Home › Services › EDR / MDR
Productized security
Antivirus tells you it blocked something. EDR tells you what was trying to happen.
Prevention stops the known. Detection and response is what covers the rest — the behavior that looks legitimate one step at a time, and the attacker who is already inside using tools that were already there.
Included from the tier shown below. Month to month, cancel any time.
What we actually do
Behavioral detection
Not just known-bad files, but sequences of actions that add up to an attack — credential access, lateral movement, suspicious PowerShell, unusual process trees.
Incident correlation
A malicious link in email and malware on a laptop become one incident with a timeline, rather than two unconnected alerts nobody joins up.
Investigation and containment
Our engineers investigate, and where necessary isolate a device from the network while keeping our management connection to it.
Vulnerability findings into the fix queue
Weaknesses found on your devices are ranked and routed into the remediation work rather than sitting in a dashboard nobody opens.
A person stays in the loop. This is the tier where response becomes ours rather than yours. Automation surfaces the diagnosis; a named engineer decides what happens next and is accountable for it.
What you need to have. Requires Microsoft Defender for Business, or Defender for Endpoint Plan 2. Microsoft 365 E3 includes Plan 1 only, which has no EDR — an E3 tenant needs a Plan 2 step-up before this service can be delivered honestly. You keep your own Microsoft licensing — we do not resell it, and we will always tell you what you already own before suggesting you buy anything.
Which package includes it
| Package | EDR / MDR |
| Monitor | Included |
| Protect | Included |
| Resist 365 | Included |
| Complete | Included |
Common questions
What is the difference between EDR and MDR?
EDR is the technology. MDR is the technology plus people operating it. Software that detects an intrusion at 2am and tells nobody has not helped you.
How fast will you respond?
Response commitments are set by tier and severity in your service agreement, and they are numbers we can actually staff rather than numbers that sound impressive.
Will you isolate a machine without asking?
Containment of an active threat is the one place speed can outweigh consultation, and how that decision gets made is agreed with you in advance and written down.
Ready when you are.
Every package includes this. Pick the tier that fits.
See packages
Other services
RMMRemote monitoring and management for visibility, maintenan…
Endpoint ProtectionManaged protection for devices, users, and business endpoi…
Patch ManagementSecurity updates and maintenance without relying on manual…
Email SecurityProtection against phishing, malicious email, and account…
Cloud BackupBackup readiness and recovery planning for business contin…
Microsoft 365Support for accounts, access, collaboration, and security…
Microsoft Defender XDRUnified endpoint, identity, email, and cloud protection ac…