The purpose of this article is to discuss “Why do you need EDR?” and how to select an EDR platform. Endpoint Detection and Response (EDR) solutions have been gaining significant prominence in the cybersecurity space. Traditional antivirus and endpoint protection solutions are not enough to protect the modern cybersecurity needs of small businesses (SMBs).

Contact an EDR Specialist
If you prefer to talk to an EDR specialist who can help you find an EDR solution based on your goals and environment, please fill out the form below (U.S. based only).
Endpoint Detection and Response solutions encompass antivirus and endpoint protection features but provide much more. EDR solutions include features like event recording and have the ability to search for processes, events, and indicators across all your endpoints. EDR solutions collect information about network connections made, lateral movements, and they map to common attack methods (MITRE ATT&CK Framework).
An EDR solution’s goal is different from the goal of antivirus. The goal of an antivirus solution is to isolate and quarantine malware. The goal of an EDR solution is to minimize dwell time of an attacker and ultimately remove them from the environment.
The challenge facing small business however, is that EDR solutions have been largely out of reach. This is due to the high cost of needing SOC analysts with the right skillsets to manage an EDR solution. EDR solutions in of themselves can be expensive.
Furthermore, small businesses have relied heavily on managed service providers (MSPs) to protect themselves from threats. However, most MSPs are unprepared themselves due to the talent gap of available cyber security professionals. Forbes.com shared that approximately 2.7 million additional cybersecurity professionals are needed to meet the current talent gap.
So what are small businesses to do?
The answer is to trust a third party managed security service provider (MSSP) that can monitor your environment for threats using an EDR tool. This is known as Managed Detection and Response, or MDR. MDR alleviates the need for hiring an internal security operations center and puts the hiring burden on a third party.
Outsourcing in this way is a wise decision because it allows the third-party company to career path SOC analysts in a way that a small business could not. SOC analysts look for advancement in their careers, and a MDR service or MSSP can provide that for them.
Contact an EDR Specialist
If you prefer to talk to an EDR specialist who can help you find an EDR solution based on your goals and environment, please fill out the form below (U.S. based only).
Where do you find an EDR MDR service?
Oftentimes, you can look to EDR vendors to find out who their best partners are to manage their solution in your environment. You can also reach out to a trusted cyber security consultancy firm to get their opinion on local MSSPs. EDR vendors also oftentimes provide their own SOC to manage their own product within customer environments. The advantage to doing it this way can reduce finger-pointing (e.g., a SOC analyst missing ransomware and saying “we didn’t see it because of limitations of the product you’re on”).
What are key evaluation criteria for an EDR with MDR?
Now that you’re convinced you need an EDR with MDR, you might be asking yourself how to select an EDR solution. You can look to several resources out on the web as it relates to evaluating an EDR solution.
- The Top10 Things to look at when evaluating an EDR solution
- Ultimate Guide to the Top 10 EDR Solutions
- SentinelOne vs Cylance vs Carbon Black
Selecting a good MDR or MSSP service is a little different than picking out an EDR solution. In fact, it may make the most sense to evaluate MSSPs and MDR services with EDR instead of evaluating a platform first. Trust is always the most important factor when working with an outsourced cybersecurity firm who is monitoring your environment for security incidents and indications of compromise.
One of the best things you can do when evaluating a cybersecurity partner is to meet them face to face, in person. In a post-COVID world, we tend to do everything remote and forget the value of building trusted personal relationships. And meeting vendors in person is the best way to vet them out and ask your questions.
Top 10 Questions for EDRs MDRs and MSSPs
Whether you meet your vendor partner in person or remotely, you should be prepared with a list of questions.
Here are 10 example questions you can ask your EDR MDR/MSSP service provider:
- How long have you been providing security services with EDR?
- What is the average experience level of your SOC analysts?
- Do your SOC analysts get to know my environment?
- AM I assigned a Technical Account Manager who knows my environment?
- What access do I have to reports and your dashboard?
- What is your service level targets for identifying and responding to incidents?
- Where is your SOC or SOC analysts located?
- Do you have your SOC II type II attestation?
- Do you offer ancillary services like vCISO and penetration testing?
- What proportion of your customers are like me in size and industry?
Getting to know the answers to these questions can help you narrow down your future vendor partner.
Contact an EDR Specialist
If you prefer to talk to an EDR specialist who can help you find an EDR solution based on your goals and environment, please fill out the form below (U.S. based only).
You cannot stop a cybersecurity attack
Despite all the marketing gimmicks, there is no one product or group of products that can prevent a cybersecurity attack from succeeding. You can only mitigate your risk and delay a threat actor from succeeding. That is the game, which is cybersecurity. You need to have all your chess pieces situated in your favor. Without that, small businesses won’t thrive in the digital world. That being said, having a sophisticated SOC empowered with strong tools like EDR significantly reduces your risk.