What is MDR & EDR?
EDR monitors endpoint behaviour to identify suspicious activity that traditional antivirus may miss. MDR adds skilled analysts who review alerts, investigate context and coordinate containment. 39Security provides managed endpoint coverage, triage, escalation and response guidance for businesses that need active security ownership without building an internal security operations centre.
Who is this service for?
Established small businesses with Windows endpoints, remote workers, valuable data or contractual security requirements, especially where no internal team is available to investigate alerts around the clock.
What problem does it solve?
An endpoint product can generate alerts without establishing whether activity is harmless, suspicious or an active incident. Delayed investigation gives attackers time to steal credentials, move between systems or encrypt data. MDR closes the ownership gap by assigning people, process and escalation to the telemetry.
What is included?
- EDR agent deployment and coverage monitoring
- Behavioural detection and threat telemetry
- 24/7 or contracted-hours alert triage according to the selected plan
- Investigation of high-priority alerts
- Endpoint isolation or containment where authorised
- Guided remediation and recovery coordination
- Named client escalation path
- Monthly detection, coverage and incident reporting
What is not included?
- Unlimited on-site incident response unless retained
- Automatic remediation of every business application issue
- Support for unsupported operating systems
- Guarantee that all attacks will be detected
- Digital forensics or legal evidence work unless separately authorised
How implementation works
We inventory supported endpoints, identify business-critical systems, agree exclusions and escalation contacts, then deploy the EDR agent in controlled groups. Coverage and policy health are validated before full rollout. Response authority is documented, including whether analysts may isolate a device immediately or must first contact the client.
Supported platforms and products
Windows desktops and servers are the primary focus. Supported macOS and Linux coverage depends on the selected EDR platform and operating-system version. Microsoft 365 identity and email signals can be considered where the wider service and licences support integration.
How quickly are alerts investigated?
Priority alerts are triaged according to the purchased service window. A high-confidence active threat is escalated promptly, while lower-confidence detections are enriched and grouped to reduce noise. Exact acknowledgement and escalation targets are stated in the service schedule rather than implied by the term “24/7”.
Who responds?
Security analysts investigate process trees, user context, network connections, persistence indicators and related endpoint activity. Where authorised they can isolate the endpoint, block indicators and coordinate credential resets, patching, reimaging or wider incident response with 39Security and the client’s IT team.
What evidence and reporting will you receive?
Customers receive device-coverage reports, material alert summaries, incident timelines, actions taken, unresolved risks and service recommendations. A serious incident should produce a clear record that can support management review, insurer notification and post-incident improvement.
Cyber Essentials, insurance and Microsoft 365
MDR and EDR strengthen malware protection, monitoring and response. They can support Cyber Essentials control operation, cyber-insurance evidence and Microsoft 365 security, but Cyber Essentials still requires the wider five-control scope and insurers may impose specific products, response periods or logging requirements.
What does it cost?
Pricing is usually per protected endpoint with a setup charge for deployment and policy design. The live page shows the current indicative rate excluding VAT. Servers, legacy devices, high-risk environments and retained incident response can affect the final scope.
How is the service governed?
Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.
Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.
What should good delivery look like?
A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.
Questions to ask before selecting a provider
- Which systems, users and locations are included in the quoted scope?
- Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
- What evidence will we receive for clients, insurers, auditors or board reporting?
- Which actions are included in the monthly fee and which require separate project approval?
- How are service quality, response times, exclusions and exit arrangements documented?
Frequently asked questions
What is the difference between EDR and MDR?
EDR is the endpoint technology that records activity and detects suspicious behaviour. MDR is the managed service around security telemetry: analysts review alerts, investigate what happened, escalate material risk and coordinate containment or remediation.
Is MDR the same as antivirus?
No. Antivirus is mainly a prevention and blocking control. EDR records deeper behaviour and MDR adds human investigation. They work together, but MDR should not be used as a reason to neglect patching, MFA, backups or secure configuration.
How quickly are alerts investigated?
Priority alerts are reviewed according to the service schedule selected by the customer. The contract should state coverage hours, acknowledgement targets, escalation contacts and what analysts are authorised to do when a contact cannot be reached.
Who responds to an incident?
The MDR analysts investigate the alert and the named 39Security team coordinates with the client. Depending on the agreed authority, the response may include endpoint isolation, account protection, evidence collection and escalation to a retained incident-response service.
Can MDR protect Microsoft 365?
Endpoint MDR does not automatically cover every Microsoft 365 identity and email event. Wider coverage depends on the selected integrations, Microsoft licences and whether identity, email and cloud alerts are included in the service scope.