Endpoint Protection for Small Business: AV vs EDR vs MDR
Antivirus, EDR, and MDR explained in plain English, with a decision table, what each costs, and the questions to ask before you buy endpoint protection.
Endpoint protection is the security software that runs on each computer, phone, and server your business uses. It comes in three tiers. Antivirus blocks malicious files and behavior on one device. Endpoint detection and response (EDR) adds a central console, a recorded history of what happened on each device, and the ability to isolate a machine. Managed detection and response (MDR) is EDR plus people who watch the alerts for you. Most small offices need at least managed antivirus with a console, and an office holding sensitive data should plan for EDR with a named person responsible for the alerts.
What counts as an endpoint?
An endpoint is any device a person or program uses to reach your business data: desktops, laptops, phones, tablets, and servers. Printers, cameras, and smart TVs sit on the network too, but they usually cannot run security software, so they are handled with network segmentation instead.
Start with a list. You cannot protect a laptop nobody remembers buying. For each device, write down who uses it, what operating system it runs, and what protection is installed today.
Antivirus, EDR, and MDR: what is the difference?
| Antivirus (including next-generation antivirus) | EDR | MDR | |
|---|---|---|---|
| What it does | Blocks known malware and suspicious behavior on the device | Records device activity, alerts on attack patterns, lets an admin investigate and isolate a device | EDR software plus a provider’s analysts who triage and respond to alerts |
| Where you manage it | On each device, or a simple console | Central console | Central console run by the provider |
| Who responds to an alert | The software, automatically | Someone you name | The provider’s analysts, then you |
| Typical fit | Very small office, low-sensitivity data | Offices with client, patient, or financial data | Offices that need alert coverage nobody in-house can give |
Antivirus is better than its reputation
Older antivirus compared files against a list of known bad signatures. Current products do more than that. Microsoft documents that Microsoft Defender Antivirus, which is built into Windows 10 and Windows 11, moved away from a static signature engine in 2015 and now uses machine learning, cloud lookups, and behavior monitoring, including for fileless attacks that never write a file to disk.
So the honest gap in a small office is rarely “the antivirus is weak.” It is that nobody can see all the devices in one place. Is protection turned on everywhere? Did a detection fire last week? Did anyone look at it? Unmanaged antivirus cannot answer those questions.
What EDR adds
EDR keeps a timeline of what happened on each device: which process started, what it launched, which files it touched, where it connected. When the pattern looks like an attack, EDR raises an alert in a central console. From there an administrator can see the whole chain, isolate the device from the network, and check whether other machines show the same signs.
This matters most for attacks that use legitimate tools already on the computer, such as PowerShell or remote management software. There is no malicious file to catch, only behavior that looks wrong in context.
CISA’s #StopRansomware Guide recommends using application allowlisting or EDR on all assets. It is a reasonable baseline for any office that holds data it cannot afford to lose or leak.
What MDR adds
EDR produces alerts. An alert nobody reads protects nothing. MDR is a service in which a provider’s analysts monitor your EDR console, sort real incidents from noise, and either act or notify you. When you compare MDR services, ask exactly which actions the provider will take on its own (isolate a device, disable an account) and which require your approval.
How do you choose for your office?
Work through these questions in order.
- What data is on the devices? Client tax files, patient records, and payment data raise the stakes. A shop with a point-of-sale tablet and no stored customer data has a different risk than an accounting office.
- Does a rule or contract require something specific? The FTC Safeguards Rule, HIPAA, and cyber insurance applications can all ask about endpoint security. Read the exact wording of your application or policy before buying.
- Who will look at alerts? If the answer is “nobody,” EDR alone will not help. Either name a person (inside the business or an IT provider) or choose MDR.
- What do you already own? Check your licenses before you shop. Microsoft 365 Business Premium already includes an EDR product, covered below.
- What platforms do you run? Confirm the product covers every operating system in your inventory, including Macs and phones if they hold business data.
A rough guide: one to five people with low-sensitivity data can do well with built-in antivirus that is centrally managed and checked. Five to fifty people with sensitive data should plan for EDR with clear alert ownership. If a breach would trigger legal notification duties and nobody is available to respond, look at MDR.
What does endpoint protection cost?
Microsoft Defender Antivirus is included with Windows at no extra charge. For EDR, Microsoft lists Defender for Business at $3.00 per user per month, paid yearly, as of September 2026, covering up to five devices per user. The same product is included in Microsoft 365 Business Premium, listed at $22.00 per user per month, paid yearly, as of September 2026. Our Defender for Business guide covers what is in it and how setup works.
Other EDR products are priced per device or per user, and MDR services are generally priced by quote. Get written quotes and compare the same term length and device count.
The subscription is the smaller cost. Budget time for deployment, tuning out false alarms, and reviewing alerts every week.
Questions to ask any endpoint protection vendor
- Which operating systems and versions are covered, and are phones included?
- Can a device be isolated remotely, and who is allowed to do it?
- How long is device activity history kept?
- What happens when a laptop is off the office network?
- Does it report missing patches or risky software?
- How are alerts delivered, and can they go to more than one person?
- What does removal look like if we switch products later?
- For MDR: what hours are covered, and what actions are taken without asking us?
Common mistakes
- Running two antivirus products at once. They can conflict, and Microsoft notes that a non-Microsoft antivirus can leave Defender’s real-time protection turned off. Pick one primary product per device.
- Buying EDR without naming an alert owner. Decide who reads alerts and what they do before the software goes in.
- Leaving out Macs, phones, and servers. Attackers use the device you forgot. Servers often need a separate license.
- Assuming a license means protection. A subscription does nothing until devices are enrolled and policies are applied. Check the console, not the invoice.
- Treating endpoint protection as the whole plan. It does not replace patching, multi-factor authentication, or tested backups.
When you do not need more than built-in antivirus
If your office has a handful of Windows 11 or macOS computers, keeps its data in a cloud service protected by multi-factor authentication, stores nothing regulated locally, and installs updates promptly, built-in protection that you actually check may be enough. Spend the next dollar on backups and account security first. Revisit the decision when you add staff, start storing sensitive files on devices, or receive an insurance or client questionnaire that asks for EDR.
Common questions
Is Windows Security enough for a small business?
For a very small office with low-sensitivity data, Microsoft Defender Antivirus is a capable antivirus. What it lacks on its own is central visibility: no single console showing every device, no recorded activity history, and no remote isolation. Those arrive with a managed product such as Defender for Business or another EDR platform.
Do Macs need endpoint protection?
Yes, if they hold business data. macOS includes built-in malware defenses, but Macs are still exposed to phishing, malicious downloads, and stolen credentials. Many EDR products support macOS. Confirm platform coverage before buying so the Macs appear in the same console as the Windows devices.
Will EDR slow down our computers?
Modern agents are designed to run in the background, and most users notice nothing. Problems usually come from scanning conflicts with specialized software such as accounting, imaging, or design tools. Test on one or two machines first and add vendor-recommended exclusions only where they are documented.
Does endpoint protection stop phishing?
Partly. It can block a malicious attachment or a known bad site, but it cannot stop someone from typing a password into a convincing fake page. Pair it with email filtering, multi-factor authentication, DNS filtering, and short staff training on how to spot phishing emails.
How we can help
Coastal Growth Co. can inventory your devices, check what your current licenses already include, deploy and tune endpoint protection, and agree with you on who owns the alerts. This can be a one-time project or part of ongoing managed IT support. Scope and price are agreed before any paid work. Contact us to talk through your setup.
- endpoint protection
- EDR
- antivirus
- MDR
- cybersecurity
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward