The short answer: antivirus blocks threats it recognises; EDR catches the attacks antivirus misses but only raises an alert; MDR adds a 24/7 team who see that alert and stop the attack. Antivirus is the lock, EDR is the alarm, MDR is the monitoring company that answers it at 3am. Find out which one you actually need in two minutes.
The essentials:
- Antivirus is still a valid baseline, but it can't see most modern attacks - which is why your insurer now asks about EDR.
- EDR raises alerts; MDR adds the 24/7 team who act on them. Most firms need the team.
- The readiness check tells you where you sit and whether you'd likely satisfy a cyber-insurance questionnaire.
Written for UK owners and directors whose cyber-insurance renewal just asked about "EDR" or "24/7 monitoring" - and who'd like to know what that actually means before they answer.
Most directors meet these three letters for the first time on a cyber-insurance renewal form. The questionnaire asks whether you run "EDR on all endpoints" or have "continuous monitoring", the real answer is "I'm not sure", and suddenly a box you've ticked for years - antivirus - isn't the box they're asking about.
So here's the whole thing in plain English: what antivirus, EDR (endpoint detection and response) and MDR (managed detection and response) each do, why the goalposts moved, whether a firm your size genuinely needs the top tier and what your insurer means by the words on the form.
No jargon for its own sake, and no fear-selling - just what a director needs to answer the question and make a sensible call.
We run this stack for a living - every Red Eagle Tech package includes managed detection and response as standard - so we'll be clear about where the line actually sits for a firm your size, including when you don't need the expensive option.
Why your insurer is suddenly asking
A few years ago, a cyber-insurance form asked whether you had antivirus and a firewall. Today it asks whether you run "endpoint detection and response on all endpoints" and have "24/7 monitoring", and it increasingly checks your answer with its own scan rather than taking your word for it.
That change isn't insurers being difficult. It's them following the money: the attacks they now pay out on - stolen logins, ransomware that lands in minutes, intrusions that use your own tools against you - are exactly the ones antivirus was never built to catch. So they've moved the bar to the technology that can.
And the risk is real and close to home: 43% of UK businesses reported a cyber breach or attack in the past year, with phishing behind 88% of those that were hit (Cyber Security Breaches Survey 2025/26).
The three terms on the form describe three different levels of protection, and the difference between them is the difference between a claim paid and a claim refused. Here's what each one is.
Antivirus, EDR and MDR: what each one actually does
The simplest way to hold the three in your head is a house. Antivirus is the lock on the door - it stops the intruders it recognises. EDR is the alarm system - it spots someone who got past the lock and raises the alert. MDR is the monitoring company - the people who hear the alarm at 3am and send someone to deal with it.
| Antivirus (AV) | EDR | MDR | |
|---|---|---|---|
| What it is | Software that blocks known malware | Software that detects suspicious behaviour and can respond | EDR plus a 24/7 human team who run it for you |
| How it decides | Matches files against a list of known-bad | Watches how software behaves, spots the abnormal | Analysts investigate what the software flags |
| What it catches | Known viruses and malware | New and fileless attacks, stolen-login misuse, ransomware behaviour | The same, but confirmed, investigated and stopped |
| What it misses | Anything it hasn't seen before; attacks with no file | Nothing technically - but alerts nobody actions | Its real limit is that no service is infallible |
| Who acts on it | Automatic; largely set-and-forget | You - someone must watch and action alerts | The provider - around the clock |
| Best thought of as | The lock on the door | The alarm system | The monitoring company |
The row that catches directors out is "who acts on it". Antivirus does its job by itself. EDR does not - it produces alerts, and those alerts only protect you if a person sees them and acts. That single distinction is the whole difference between EDR and MDR, and it's the one insurers care about most.
Is Microsoft Defender an EDR?
This comes up constantly, because so many UK firms run Microsoft 365 - and the answer is a genuinely useful "it depends which one". Many businesses already own EDR without knowing it.
| What you have | What it is | Is it EDR? |
|---|---|---|
| Microsoft Defender Antivirus (built into Windows, free) | Antivirus with some behaviour detection | No - antivirus only |
| Defender for Business (in Microsoft 365 Business Premium) | SMB-grade endpoint detection and response | Yes - real EDR |
| Defender for Endpoint Plan 2 (in E5 licences) | Full enterprise EDR with threat hunting | Yes - full EDR |
So if you pay for Microsoft 365 Business Premium, you already have an EDR - Defender for Business - included. The catch is that owning it isn't the same as being protected by it: it has to be switched on, configured and, above all, monitored.
And none of these Microsoft tiers include a team watching the alerts. That watching is MDR, and you add it separately - which is exactly the gap the rest of this guide is about.
One note for Mac and mixed fleets: EDR and MDR aren't a Windows-only story. The same detection and response covers Macs and servers, and increasingly mobiles and cloud accounts too - so "every device" on your insurance form really does mean every device, whatever it runs.
