better endpoint software, or are you trying to fill a gap in people and expertise?
Source: Cybereason customer story. Vendor-published.
Global real-estate company: 3,300 endpoints, four security people
A global real-estate company had 1,600 employees, 3,300 endpoints and a four-person security team.
Its legacy antivirus setup was producing more alerts than the team could comfortably handle. It chose Cybereason EDR and MDR.
There is no universal rule for how many security people a company needs.
But this case shows why endpoint count alone does not tell us whether a company needs managed help.
Question for a buyer: How much security work is your team expected to handle, and what happens when that workload exceeds its capacity?
Source: Cybereason customer story. Vendor-published.
GMG: 3,500 endpoints and limited security skills
GMG had about 3,500 endpoints and said its internal team had limited security skills.
It moved from legacy antivirus to CrowdStrike Falcon Complete MDR.
Again, the decision involved more than endpoint software. The company also wanted outside security expertise.
Question for a buyer: Does your team have the time and expertise to investigate threats, not just administer the software?
Source: CrowdStrike customer story. Vendor-published.
Pella: 5,200 endpoints and 800 servers
Pella had about 5,200 endpoints and 800 servers.
It chose CrowdStrike products including Falcon Complete MDR.
Pella said that building comparable round-the-clock coverage internally would have required hiring, training and retaining six additional full-time employees.
That does not prove MDR is cheaper for every organization.
It does show what Pella was comparing the service against: not just another software license, but the cost of building more internal security capacity.
Question for a buyer: When comparing MDR with running EDR yourself, are you including the real cost of staffing the internal alternative?
Source: CrowdStrike customer story. Vendor-published.
Endpoint count is not enough
It would be convenient if there were a rule like:
Under 1,000 endpoints: use EDR.
Over 1,000 endpoints: use MDR.
Our evidence does not support one.
A company with 600 endpoints and two IT people may have a bigger coverage problem than a much larger company with a staffed security team.
Endpoint count matters. But so do:
- the number of people available
- their security experience
- whether anyone is covering nights and weekends
- how much alert and investigation work they can handle
- who has authority to respond
Two companies can have the same number of endpoints and very different security needs.
Already paying for Microsoft Defender?
Before buying another EDR product, ask:
What endpoint security are we already paying for?
This matters especially for organizations with Microsoft licensing.
Venerable had more than 1,000 endpoints, Microsoft 365 E5 and a small security team.
According to its MDR provider, Venerable used Microsoft Defender for Endpoint and added eSentire for 24/7 managed detection and response rather than continuing to pay for overlapping endpoint protection.
Source: eSentire customer story. Vendor-published.
That does not mean every Microsoft customer should choose Defender.
It raises a useful question:
Is our bigger gap the endpoint software, or the people operating it?
If you already own endpoint protection through Microsoft, find out exactly what your license includes before paying for another product.
Then decide whether your remaining problem is technology, monitoring and response, or both.
When running EDR yourself may make sense
Running EDR internally may make sense if you have people who can:
- monitor it consistently
- understand and investigate alerts
- respond quickly
- cover the hours you need covered
- maintain and tune the system
The important part is having a clear owner for those jobs.
When MDR deserves a closer look
MDR deserves a closer look if:
- security is only one of many jobs your IT people handle
- nobody is truly watching after hours
- your team is already overloaded by alerts
- you lack people with threat-investigation experience
- hiring security specialists is difficult or too expensive
- your EDR works, but your team does not have enough time to operate it well
Do not assume every MDR service does the same thing.
Some may mainly alert you. Others may investigate and take agreed actions.
Ask exactly what happens after a threat is detected.
10 questions to ask an MDR provider
- Who monitors our environment at night and on weekends?
- What happens when you believe an endpoint is compromised?
- Can you isolate a device without waiting for us?
- What can you do without our approval?
- What still requires someone on our team?
- How quickly do you begin investigating an alert?
- Which parts of our environment do you monitor?
- Does the service work with the endpoint security we already own?
- Who handles false positives and tuning?
- If an incident becomes serious, where does your responsibility end and ours begin?
These questions help define what you are actually buying.
The decision
Do not start with:
Which EDR product should we buy?
Start with:
Who is going to operate our endpoint security?
If you already have the people, expertise and coverage, operating EDR internally may be enough.
If you have the technology but not enough people to watch, investigate and respond, MDR may solve the more important problem.
And if you already own endpoint protection through Microsoft or another product, understand what you have before paying for overlapping software.
Our evidence does not give us a universal endpoint cutoff or a single answer that works for everyone.
It does give us a useful place to start:
Know who is responsible when something happens at 3 AM.
Then compare the products and services that fit that operating model.
About the evidence
This guide currently uses documented buying decisions from RAFTRx, The Third Floor, Venerable, an international business-services provider, a global real-estate company, GMG and Pella.
Most of these records come from customer stories published by the vendor or service provider involved. They can help document the buyer's situation and stated decision. They do not independently prove that the product or service chosen was better than the alternatives.
When a source does not disclose something, we leave it undisclosed.
We will update this guide when new evidence gives us a reason to change it.