The Lab
You bought the EDR. Who's watching it at 2am?
Frank De Pasquale ·
It is a little after two in the morning and something on a laptop in your business starts behaving oddly. One process spawns another, a set of credentials gets reused, a connection opens to somewhere it has no reason to go. Your endpoint tool sees all of it and raises an alert. The question that decides how the next hour goes is a plain one: who reads that alert, and how quickly?
For a lot of businesses the honest answer is that the alert waits until someone logs in and gets to it, and by then the window that mattered has closed. In 2025 the average time for an intruder to move from the first machine they landed on to the next was 29 minutes, and the fastest was 27 seconds (CrowdStrike 2026 Global Threat Report). That difference between a tool detecting at 2am and a person responding at 9am is where the damage happens.
Three words that get used as one
Part of what makes this hard to buy is that three terms get treated as interchangeable, and they are not. EDR is the sensor: the agent on the endpoint that sees what is happening and can act on it. XDR is the correlation beyond the endpoint, tying together signals from identity, email, cloud and network so a quiet event in each becomes one visible story. MDR is the people: a team operating the tool around the clock, reading the alerts, and containing the problem while you sleep. Which of those three you are buying is a bigger decision than which logo sits on the box.
The real question is who operates it
So the useful question is not which EDR, but who runs it around the clock, and how fast they contain. An excellent sensor with nobody watching it is a cost with no outcome. For most businesses the decision comes down to the operating model: whether you have the people to watch alerts 24 hours a day yourself, which very few organisations outside a dedicated security team genuinely do, or whether you buy that watching as a managed service. Where we land clients, more often than not, is on the vendor's own managed service, because it is usually the cost-effective way to get expert eyes on the tool at 2am. We resell and help run that service; we are not the ones sitting in the chair, and it would be wrong to imply otherwise.
We publish Frank's read on each market to the Lab as we test it. Get it in your inbox →
The best platform is the one you never open
Ask an IT lead what a good outcome looks like and the honest answer runs counter to intuition: the best platform is the one they never have to open, because it caught the thing, contained it and rolled it back before it became their morning. That is the outcome to buy for, and features earn their place as evidence of it: how fast the managed team contains, how light the agent sits on a machine, whether it can roll a device back to its pre-incident state. Microsoft Defender belongs in this conversation as a capable floor, and for many businesses it is a sensible starting point. The gap it leaves is the one everything here circles back to: round-the-clock operation, and correlation across more than the endpoint.
See it in your own environment
None of this needs to be taken on trust. A managed detection and response layer can be tested against your own environment before you commit, with a proof of concept that shows what it catches and how quickly the team behind it responds, on machines that look like yours. If the risk you are weighing is the rollout itself, that can be run the other way round, proving deployment is safe before it touches production. It is also the control your cyber insurer increasingly expects to see, so the exercise doubles as a straight answer to a question they will ask. If it is useful, we start with a short assessment.
Sources
1. CrowdStrike 2026 Global Threat Report — in 2025 the average eCrime breakout time was 29 minutes and the fastest observed was 27 seconds (global; 2026 edition)