If a vendor, an insurer or your IT provider has told you that antivirus is no longer enough, this guide explains what they mean. It covers EDR vs XDR vs antivirus in plain English, what each one costs to run, and which of them a UK business of your size needs.
The EDR vs XDR question comes down to scope and who responds. Antivirus stops known and suspicious malware on a device. EDR records what happens on that device so an attack can be investigated and stopped. XDR joins that up with email, identity and cloud. MDR is people running any of them for you, around the clock.
EDR vs XDR is a question of scope. Endpoint detection and response records activity on each device, then lets an analyst isolate it or quarantine a file. Extended detection and response correlates those endpoint signals with email, identity, cloud and application data so one attack shows up as one incident.
What Is EDR?
EDR, or endpoint detection and response, records what happens on each device and gives an analyst the tools to investigate and respond. Microsoft’s own description of its EDR is that it continuously collects behavioural telemetry: process activity, network connections, logins, registry and file changes. Where antivirus blocks a file, EDR shows you the whole attack and lets you stop it.
The idea behind it is “assume breach”. Antivirus assumes it can stop the malware. EDR assumes something will get through and makes sure you can see it when it does. In Microsoft Defender for Endpoint, alerts that share an attacker or a technique are grouped into one incident, the telemetry is kept for six months on Plan 2, and Defender for Business and Plan 1 come with four manual response actions: run an antivirus scan, isolate the device, stop and quarantine a file, and block or allow a file by indicator.
What Is XDR?
XDR, or extended detection and response, extends detection and response beyond the device. Microsoft’s definition of its own XDR is a suite that “natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications”. The point is correlation: a phishing email, the login that followed it and the file dropped on a laptop become one incident.
Two things follow from that. First, XDR is only as wide as what feeds it. Microsoft’s documentation says Defender XDR correlates signals only from the Microsoft products you have licensed, so an XDR licence with nothing but endpoints attached is EDR with a different badge. Second, the extra value is in response: Microsoft’s cross-product features include a combined incident queue, self-healing of compromised mailboxes, identities and devices, and 30 days of raw signal for threat hunting. Transputec runs a Microsoft Sentinel SOC operated by Microsoft-certified analysts, and Sentinel is where this correlation happens for estates that mix Microsoft and non-Microsoft tools. The EDR vs XDR comparison below shows where the differences bite.
Choosing Between EDR and XDR? Start With Who Watches It
Transputec's MDR security services monitor Microsoft Defender for Endpoint, CrowdStrike and SentinelOne 24/7/365 from a UK-staffed team, with pre-authorised containment and weekly proactive threat hunts. Talk to our team about the security work behind your endpoint decision.
Get a Strategic ConsultationIs EDR Better Than Antivirus?
Yes, at what it does, but it doesn’t replace antivirus and you need both. Antivirus is prevention: it blocks malware before or as it runs. EDR is detection and response: it assumes some attacks get past prevention and gives you the recording and the controls to deal with them.
Antivirus has moved on from signatures. Microsoft says its Defender Antivirus dropped the static signature engine in 2015 for machine learning and cloud intelligence, blocks almost all malware at first sight and can stop threats from their behaviour even after they start running. That is a good prevention layer, and it’s the layer Cyber Essentials asks for. The NCSC’s Requirements for IT Infrastructure v3.3 (April 2026) needs anti-malware that’s kept updated, prevents malware from running and blocks connections to malicious websites. It does not ask for EDR. Our guide to the 5 Cyber Essentials controls covers the rest.
Insurers are the ones asking for EDR. Their proposal forms ask for endpoint detection and response on every device, as our post on cyber insurance requirements explains. So the endpoint protection vs antivirus question is settled for most businesses: run antivirus and EDR together. In Microsoft’s range that means Defender for Business or Defender for Endpoint Plan 2, because Plan 1 has no EDR. Modern products bundle the two, which is why endpoint protection vs antivirus is mostly a question of what you switch on.
What Is the Difference Between EDR, XDR and MDR?
EDR and XDR are technology. MDR is a service. EDR watches devices, XDR watches devices plus email, identity, cloud and applications, and MDR is a team of analysts running either of them for you 24/7. You can buy XDR and still have nobody reading it at 3am, which is the gap MDR exists to close.
