If you have started shopping for security help, you have probably hit a wall of three-letter acronyms — EDR, MDR, XDR, MSSP, SOC — used almost interchangeably by people selling different things. This guide untangles the one that matters most for a small business, and tells you what to ask before you sign anything.
The short version
MDR is security software plus the people who watch it.
That is the whole idea. You can buy excellent detection software and install it on every laptop in your company, and it will faithfully generate alerts. The question MDR answers is: who reads them?
At enterprise scale the answer is an in-house security operations centre. Round-the-clock coverage takes a minimum of five or six analysts once you account for shifts, holidays and turnover, which puts an internal SOC out of reach for almost any business under a few hundred staff. MDR is how that capability gets sold by the seat instead.
What you actually get
A real MDR service includes all five of these. If a provider is missing one, that is worth knowing before you buy, not after.
1. Detection tooling deployed and maintained. An agent on every endpoint, and increasingly on your Microsoft 365 or Google Workspace tenant too, because identity is now where attacks start. The provider owns keeping it deployed, updated and actually reporting.
2. 24/7 human investigation. Every detection gets triaged by an analyst. This is the part that separates MDR from a dashboard subscription. Most alerts are benign, and the value is in someone competent deciding which are not — at 3am on a Sunday, without calling you first.
3. Authorised response. The provider can isolate a compromised endpoint from the network, terminate a malicious process, or disable an account, without waiting for approval. This is the single most important thing to confirm. Containment that waits for a human at your end to wake up and reply is not response, it is a notification with extra steps.
4. Threat hunting. Proactively looking for attackers who got in without tripping an alert — persistence mechanisms, footholds, rogue mailbox rules. Good MDR finds things no detection fired on.
5. Reporting you can actually use. What was seen, what was contained, what it means. You will need this for cyber-insurance renewals and client security questionnaires whether you want it or not.
EDR vs MDR vs MSSP vs XDR
The distinction that matters is who does the work, not the acronym.
| What it is | Who responds | |
|---|---|---|
| EDR | Endpoint detection software | You |
| MDR | EDR plus a 24/7 SOC | The provider |
| MSSP | Managed security tooling, broadly | Traditionally alerts you; varies |
| XDR | Detection across endpoint + identity + cloud + network | Depends — it's a data scope, not a service |
EDR is covered properly in our guide to what EDR is and how it differs from antivirus. Short version: antivirus matches known-bad files, EDR watches behaviour.
MSSP is the broader category — see what an MSSP is and what it costs. The historical difference is that an MSSP manages your tools and tells you when something fires; MDR contains it. That line has blurred, which is exactly why you should ask the question directly rather than trust the label.
XDR describes how much ground the detection covers, not whether anyone is watching. "XDR" with nobody reading it is still just software.
What MDR costs
Two pricing shapes are common.
Per endpoint. Roughly $10–$30 per endpoint per month for small-business MDR. For reference, published vendor rates sit at the bottom of that band before anyone manages them for you — Huntress lists Managed EDR at $7.99 per endpoint per month at a 100-endpoint tier, and CrowdStrike publishes Falcon Enterprise at $19.99 per device per month, with its fully managed Falcon Complete tier quote-only.
Per user, bundled. Roughly $25–$85 per user per month when MDR is folded into a managed security plan alongside email protection, identity monitoring, awareness training and backup. This is usually the better deal below about 100 staff, because per-endpoint pricing punishes you for the person with a laptop, a desktop and a tablet.
Two costs people miss:
- Minimums. Several vendors impose a 50-unit minimum for direct purchase. Under that, buying through a provider who already holds the licensing is cheaper than going direct.
- The gaps. MDR covers detection and response. It is not backup, not an email gateway, not a firewall. Budget those separately — see the coverage matrix on our managed cybersecurity page for exactly which vendor covers which.
Seven questions to ask a provider
These separate real MDR from a reseller with a dashboard. Ask them in this order.
- Will you contain a threat without calling me first? If the answer involves waiting for your approval, that is alerting, not response.
- What is your response time for a high-severity detection? You want a number with a unit attached, not "rapid."
- Who is actually in the SOC? Some providers resell another company's SOC. That is fine — but you should know whose analysts you are buying, and whether they are in-house or offshore.
- Does this cover Microsoft 365, or only endpoints? Email account takeover leaves no malware on any device. Endpoint-only MDR does not see it.
- What happens after containment? Who does the cleanup, the root-cause write-up, and the notification advice? Is that included or billed separately?
- Can I see a real detection report? Redacted is fine. A provider who cannot show you what their output looks like may not produce much.
- What is explicitly not covered? Any honest answer includes backup, firewall and email gateway. A provider who claims to cover everything is describing a product that does not exist.
Where MDR does not help
Worth being straight about. MDR reduces the time an attacker spends undetected in your environment. It does not:
- Replace backups. If ransomware encrypts your file server, containment stops the spread; restoring the data is a backup problem. No major EDR vendor sells backup.
- Stop the invoice fraud that involves no malware. If someone is tricked into wiring money to a fake supplier, no detection fires. That is a process and staff training problem.
- Fix unpatched software. Detection catches exploitation; patching prevents it. You need both.
- Cover what it cannot see. Personal devices, shadow SaaS and unmanaged servers are invisible to the agent that was never installed on them.
Is it worth it for a small business?
The honest test is not "can we afford MDR." It is: if something malicious ran on a company laptop at 2am tonight, what would happen?
For most businesses under 200 staff the accurate answer is nothing, until somebody notices in the morning — and by then an attacker who got in overnight has had eight hours to spread, establish persistence and find your backups. The measurable value of MDR is compressing that window from hours to minutes.
If you already have an internal team reading alerts around the clock, you do not need MDR. Almost nobody at this size does.
We run managed detection and response for Houston businesses, on a flat per-user plan alongside email security, identity protection, awareness training and tested backups. If you want to know what is actually running in your environment right now, our free security assessment will tell you — no cost, no obligation. See the full scope on our managed cybersecurity page, or read how it bundles with managed IT services.

Houston IT Developers
Houston IT Developers is a leading software development and digital marketing agency based in Houston, Texas. We specialize in web development, mobile apps, and digital solutions.
View all posts →Need Help With Your Project?
Our team of experts is ready to help you build your next web or mobile application. Get a free consultation today.
Get in Touch


