Skip to main content
Norvet MSP

Small Business Guide

What is MDR?

MDR is a security service where software watches your computers for attacks and a team of people watches the software. It builds on EDR, the software part. Below is what EDR, MDR, and security awareness training each mean, how they differ, and how to tell what your business needs.

The three terms, in plain English

  • EDR: Endpoint Detection and Response

    Software on each work computer that watches what programs are doing and raises a flag when something looks like an attack.

  • MDR: Managed Detection and Response

    EDR plus people. A security team reads the alerts, works out which ones are real, and acts on them or tells you what to do.

  • SAT: Security Awareness Training

    Short, regular lessons and practice phishing emails that teach your staff to spot scams before they click.

EDR: the software

Older antivirus mostly checks files against a list of known bad ones. EDR also watches behavior. If a program starts doing something an ordinary program should not do, like quietly locking up files, EDR can flag it even when that exact program has never been seen before.

The "endpoint" part just means the devices your people work on: laptops, desktops, and servers. EDR can usually help contain a problem, for example by cutting an affected computer off from the network so trouble does not spread.

The catch is that EDR produces alerts, and an alert only helps if a person reads it and acts on it.

MDR: the software plus the people

Most small businesses do not have someone whose job is to read security alerts. MDR fills that gap. A security team monitors the alerts for you, investigates which ones are real, and either responds or tells you exactly what to do.

The simplest way to remember it: EDR is the smoke detector, and MDR is the smoke detector plus someone who checks on it and calls you when it goes off.

MDR is not magic. It does not replace software updates, backups, or careful sign-in settings, and no provider can promise to stop every attack. What it can do is shorten the time between something going wrong and someone dealing with it.

SAT: helping your staff spot scams

Many attacks start with an email that looks real: a fake invoice, a password reset you did not ask for, a message that seems to come from the boss. Software catches a lot of these, but not all. Security awareness training teaches your team what to look for, and practice phishing emails show who could use a refresher.

It pairs well with EDR or MDR because the two cover different gaps: one protects the computer, the other helps the person using it.

Which one does your business need?

A fair rule of thumb: if someone on your team reads security alerts every day and knows what to do with them, EDR may be enough. If nobody does, you are paying for an alarm that rings in an empty building, and MDR is worth a look. Staff training makes sense either way.

Whoever you buy from, these questions will tell you what you are really getting:

  • Who looks at the alerts, and during what hours?
  • What can they do on their own (like cutting a laptop off the network), and what do they call me about first?
  • What happens on a weekend or holiday if something is found?
  • What do I get in writing afterward: a report, a summary, or just a ticket number?
  • What is included in the price, and what costs extra?

Want the full picture of what Norvet MSP does in this area? See business cybersecurity services or security awareness training. Not sure where you stand today? Start with a security assessment.

Common questions

What does EDR stand for?

EDR stands for Endpoint Detection and Response. An endpoint is any device your people work on, such as a laptop, desktop, or server. EDR is software that runs on those devices, watches for suspicious behavior, and can help contain a problem once it is spotted.

What does MDR stand for?

MDR stands for Managed Detection and Response. It takes the same kind of software as EDR and adds a team of people who monitor it for you, investigate what it finds, and respond or advise you on what to do next.

Is EDR the same as antivirus?

Not quite. Traditional antivirus mostly checks files against a list of known bad ones. EDR also watches behavior, so it can notice something harmful even when the file has never been seen before. Many EDR products also include antivirus-style protection.

What is the difference between EDR and MDR?

EDR is the tool. MDR is the tool plus a team that runs it for you. With EDR alone, someone at your business has to read the alerts and decide what to do. With MDR, that work is handled by the provider, within whatever limits you agree on.

Does a small business need MDR?

It depends on who would read the alerts. If you have a skilled IT person or team who checks them every day, EDR on its own can be enough. If nobody on your side is watching, an alert nobody reads protects very little, and MDR is worth a serious look. Cyber insurance applications and customer contracts may ask about this kind of protection, so check what yours require.

What is security awareness training?

Security awareness training (SAT) teaches your staff how to recognize phishing emails, fake invoices, and other common scams. Good programs are short and repeated, and they test people with practice emails so the lessons stick.

Will MDR stop every attack?

No. No security product stops everything. MDR is meant to catch problems earlier and shorten the time between "something is wrong" and "someone is dealing with it." It works best alongside updates, strong sign-in protection, backups, and trained staff.

Does Norvet MSP offer this?

Norvet MSP helps small businesses with cybersecurity, including computer protection and staff training. Tell us what you have in place today and we will say plainly what is covered and what is missing.

Not sure what you have today?

Tell Norvet MSP what is on your computers and who watches it. We will tell you plainly what is covered and what is not.