Here is the EDR vs XDR vs antivirus comparison, with MDR alongside because it is usually the real question:
| Question | Antivirus | EDR | XDR | MDR |
|---|---|---|---|---|
| What is it? | Prevention software on the device | Detection and response software on the device | Detection and response across endpoints, identity, email, cloud and apps | A service: analysts operating EDR or XDR for you |
| What does it watch? | Files and processes as they run | Everything the device does: processes, network, logins, registry, files | The same, joined with email, identity, cloud and app signals | Whatever platforms you run, plus network and SaaS sources |
| What happens on a hit? | Blocks or quarantines the file | Alerts an analyst, who can isolate the device or quarantine a file | Groups alerts into one incident and can self-heal mailboxes, identities and devices | Triages, investigates and contains on your behalf |
| Who operates it? | Nobody, once configured | Your IT or security team | A security team, usually with a SIEM | The provider’s SOC, 24/7 |
| Cyber Essentials? | Required (malware protection) | Not required | Not required | Not required |
| Microsoft example | Microsoft Defender Antivirus, built into Windows | Defender for Business, Defender for Endpoint Plan 2 | Microsoft Defender XDR portal | Microsoft Defender Experts MDR (Plan 2 needs 1,500 seats) |
| Cost basis | Included with Windows | From £2.30 per user per month with Defender for Business | No extra cost with Business Premium or Defender for Business; a separate product from other vendors | Per endpoint per month, priced by hours of cover |
The MDR column is where Transputec sits. Our MDR security services take telemetry from endpoint, identity, network, cloud and SaaS, and pre-authorised UK responders contain confirmed intrusions on your behalf, with a median time-to-contain of 11 minutes. Microsoft’s own MDR service, Defender Experts, exists too. Its Plan 2 needs at least 1,500 licensed seats, which tells you who it was built for.
EDR vs XDR: Which One Do You Need?
Start with EDR on every device, then add XDR when the attacks you worry about start somewhere other than the device. For most UK businesses that is true: phishing was the most common attack type in the government’s 2025/26 breaches survey, at 38% of businesses, and phishing arrives by email and lands on an identity before it touches an endpoint.
A practical way to settle the EDR vs XDR question:
- EDR is enough for now if your risk sits mostly on devices, email is covered by Defender for Office 365 or similar, and a named person reads the EDR alerts every working day.
- You need XDR-style correlation if one phishing email could reach a mailbox, a login and a file share, and you want those to show as one incident with the accounts and devices contained together.
- You need MDR if nobody is on duty outside working hours. Detection without a response is an audit trail.
If you hold Microsoft 365 Business Premium or Defender for Business, check what you have before buying anything. Both are on Microsoft’s list of licences that open the Defender XDR portal at no extra cost, and the portal correlates whichever Microsoft products you have licensed. With Business Premium that means Defender for Business on the devices and Defender for Office 365 Plan 1 on email, in one incident queue. Our Microsoft Defender for Business guide lists exactly what that licence includes.
Do Small Businesses Need XDR?
Most small businesses need EDR, email protection and someone watching both. Those on Microsoft 365 Business Premium get XDR-style correlation with the licence they hold, and rarely need a separate XDR platform. The figures explain why: 43% of UK businesses identified a breach or attack last year, 81% run up-to-date malware protection, and only 32% use security monitoring tools.
Those three numbers come from the Cyber Security Breaches Survey 2025/26, published by DSIT and the Home Office on 30 April 2026, and they describe the gap. Prevention is nearly universal. Watching is not. The survey also found that just 25% of businesses have a formal incident response plan, so when EDR does raise an alert, three in four have no formal plan for what happens next. Among medium businesses the breach figure rises to 65%, and among large ones to 69%.
So for a 40-person firm, the EDR vs XDR debate is usually the wrong one. The right questions are whether every device has EDR switched on, whether email and identity signals land in the same console, and who is on duty when the alert fires at 2am on a Sunday. Transputec’s managed SOC services exist for the third question: UK-staffed cover on every shift, a median of under 60 seconds to detect known attacker techniques and a median 4 minutes to triage a P1 alert.
Who Responds When EDR or XDR Raises an Alert?
Somebody has to, and that is the difference between EDR, XDR and MDR. Microsoft’s description of its MDR service is a good definition of the category: analysts manage your incident queue around the clock, triage and investigate on your behalf, and either take action or guide your team through the response. The tool finds it. The service deals with it.
