EDR (endpoint detection and response) is a technology: software on each laptop and server that records activity, raises alerts and lets an analyst isolate a device or stop a process. MDR (managed detection and response) is a service: a provider's analysts watch those alerts around the clock, investigate them and respond, usually running an EDR tool as their main sensor. So the real choice is rarely EDR or MDR. It is who operates the EDR, at what hours, and with what authority to act on your behalf.
The rest of this guide sets out the difference in one table, what each gives you and leaves with you, a checklist to choose by team size and hours of cover, and how a third option, a platform plus a smaller team, compares.
MDR vs EDR at a glance
| EDR | MDR | |
|---|---|---|
| What it is | Software: an agent on each endpoint plus a console for alerts, investigation and response actions | A service: people, process and a detection stack, which normally includes an EDR agent |
| Who operates it | Your own team, or whoever you assign | The provider's analysts, working with your nominated contacts |
| Hours covered | The agent records all the time, but alerts wait until someone looks | Round the clock is the norm for the service tier; check what the contract says for weekends and holidays |
| Response authority | Your analysts, using the tool's actions (isolate, stop process, quarantine) | Whatever the contract grants: some providers act directly, some guide your team |
| Typical pricing model | Subscription per device or per user, often with a public list price | Annual contract per endpoint or per user, usually quoted on request |
| What you still own | Everything: triage, investigation, response, tuning, reporting | Policy, high-impact decisions, recovery, systems outside scope and the provider relationship |
The table rows are the questions buyers ask most. The detail behind each one follows.
What EDR does, and what it leaves to you
An EDR agent collects detailed telemetry from each endpoint and turns suspicious patterns into alerts. Microsoft's documentation for Defender for Endpoint is a clear example. It says the product "continuously collects behavioral cyber telemetry", including process information, network activity, user logins and registry and file changes, stored for six months. When a threat is detected, "alerts are created in the system for an analyst to investigate" (Microsoft Learn).
That last phrase is the point. EDR is built for an analyst. Some products contain certain attacks automatically; Microsoft's, for instance, feeds an automatic attack disruption feature. Manual actions such as isolating a device or quarantining a file take a click. But the triage, the judgement about what an alert means and the decision to act all sit with a person. If no one is watching at 03:00 on a Sunday, the alert waits.
EDR is also not a guarantee of detection. In a peer-reviewed test of eleven EDR products against advanced persistent threat techniques, Karantzas and Patsakis found that the products they tested failed "to prevent and log the bulk of the attacks" in their scenarios (Journal of Cybersecurity and Privacy, 2021). The lesson is not that EDR is weak. It is that detection content needs tuning, hunting and review, which is people's work. Our guide to EDR covers how the technology works, and our EDR solutions comparison compares the leading products.
What MDR adds: people, hours and a response process
A managed detection and response service adds three things to the tool: analysts, the hours they cover, and a defined way of responding.
Microsoft describes its own service in terms that apply across the market: its analysts "manage your incident queue around the clock, triage and investigate incidents on your behalf, and either take action or guide your team through the response" (Microsoft Learn, Defender Experts MDR). CrowdStrike's pricing page describes Falcon Complete Next-Gen MDR as "24/7 expert-led" managed detection and response, sold as a separate tier above its EDR plans (CrowdStrike pricing).
NIST's incident response guidance, SP 800-61 Revision 3 (April 2025), treats this as a normal arrangement. It lists incident handlers who may be "on staff", "on contract (e.g., outsourcing a security operations center [SOC] to a managed security services provider [MSSP])", or available when needed. It calls the arrangement "a shared responsibility model in which the organization transfers some of its responsibilities to a provider", and says those responsibilities "should be clearly defined in a contract", including "authority to act on behalf of the organization" (NIST SP 800-61r3).
NIST also names the benefit and the risk. A provider "may detect malicious activity sooner" because it can correlate events across customers. But providers "often have privileged access to organizational systems", so the risk of a malicious insider or a compromised provider has to be considered.
What you still own with a managed service
Buying a service moves the work, not the accountability. Four things stay with you.
- High-impact decisions. NIST notes that leadership "may have decision-making authority on high-impact response actions, such as shutting down or rebuilding critical services". A provider can isolate a laptop. It should not decide alone to take your payment system offline.
- Anything outside scope. Read the service boundaries. Microsoft's, for example, state that neither of its MDR plans covers Defender for Cloud workloads, and that the service "doesn't provide incident response services for an active compromise", which is sold separately.
- Recovery and asset owners. Rebuilding systems, restoring data and telling the business what happened remain your jobs.
- The provider itself. Someone must review reports, challenge missed detections and renew or exit the contract.
Decision checklist by team size and hours of cover
Start from the hours you need covered and the people you have. Twenty-four hours a day, seven days a week is 168 hours. A full-time analyst works roughly 37 to 40 of them, before leave, sickness and training, so one seat covered at all hours takes more than four people. That arithmetic, not the tool, usually decides the answer. Our managed SOC vs DIY guide works through the rota in detail.
| Your situation | Likely fit | What to watch |
|---|---|---|
| No dedicated security staff; IT generalists only | MDR, on the provider's sensor or your existing EDR | Name one internal owner for decisions and the contract |
| One to three security people, office hours | EDR run in-house by day, MDR or a co-managed service out of hours | Clear hand-over rules between your team and the provider |
| Four to eight security people | EDR in-house with an out-of-hours service, or a platform that automates triage | Whether the team spends its time on triage or on improvement |
| A staffed 24/7 SOC | EDR in-house; an incident response retainer for surge | Detection coverage and tuning, not staffing |
Before you sign anything, answer these questions:
- Who acts on a critical alert at 03:00 on a Sunday, and how quickly?
- Which response actions may the provider take without asking, and which need your approval? Get this in the contract, as NIST advises.
- Which data sources are in scope beyond the endpoint: identity, email, cloud, network?
- Does the service require a particular EDR, and what happens to your existing licence?
- What incident response help is included, and what is a separate engagement?
- How will you measure the service: time to acknowledge, investigate and contain, on your own data?
- How do you get your data and detection history out if you leave?
The UK picture suggests many organisations face this choice. The government's Cyber Security Breaches Survey 2025 found that 44% of businesses, and 68% of medium businesses, had an external cyber security provider, while only 53% of medium businesses had a documented incident response plan. The 2025 skills study found nearly half (49%) of businesses had a basic skills gap. A managed service fills a staffing gap. It works best when you have the incident plan it plugs into.
How a platform plus a smaller team compares
There is a third option between running EDR yourself and handing operations to a provider: a platform that automates most triage and investigation, so a small in-house team owns the decisions without a full rota.
| EDR run in-house | MDR | Platform plus a smaller team | |
|---|---|---|---|
| Who triages | Your analysts | Provider's analysts | Automation, with your team reviewing |
| Who decides | Your team | Provider within contract; you for high-impact actions | Your team, within policy you set |
| Context about your business | High | Depends on onboarding and contacts | High |
| Out-of-hours cover | Only if staffed | Included | Automated containment within policy; an on-call owner still needed |
| Main risk | Alert backlog and burnout | Scope gaps and unclear authority | Automation acting beyond its intended scope |
The platform route keeps the context and the decisions in-house. It does not remove the need for an on-call person, and automation has to be governed: every automated action should be bounded by policy and leave a record. Our explainer on the AI SOC sets out how to judge that. Many organisations combine routes, for example a platform by day and a managed service at night.
Where SenseOn fits
SenseOn is a platform, not a pure MDR service, and it is one option among several. Its Universal Sensor is a single agent that captures endpoint, network and identity telemetry on Windows, macOS and Linux, and its antimalware has a dual-running mode designed to operate alongside another real-time scanner, so it can run beside an EDR you already own. In the AV-Comparatives Business Security Test March-June 2024, SenseOn recorded 95.9% in the Real-World Protection Test and 98.7% in the Malware Protection Test, with zero false alarms.
On triage, SenseOn reports that 92.5% of cases across customer environments over a rolling 30-day window are resolved by AI under human governance, with people making the consequential decisions. Across its managed-service customer environments, the mean time to detect and respond is under 20 minutes over a rolling 30-day window. Pricing is an annual pool of Flex Intelligence Credits, with no per-GB charge for sensor telemetry. The method behind each figure is on the proof points page.
Sources
- National Institute of Standards and Technology, A. Nelson, S. Rekhi, M. Souppaya, K. Scarfone, SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, April 2025, accessed 23 September 2026 (full text: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf)
- George Karantzas, Constantinos Patsakis, "An Empirical Assessment of Endpoint Detection and Response Systems against Advanced Persistent Threats Attack Vectors", Journal of Cybersecurity and Privacy, 2021, https://doi.org/10.3390/jcp1030021 (open access preprint: https://arxiv.org/abs/2108.10422)
- Microsoft Learn, Overview of endpoint detection and response capabilities (Microsoft Defender for Endpoint), accessed 23 September 2026
- Microsoft Learn, What is Microsoft Defender Experts MDR?, updated 7 August 2026, accessed 23 September 2026
- CrowdStrike, Falcon pricing (US site, prices in USD), accessed 23 September 2026
- Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025, 10 April 2025, accessed 23 September 2026
- Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025, accessed 23 September 2026
- AV-Comparatives, Business Security Test March-June 2024, published 15 July 2024, accessed 23 September 2026
How SenseOn writes, checks and corrects its content: editorial standards.
Frequently asked questions
Is MDR better than EDR?
Neither is better in general, because they are different things. EDR is the tool that records endpoint activity and lets someone respond. MDR is a service in which a provider's analysts use tools like EDR on your behalf, around the clock. If you have people who can triage and respond at every hour you need cover, EDR on its own can be enough. If you do not, EDR without someone watching it leaves alerts unread out of hours, and a managed service or a more automated platform closes that gap.
Do I still need EDR if I buy MDR?
Usually yes. Most managed detection and response services run on an endpoint agent, either their own or one you already license, and some require a specific product. Ask the provider which sensor the service depends on, whether your existing EDR licence is supported, and who pays for it.
Can MDR replace an in-house security team?
It can replace the round-the-clock monitoring and first response, but not the ownership. NIST SP 800-61r3 describes outsourcing a SOC as a shared responsibility model in which the division of duties, including the authority to act on your behalf, should be set out in the contract. Someone inside the organisation still owns risk decisions, recovery, asset owners and the provider relationship.
How is MDR priced?
Most providers quote per endpoint or per user on an annual contract, with tiers for the data sources and response actions included. Many do not publish prices: CrowdStrike lists Falcon Complete Next-Gen MDR as contact sales, and Microsoft sells Defender Experts MDR separately from its Defender products, through a customer interest form or its account team. EDR tools are more often listed; CrowdStrike's US pricing page showed Falcon Go at $59.99 per device per year, billed annually, when we checked on 23 September 2026.
Is MDR the same as an MSSP?
No. An MSSP traditionally manages and monitors security devices and forwards alerts; an MDR provider focuses on detection, investigation and response, usually with its own detection stack. The line has blurred and some firms offer both. Our MDR vs MSSP guide compares the two models in detail.