Why antivirus alone isn't enough any more
Let's be fair to antivirus first, because the "antivirus is dead" line you'll read online overstates it. Antivirus is still a valid baseline control - it's one of the five controls in the government's Cyber Essentials scheme, and you should keep running it. The problem isn't that antivirus stopped working. It's that the attacks changed shape around it.
Antivirus works by recognising known-bad files. But most attacks now don't bring a file to recognise. In CrowdStrike's 2026 threat report, 82% of the attacks it detected in 2025 were "malware-free" - they used stolen logins, trusted identity flows and legitimate built-in tools like PowerShell, none of which antivirus has a signature for.
There's simply nothing for the lock to reject. Security researchers now find these "living off the land" techniques - attacks that abuse tools already on your machine - in 84% of the most serious incidents (Bitdefender, 2026).
How today's attacks get in, and move fast
So how do the stolen logins get stolen? Usually a convincing email. Phishing is still the most common way attackers get a first foothold, and AI has made it far harder to spot - Microsoft found AI-written phishing emails are clicked 54% of the time, against 12% for the old-style kind (Microsoft Digital Defense Report 2025).
The first step of a modern attack is now often a click, not a virus - so the thing that stops it can't be a file-scanner.
They're also fast. The same report put the average "breakout time" - how long from the first machine compromised to the attacker spreading to the next - at around 29 minutes, and the fastest at under a minute. An attack that's over before your team is back from lunch can't be handled by a tool nobody's watching.
And yet the median breach still goes 14 days before anyone notices, according to Mandiant's 2026 M-Trends report. Minutes to do the damage; a fortnight to spot it. That gap - between how fast attacks move and how slowly they're found - is the entire reason detection and response exists, and why "install antivirus and forget it" no longer covers you.
In plain terms. Antivirus isn't obsolete - keep it. But it's now the floor, not the ceiling. The shift to EDR and MDR is driven by the attacks above and by what insurers will underwrite, not by antivirus suddenly failing at the job it was always good at: stopping known malware.
How MDR actually works
"A 24/7 team" is easy to say and hard to picture, so here's what actually happens when managed detection and response is doing its job - using the example of a finance laptop that starts encrypting files at three in the morning.
- Detect. The EDR sensor on that laptop is streaming what it does to the provider. Unusual behaviour - mass file encryption at 3am - trips a detection.
- Triage. A human analyst checks it in seconds. Is this a real attack or the finance director running an unusual backup? They filter the noise, so a real threat isn't lost among false alarms.
- Investigate. Confirmed real, the analyst traces how it got in and whether it has spread anywhere else - the questions your own team would take hours to answer, if they were even awake.
- Contain. The analyst acts - isolates the laptop from the network, kills the process, removes the foothold - often within minutes, while your team sleeps. Good services measure this in minutes, not hours.
- Report. By morning you have a write-up of what happened, what was done and what to fix - the evidence trail your insurer and auditors will want.
Steps two to five are what a lone EDR tool can't do. It performs step one brilliantly - it raises the alarm. But an alarm only protects you if someone hears it and acts. As the saying in the trade goes: EDR without MDR is a smoke alarm with nobody in the building to hear it.
Want the alarm answered, not just raised? Every Red Eagle Tech package includes 24/7 CrowdStrike managed detection and response as standard, from our entry tier up - not an add-on. See what's in each tier.
Do you actually need MDR?
Not every business needs every layer, and it would be a poor guide that told you otherwise to sell you the top tier. Here's where the line actually falls.
When antivirus alone is defensible
A sole trader or a very small, low-risk operation holding little sensitive data, with no compliance obligation and no insurance asking the question, can reasonably run good antivirus - paired with multi-factor authentication, patching and a bit of staff awareness. That's a genuine position, not a failing.
When you need EDR
Once you pass roughly 20 staff, have remote or hybrid workers, handle client or regulated data or your insurer asks for it, EDR becomes the sensible baseline. At that size the odds of an attack antivirus can't see are no longer academic.
The counter-intuitive bit: you need MDR more when you're small
Here's the part most guides skip. EDR only pays off if someone watches and acts on its alerts around the clock. A large company can staff a night shift; a 20 or 50-person firm never will.
So the smaller you are, the more likely it is that "EDR on its own" means nobody is actually watching - which is the false economy insurers now price against.
It isn't hypothetical: the US cyber-insurer At-Bay found in 2026 that 60% of businesses hit by the Akira ransomware group already had a leading EDR tool installed and were breached anyway - the ones that escaped full encryption were those pairing EDR with a 24/7 team. For most small and medium UK firms, the realistic choice isn't EDR versus MDR; it's MDR versus an alarm nobody answers.
