Rejuvenate IT Logo
  1. Home
  2. Guides
  3. Cyber Security

Comparison

MDR, EDR and antivirus: what each one actually catches

Antivirus blocks known bad files. EDR spots suspicious behaviour and raises an alert. MDR is EDR with people who act on it. The real question is who responds when an alert arrives at three in the morning.

By Claire Donnelly · Last reviewed 11 August 2026 · 4 min read

The short version

  • Antivirus catches known threats and cannot see an attacker using a valid password
  • EDR watches behaviour and records it, but somebody has to read what it finds
  • MDR is EDR plus a team who investigate and act, including overnight
  • The decision is not which tool is best - it is who responds, and how quickly
  • An alert nobody reads is not detection, it is a log entry

What the three actually are

Antivirus compares files against a list of things known to be malicious, plus some pattern matching for variants. When it finds one it blocks or quarantines it, automatically, with nobody involved. It is fast, cheap, and works on the enormous volume of ordinary malware.

EDR – endpoint detection and response – watches what happens on a machine rather than what a file looks like. Processes launching other processes, a program encrypting files rapidly, an account reaching for things it never normally touches. It records that activity, flags anything unusual, and gives someone the ability to investigate and isolate the machine.

MDR – managed detection and response – is that same technology with a team behind it. The distinction is not more detection; it is that somebody is employed to look at what comes out and act on it.

So the progression is really about two separate things: what the software can see, and who is awake when it sees something.

What you are buying

EDR
Software, licensed per machine

MDR
Software plus a team who watch it

Who investigates an alert

EDR
Somebody at your end

MDR
The provider's security team

Overnight and weekends

EDR
Alerts wait for the morning

MDR
Reviewed as they arrive

Isolating a compromised machine

EDR
You do it, once you notice

MDR
Done for you, often within minutes

What it needs from you

EDR
Someone with time and the skill

MDR
Somebody to answer the phone

Cost

EDR
Lower, per device

MDR
Higher - you are paying for people

Which should you choose?

EDR only pays off if a named person genuinely reviews what it produces. If nobody in the business does that, you are paying for a recorder rather than a defence, and MDR is the honest choice. If you do have someone technical who would act on an alert, EDR alone can be perfectly sufficient.

The same attack, seen three ways

Take a common case. Someone in accounts is phished, their password is stolen, and an attacker signs in from abroad, reads the mailbox for a fortnight, then sends a fake invoice to a customer.

Antivirus sees nothing at all. There is no malicious file anywhere. Every action is a legitimate user with valid credentials doing ordinary things.

EDR may see some of it – an unusual sign-in, a mailbox rule quietly forwarding messages, access from a location that makes no sense. It records these and raises alerts. Whether that helps depends entirely on whether anybody looks at them before the invoice goes out.

MDR sees it and does something. The same signals reach a team who investigate, decide it is real, disable the account and ring you.

The technology gap between the second and third is small. The outcome gap is the entire incident.

What none of them do

Worth being clear about the limits, because all three get sold as though they were complete.

None of them stops a member of staff being talked into paying a fraudulent invoice, because no software is involved in that. None replaces backups: if ransomware does get through, what saves you is a copy it cannot reach. None removes the need to patch, because the easiest way in remains a known flaw nobody fixed. And none covers accounts, unless it is specifically watching your Microsoft 365 sign-ins as well as your machines.

They are one layer. A good one, and not the whole thing.

Questions to ask about any of them

  • Who reviews the alerts, and when did they last do it?
  • What happens to an alert raised at two in the morning?
  • Who is authorised to isolate a machine, and can they do it remotely?
  • Does this cover our Microsoft 365 accounts as well as our computers?
  • What would we be told, how quickly, and by whom?
  • Is there a written account of what happens during an incident?

Common questions

Is Windows Defender good enough?

As antivirus, the built-in protection is genuinely capable and no longer the poor relation it once was. The gap is not the quality of the blocking - it is that basic antivirus has no answer to an attacker with a valid password, and nobody is monitoring it on your behalf.

Do we need EDR if we already have antivirus?

Antivirus alone is a reasonable baseline for a very small business with little sensitive data. The case for EDR strengthens as soon as you have something worth stealing, staff working from various places, or a client or insurer asking what you have in place.

Is MDR only for larger companies?

It used to be. Providers now package it for small businesses, per device per month, precisely because the alternative - employing someone to watch a console overnight - is not available to a business of ten people at any price.

How is MDR different from a helpdesk that also does security?

Chiefly in who is watching, and when. A helpdesk responds to what people report during working hours. MDR responds to what the software noticed, whenever it noticed it, and the incidents that matter rarely happen at eleven on a Tuesday morning.

Will any of this stop ransomware?

It significantly improves the odds, because modern ransomware behaves distinctively before it encrypts anything, and behaviour is exactly what EDR and MDR watch for. It is not a guarantee, which is why tested backups remain the thing that actually gets you back.

Written by Claire Donnelly

Got security software nobody is watching?

It is more common than you would think, and easy to check. Tell us what you have and we'll say what it covers, what it misses, and whether anybody would notice if it fired tonight.

Ask us what you have