Managed EDR and MDR for Small Business: 2026 Buyer's Guide
Contents
- Executive summary
- What is managed EDR, and how is it different from MDR?
- Which managed EDR and MDR products are available to small businesses?
- How should a small business evaluate a managed EDR provider?
- Which managed EDR fits which business?
- Is Huntress worth it for a small business?
- Huntress or SentinelOne for an MSP?
- How do you roll out managed EDR in a small business?
- Frequently asked questions
- Recommendations
- Methodology and caveats
- Sources
Executive summary
A small business that cannot answer a security alert at night should buy managed EDR, and should judge providers on what their analysts are contractually allowed to do, not on the software. Managed EDR puts a vendor's security team behind the EDR agent on your devices: they sort real alerts from noise and contain threats, often before you hear about it. Across the 17 products in the database (last price check 2026-10-02), 3 include that 24/7 service in the base price and 2 sell it as an add-on.
The price gap is the cost of people. The cheapest published bundle with analysts included is $99.00 per seat per year (ThreatDown Elite). The cheapest self-managed antivirus is $30.00.
The buyer mistake this guide exists to prevent: paying for EDR, leaving it unwatched, and discovering after an incident that the alerts were there all along. The other expensive mistake is a "managed" service that only emails you.
Three questions decide between providers:
- Will the provider act, or only notify? Isolation and containment should be done by their analysts, in writing.
- What independent evidence backs the detection engine? Some bundles have no public lab result at all.
- Does it fit how your IT is run? An MSP-run business needs multi-tenant support and RMM integration; a regulated one needs a signed BAA.
What is managed EDR, and how is it different from MDR?
Managed EDR is endpoint detection and response software watched by the vendor's own security operations centre (SOC). MDR (managed detection and response) is the wider service category; Gartner defines it as remotely delivered SOC functions that detect, investigate and actively respond to threats. For a small firm shopping for device protection, the two labels usually mean the same purchase: an EDR agent on every device plus analysts who respond for you.
The difference is scope. Managed EDR watches laptops, desktops and servers. A broader MDR service may also watch email, Microsoft 365 sign-ins, firewalls and cloud workloads. Most small businesses start with endpoints because ransomware runs there.
EDR vs MDR vs XDR vs antivirus covers the wider set of acronyms.
Which managed EDR and MDR products are available to small businesses?
Three routes exist, and they suit different buyers.
Bundles with analysts in the base price. These are the simplest purchase for a business with no security staff:
| # | Product | Price at 10 seats | 24/7 managed response | Min seats | SMB Fit Score |
|---|---|---|---|---|---|
| 01 | $99.00 /endpoint/yr | Included | 5 | 52 | |
| 02 | Min 50 seats | Included | 50 | 35 | |
| 03 | Quote only | Included | 1 | 34 |
EDR with managed response sold on top. You buy the EDR licence, then add the vendor's managed service at extra cost: WatchGuard Endpoint Security 360, Webroot Business Endpoint Protection. Budget for both lines; the add-on price is usually quoted, not published.
Your MSP's own SOC. Some MSPs run round-the-clock monitoring on a third-party EDR. Get the hours and response actions into your contract with them.
Five capabilities separate these products for a managed purchase:
| Product | 24/7 managed response | Ransomware rollback | macOS | MSP multi-tenant | RMM/PSA integration |
|---|---|---|---|---|---|
| Add-on | Included | Included | Included | Included | |
| Included | Included | Included | Included | Included | |
| Included | Not offered | Included | Included | Included | |
| Included | Included | Included | Included | Included | |
| Add-on | Included | Included | Included | Included |
How should a small business evaluate a managed EDR provider?
Does the provider respond, or only alert?
This question outweighs every other. A managed response service takes action: it isolates an infected device, kills malicious processes, removes persistence, then tells you what it did. A service that only emails you an alert has handed the hard part back to you. Put three questions to every provider:
- Which actions will your analysts take without asking me first?
- What is your response time for a critical alert, and is it in the contract?
- Who do I speak to during an incident, and at what hours?
Published speed figures are not the same as a contractual commitment. Huntress advertises an 8-minute mean time to respond (MTTR) for Managed EDR, a marketing figure rather than an SLA. ThreatDown reports a median 5 minutes to detect and 19 minutes to contain for its MDR, from its own incident data, and offers contractual SLAs only with MDR Plus, not with Elite.
What independent evidence backs the detection?
Labs test software, not analysts, so only the EDR engine underneath has a public score. The bundles differ sharply:
| Product | AV-Test protection | AV-Comparatives protection | MITRE ATT&CK Evaluation |
|---|---|---|---|
| No public result | No public result | Participated 2024 Dated | |
| No public result | No public result | No public result | |
| No public result | No public result | 100% coverage 2025 |
Huntress Managed EDR has no public AV-Test, AV-Comparatives or MITRE ATT&CK result. ThreatDown Elite's last MITRE round was 2024 (ER6), and it has no AV-Test business result since October 2023 or AV-Comparatives business result since 2022. Cynet took part in MITRE's 2025 round (ER7). None of this proves weakness. Where results are missing you are relying on the vendor's claims, so ask for references from businesses your size.
What does it cost at your seat count?
Managed bundles cost more per seat because the price includes people. Compare the all-in price at your real seat count: separate EDR licences, onboarding fees and seat minimums all count. Huntress Managed EDR bought direct or from a reseller has a 50-endpoint minimum (Huntress sets none through an MSP), which changes the sum completely for a ten-person firm. The cost report lists published prices at 10, 25 and 100 seats, and the price index shows which managed products publish a price at all.
Does it work with your MSP?
If an MSP runs your IT, check three things:
- Multi-tenant management, so the MSP can run your account alongside its other clients.
- Integration with the MSP's RMM and PSA tools. Each product page names the integrations.
- Who the SOC calls during an incident: you, or the MSP. Agree this before signing.
What happens after the provider contains a threat?
Containment stops the spread; recovery is a separate job. Ask whether the product can roll back ransomware changes, whether the provider helps restore systems, and what incident response beyond containment costs. Huntress Managed EDR does not offer automated ransomware rollback. ThreatDown Elite does, on Windows only.
What does the contract lock you into?
Terms vary more than prices. ThreatDown Elite's licence agreement renews the subscription automatically; opting out takes 30 days' written notice before the renewal date. Cynet's terms say a signed sales order cannot be cancelled or refunded. Read the term and notice clauses on each product page before you sign a multi-year order.
Which managed EDR fits which business?
- If you have 5 to 20 devices, no IT provider and want to buy online, ThreatDown Elite is the only managed bundle here sold self-serve, at $99.00 per endpoint per year. Its online store takes 5 to 20 devices; larger orders go through ThreatDown sales or a partner, by quote.
- If your IT is outsourced to an MSP, find out whether it resells Huntress Managed EDR; bought through an MSP it carries no seat minimum. The Huntress vs ThreatDown Elite comparison sets the two side by side.
- If you handle patient data, confirm the BAA first. Huntress states it does not provide one, and ThreatDown's HIPAA notice says its services are not designed to receive health data. Cynet maps its reporting to HIPAA but does not say publicly that it signs a BAA, so get the signed agreement before deployment.
- If you already run Microsoft Defender for Business, nobody watches it for you: Microsoft offers no managed response for this product, and its Defender Experts services attach to enterprise suites such as Microsoft 365 E5. Either pay an IT provider or MSP to monitor it, or switch to a bundle with analysts included. Compare the two routes in the Huntress vs Microsoft Defender for Business comparison.
- If you want independent lab evidence above all, Cynet is the only bundle here with a lab result from the last 18 months: MITRE's 2025 evaluation (ER7), where it detected all 90 substeps. The EDR product with the broadest recent results, Microsoft Defender for Business (AV-Test August 2026, AV-Comparatives first half of 2026), includes no managed response and Microsoft sells none for it, so choosing it means pairing it with an MSP or third-party SOC.
The regulatory position of the products with managed response, included or as an add-on:
| Product | HIPAA BAA | Supports PCI DSS | CMMC-relevant | FedRAMP |
|---|---|---|---|---|
| Unknown | Unknown | Unknown | none | |
| No | Yes | Unknown | none | |
| No | Unknown | Yes | none | |
| Unknown | Yes | Yes | none | |
| Unknown | Yes | Unknown | none |
Is Huntress worth it for a small business?
Huntress Managed EDR folds its 24/7 SOC into the per-seat price, $107.88 per endpoint per year, and sells mostly through MSPs. Its SMB Fit Score is 35. Three facts decide whether it is worth it:
- Managed response is included. That is the point for a firm without security staff: the analysts do the work.
- No public lab results. Huntress appears in none of the AV-Test, AV-Comparatives or MITRE ATT&CK results recorded here, so it scores zero on efficacy under the published formula. That explains much of its rank.
- No automated ransomware rollback. Huntress relies on its SOC's response instead, as its product page records.