The one question to ask yourself: if a device does something dangerous at 3am on a Sunday, who sees it and who stops it? If that answer is "nobody until Monday", you need MDR - not just a better antivirus.
Your cyber-insurance questionnaire, decoded
Since the questionnaire is what sent most people to this page, let's translate it. UK cyber-insurance forms are remarkably consistent about what they want, and they split into controls that decide whether you're covered at all and controls that set your price.
The three that decide whether you're covered
- Multi-factor authentication, everywhere. Email, remote access, admin accounts, cloud apps. The word that sinks applications is "everywhere" - one unprotected account can fail the whole form.
- EDR or MDR on every device and server. Behavioural detection with active response, not just antivirus, and not just on some machines. This is the control this whole guide is about.
- Tested, off-site backups. Backups you've actually restored from, kept somewhere ransomware can't reach.
After those, insurers rate you on a written and tested incident-response plan, documented patching, security-awareness training and controlled admin access. Two things worth knowing before you fill it in: the questionnaire is a warranty - getting an answer wrong, even by accident, can void a claim - and a growing number of insurers now run their own external scan to check what you've told them. Answer it as the technical audit it has become.
The jargon, in plain English
Insurers choose their words carefully, so it's worth knowing what each phrase is really asking for.
| The form says… | …which means |
|---|---|
| "Next-generation antivirus (NGAV)" | Behaviour-based protection - a step up from classic antivirus, but usually below a full EDR requirement |
| "EDR on all endpoints" | Detection-and-response software on every laptop, desktop and server - no exceptions |
| "Continuous / 24×7 monitoring" | Someone - in practice, MDR - is watching and responding around the clock, not just in office hours |
| "Active response / auto-containment" | The tool can isolate a device or kill a process itself - logging an email isn't enough |
| "Managed detection and response (MDR)" | EDR plus a human team running it for you |
| "Endpoint coverage matches your asset list" | Prove the software is on essentially every device you own - one stray laptop can fail the application |
The pattern is clear once you see it: an EDR tool that emails an alert to a mailbox nobody watches until Monday does not meet a "continuous monitoring" requirement, and insurers now say so explicitly. One carrier's application asks you to set out "how your EDR product is monitored and managed - internal IT team or outsourced" - proof that having EDR and having someone watch it are two different questions. Detection and response has to be watched to count.
Does Cyber Essentials cover this?
Not on its own, and this catches a lot of directors out. Cyber Essentials asks for "malware protection", and antivirus satisfies that - so you can hold Cyber Essentials and still not have the EDR or MDR your insurer asks for separately. They're different bars.
Cyber Essentials is well worth having - the government reports far fewer insurance claims from businesses that hold it, and free cyber cover for smaller turnovers - but treat it as the floor and answer the insurer's endpoint question on its own terms.
Estimate what your cover should cost
Once you know which controls you have, the next question is what cover should cost - and whether you're overpaying. Our free calculator gives you a UK estimate and the level of cover to ask for, with no email address or sign-up.
Cyber insurance cost calculator
Estimate what cyber insurance should cost your UK business, plus how much cover you need. Anonymous, no email required.
Filling one in right now? Every one of our packages is built to answer "yes" to the endpoint and monitoring questions - EDR on every device with 24/7 MDR behind it, as standard. See the packages, or talk it through with a UK engineer.
Where do you sit? A two-minute readiness check
Tell it what you're running today and it'll place you on the antivirus-to-MDR ladder, then give you a clear read on whether you'd likely satisfy a typical cyber-insurance questionnaire's endpoint and monitoring controls. No email address, no sales call.
Pick where you sit above, and your readiness verdict appears here.
Where to focus next:
On this evidence you'd likely satisfy a typical questionnaire's endpoint and monitoring controls. Keep the evidence - restore logs, MFA reports - ready for renewal.
How this is scored
The rung is where your endpoint protection sits: antivirus, EDR or EDR watched around the clock (MDR). The verdict then checks that against the controls a typical UK cyber-insurance questionnaire treats as essential - detection and response that's actually monitored, multi-factor authentication and tested backups. It's editorial guidance to help you answer the form, not a certified assessment or a quote - your insurer's exact wording is what counts.
What should this cost?
Good detection can't be free - but it's a fraction of one bad day. As a rough guide, per user per month, antivirus runs a few pounds, EDR a little more and MDR - the tool plus the team - typically lands in the low tens of pounds. Set that against the cost of a single incident: a breach at a larger firm runs into the millions (IBM's studied UK average is £3.29m), but even a modest small-business ransomware event costs tens of thousands in downtime and recovery - many times what a year of proper protection would have cost.
Be wary of anything suspiciously cheap. If a "fully managed security" price looks too good, something has usually been left out - the tooling alone costs a provider real money, so a rock-bottom figure means either antivirus wearing a better name or a tool with nobody watching it.