Three things to check in any MDR contract, whichever platform sits underneath:
- Hours. 24/7/365 with named humans on shift. Transputec’s MDR security services run UK-staffed cover on every shift, with a median P1 acknowledgement under 4 minutes.
- Authority to act. Whether the provider can isolate a device or disable an account without waking you up. Pre-authorised containment is what turns detection into response, and our median time-to-contain a confirmed intrusion is 11 minutes.
- Sources. Whether the service reads only the EDR, or endpoint, identity, network, cloud and SaaS telemetry together. The second is XDR in practice, whatever the platform is called.
Pricing is per endpoint per month and driven mostly by the hours of cover. Our post on how much a managed SOC costs works through the bands, and the managed SOC cost calculator gives you a figure for your estate. For the broader definition of the service, our earlier explainer on managed detection and response still applies.
Your EDR vs XDR Checklist
Use this before you sign for anything with “detection and response” in the name.
- Confirm antivirus is active on every device, updated in line with the vendor’s guidance, and set to block malicious websites. That is the Cyber Essentials control.
- Confirm EDR is licensed and switched on for every device, including servers. Defender for Business includes it; Defender for Endpoint Plan 1 does not.
- Name the person who reads EDR alerts during working hours, and write down what they’re allowed to do.
- Check whether your Microsoft licence already opens the Defender XDR portal before buying a separate XDR product.
- Make sure email and identity signals land in the same incident queue as device alerts.
- Decide who covers nights and weekends. If the answer is nobody, the EDR vs XDR choice matters less than the MDR one.
- Ask any MDR provider for hours, authority to contain, telemetry sources, and median detect and contain times.
- Write the formal incident response plan that 75% of UK businesses don’t have, and tie it to the alerts.
Conclusion
EDR vs XDR is a scope decision, and for most UK businesses the order is fixed: antivirus on every device because Cyber Essentials requires it, EDR on every device because insurers ask for it, XDR-style correlation because phishing starts in the inbox, and MDR because a tool nobody watches is only a log. The acronym you buy matters less than whether anyone responds.
Transputec runs both sides of this. Our cyber security services include a 24/7/365 UK-staffed SOC, a Microsoft Sentinel SOC operated by Microsoft-certified analysts, and MDR across Microsoft Defender for Endpoint, CrowdStrike and SentinelOne, with more than 50,000 endpoints monitored. The work is operating whichever platform you already own and putting people behind it.
If an insurer, an auditor or a board member has asked whether you have EDR or XDR, talk to us about the security work behind your answer.
FAQs
What Is the Difference Between EDR and Antivirus?
Antivirus prevents: it blocks known and suspicious malware on a device, and Cyber Essentials requires it. EDR detects and responds: it records what happens on the device so an attack that gets past prevention can be investigated, and lets an analyst isolate the device or quarantine a file. You need both, and most modern products bundle them.
Is XDR Included in Microsoft 365 Business Premium?
Microsoft 365 Business Premium and Defender for Business are both on Microsoft’s list of licences that give access to the Defender XDR portal at no extra cost. The portal correlates the Microsoft products you have licensed, so with Business Premium that means Defender for Business on devices and Defender for Office 365 Plan 1 on email in one incident queue.
Is MDR the Same as XDR?
No. XDR is technology that correlates signals across endpoints, identity, email, cloud and applications. MDR is a managed service in which analysts monitor, triage, investigate and respond on your behalf, usually 24/7. Transputec’s MDR security services take telemetry from endpoint, identity, network, cloud and SaaS and contain confirmed intrusions with pre-authorised UK responders.
Does Cyber Essentials Require EDR?
No. The NCSC’s Requirements for IT Infrastructure v3.3 (April 2026) requires malware protection: anti-malware software that is updated in line with the vendor’s recommendations, prevents malware from running and prevents connections to malicious websites, or application allow-listing. EDR is not part of the standard, although cyber insurers ask for it.
Which Microsoft Licences Include EDR?
Microsoft Defender for Business, which is included in Microsoft 365 Business Premium or sold standalone at £2.30 per user per month, includes EDR. Defender for Endpoint Plan 2 includes it with six months of data retention. Defender for Endpoint Plan 1 does not include EDR. Start by checking which of these you hold.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