Our read: Huntress suits MSP-served businesses that value a human-led response over lab scores. A buyer who wants independent test evidence should compare it with products that have it. The Huntress vs SentinelOne comparison lays out the trade-offs field by field.
Huntress or SentinelOne for an MSP?
Huntress and SentinelOne sell into the same MSP market from opposite ends:
| Huntress Managed EDR | SentinelOne Singularity Complete | |
|---|---|---|
| 24/7 managed response | Included in the price | Not offered in Complete |
| List price | $107.88 per endpoint per year | $179.99 per endpoint per year |
| Independent test evidence | No public results | MITRE ATT&CK 2024 (ER6); skipped the 2025 round |
| Renewal clause | Not stated in the public pricing FAQ | Renews at 120% without 30 days' notice (MSA 11.1) |
| SMB Fit Score | 35 | 33 |
An MSP that wants the vendor's SOC to carry response gets that built into Huntress. An MSP with its own SOC, or one that wants a MITRE evaluation history and can staff response itself, has the stronger case for SentinelOne, since Complete comes with no managed service.
How do you roll out managed EDR in a small business?
- Onboarding call. Agree contacts, escalation rules and the actions analysts may take without asking.
- Agent deployment. Install the agent everywhere, remove the old antivirus if the new product replaces it, and reconcile the device count against your asset list.
- Tuning period. Expect an initial period in which the SOC learns what normal looks like and you approve exclusions for legitimate business software.
- Steady state. Read the monthly report. Re-confirm emergency contacts each quarter, because a stale phone number turns a contained incident into an uncontained one.
Frequently asked questions
What is the best MDR for a small business?
The best MDR is the one whose analysts will act on your behalf within a contracted response time. Among bundles, the right pick depends on whether you buy online or through an MSP, whether you need a HIPAA BAA, and how much weight you give independent lab results. The ranked table above orders the bundles by SMB Fit Score.
How much does MDR cost for a small business?
Among bundles that include 24/7 managed response and publish a price, the lowest is $99.00 per seat per year (ThreatDown Elite). Cynet and most add-on services are quote-only, so real prices spread wider than the published figures.
Do I need MDR if I have an IT provider?
You need MDR if your IT provider does not monitor and respond to security alerts around the clock. Many providers work business hours only. Ask yours who handles a critical EDR alert at 2am on a Sunday, and get the answer in writing.
Is managed EDR the same as MDR?
Managed EDR is MDR limited to devices. Both put a vendor team behind an EDR agent; MDR can extend to email, identity, network and cloud.
What should an MDR contract include?
An MDR contract should list the response actions taken without asking, a response time for critical alerts, named escalation contacts and the price of incident response beyond containment. Check the term, auto-renewal and notice period too; each product page records them.
Recommendations
- Buy managed response if nobody can answer alerts around the clock. An unwatched EDR console is spending on alarms nobody hears.
- Get response actions and response times written into the contract.
- Weigh lab evidence, and ask for references where there is none.
- Compare all-in cost at your seat count, separate EDR licences and minimums included.
- Confirm the BAA before deployment if you handle health data.
- If an MSP runs your IT, agree who the SOC calls first and write it down before an incident.
Methodology and caveats
Managed-response status, prices, scores and lab results in this guide come from the Endpoint Index database at build time, the same records behind every product page. Those pages show a source link and a verification date beside each value.
- "Included" means in the base price the vendor publishes. "Add-on" means sold at extra cost.
- Prices are US dollar list prices per seat per year, without promotions, reseller margins or onboarding fees. Quote-only bundles are ranked but not priced.
- The SMB Fit Score judges how well a product suits a small buyer. It cannot judge a provider's analysts, because no public test does. The formula is published.
- Coverage. 17 products from 14 vendors are tracked. Providers missing from the list can apply for a free listing.
Treat this as information rather than procurement or legal advice, and confirm response commitments with the provider before signing.
Sources
- Gartner. Managed Detection and Response market overview. Definition of MDR services.
- Huntress. Huntress and HIPAA compliance. Statement that Huntress does not provide BAAs.
- ThreatDown. ThreatDown and HIPAA and software licence agreement, section 5(a).
- Cynet. Terms and conditions, section 6.4.
- SentinelOne. Master Subscription Agreement, section 11.1.
- MITRE. ATT&CK Evaluations: Enterprise results.
- AV-Comparatives. Business Security Test 2026 (March to June).
- Endpoint Index. Product pages and comparisons for each product named, with per-value sources and verification dates. Last price verification in this dataset: 2026-10-02.
Related research
All research ›Methodology · Report an error · Vendor not listed? Get listed