Antivirus, EDR or MDR: which endpoint protection do you need?
The difference between signature antivirus, EDR and a managed detection service, and how to choose without overspending.
By the Telappliant team

Antivirus, EDR, XDR, MDR. The labels are used loosely and priced very differently. Here is what each layer genuinely does, and how to work out which one your business needs.
Signature antivirus
Traditional antivirus matches files against known-bad signatures and simple heuristics. It still catches commodity malware and it is not worthless, but it is blind to attacks that use legitimate tools, stolen credentials or code it has never seen before, which describes most serious intrusions.
EDR: recording behaviour, not just files
- Continuously records process, network and file activity on the endpoint
- Detects patterns of behaviour rather than known file hashes
- Lets a responder isolate a device from the network in one action
- Provides the timeline needed to answer what an attacker actually touched
- Supports threat hunting across the estate for indicators found elsewhere
MDR: the part most SMEs are actually missing
EDR produces alerts. If nobody triages them at 3am on a Sunday, the tool changes nothing, and that is precisely when ransomware is deployed. Managed detection and response puts an analyst team behind the tooling with an agreed mandate to contain, so the response happens in minutes rather than at the start of the next working day.
How to choose without overspending
- Check what you already own; Microsoft 365 E5 and Business Premium include capable tooling
- Be honest about who watches alerts out of hours, and whether they are allowed to act
- Match retention to the investigation you would need to run, not the cheapest tier
- Confirm coverage for servers, macOS and any Linux you quietly depend on
- Ask for the containment mandate in writing, not just the alerting SLA
What good looks like after deployment
Every endpoint reporting in, no long-term exclusions nobody can justify, tamper protection on, alerts triaged within an agreed window, and at least one rehearsed isolation test so you know the containment button works before you need it.