For how this fits into the total cost of IT support - and where the fair price bands sit - see our guide to IT support costs in the UK, and for what a full managed contract should include, what managed IT support actually covers.
How Red Eagle Tech does it
We'll be straight about where we stand, since we've spent the whole guide telling you what good looks like.
- MDR is standard in every package, not an upsell. Every Red Eagle Tech tier includes CrowdStrike Falcon Complete - endpoint detection and response on every device, plus CrowdStrike's own team providing 24/7 managed detection and response - from our entry tier up. You don't pick a cheaper plan and lose the security.
- It's the answer to the insurance questions. The endpoint, monitoring and active-response boxes on your questionnaire are ones our packages are built to let you tick with confidence - because the protection is really there and really watched.
- Dark-web monitoring and awareness training come in higher up. The extra layers insurers reward - monitoring for leaked staff credentials, phishing-awareness training - are built into our upper tiers rather than sold piecemeal.
- The prices are on the website. Every package, every per-user price, monthly rolling, with the security stack named. You can compare us against this guide without booking a call.
See it in plain figures. Our packages start at £69 per user per month ex VAT, monthly rolling, with 24/7 CrowdStrike MDR in every one. See the full price list, or talk to a UK engineer.
Frequently asked questions
Antivirus blocks known threats by matching them against a list of known-bad files. EDR - endpoint detection and response - watches how software behaves and can catch and shut down the novel attacks antivirus never had a signature for, but it raises alerts a human still has to act on. MDR - managed detection and response - is EDR plus a 24/7 team who watch those alerts and respond for you. In one line: antivirus is the lock on the door, EDR is the alarm and MDR is the monitoring company that answers it at 3am.
Not on its own for most businesses. Antivirus is still a valid baseline control - it's part of Cyber Essentials, and you should keep it - but 82% of attacks CrowdStrike detected in 2025 involved no malware file for antivirus to match. Attackers increasingly use stolen logins and legitimate tools, which signature antivirus can't see. That's the case for EDR, and increasingly it's what your cyber-insurer expects. Antivirus is necessary; in 2026 it's rarely enough.
It depends which Defender you mean. The free Microsoft Defender Antivirus built into Windows is antivirus, not EDR. Defender for Business, which comes with Microsoft 365 Business Premium, is EDR - genuine endpoint detection and response for firms up to 300 staff. Defender for Endpoint Plan 2, in the E5 licences, is full EDR. The catch: none of them include a human team watching the alerts - that's MDR, and you buy it separately. Many UK small businesses already own EDR through Business Premium and don't realise it.
Yes - Business Premium includes Defender for Business, which is a real EDR. But owning it isn't the same as it protecting you. It has to be switched on, configured properly and, above all, monitored - the alerts it raises only help if someone sees and acts on them. If nobody on your team is watching a security dashboard around the clock, you have the tool without the service, which is where managed detection and response comes in.
Ask one question: if a laptop starts doing something dangerous at 3am on a Sunday, who sees it and who stops it? EDR raises the alarm, but it doesn't answer it - a person does. If you don't have a security team watching around the clock, the answer is usually MDR, not EDR alone. Counter-intuitively, the smaller you are the more that's true: a large firm might staff a night shift, but a 20-person business never will. EDR without anyone watching is a smoke alarm in an empty building.
EDR is the software; MDR is the software plus the people. EDR sits on your devices, detects suspicious behaviour and can isolate a machine or kill a process - but it produces alerts that someone has to triage and act on. MDR wraps a 24/7 team of security analysts around that tool: they watch the alerts, weed out false alarms, investigate real ones and respond on your behalf, day and night. You can buy EDR without MDR, but then the watching and responding is your job.
A managed security service provider (MSSP) manages your security tools - firewalls, antivirus, patching - and monitors them, but it usually hands incidents back to you to deal with. MDR is narrower and deeper: it's focused on detecting and responding to active threats, with dedicated analysts who take action rather than just raising a ticket. If an MSSP is facilities management for your security kit, MDR is the response team that actually tackles the intruder.
It means someone - or something watched by someone - is looking at your systems around the clock, not just during office hours. In practice, insurers use it to mean MDR: endpoint detection and response with a 24/7 team behind it. An EDR tool that emails an alert to a mailbox nobody reads until Monday does not meet a "continuous" or "24/7 monitoring" requirement, and insurers have started saying so explicitly. When the questionnaire uses that phrase, it's asking whether you have the humans, not just the software.
Because antivirus misses the attacks insurers now pay out on - credential theft, fileless intrusions, fast ransomware. Most carriers now treat EDR as a baseline: without it you may be refused or loaded heavily, and premium uplifts of 40-100% for having no EDR were common by 2025. Running EDR typically earns a modest reduction against antivirus-only; documented 24/7 MDR earns more - typically 10-25% credit, and some UK insurers offer a specific MDR discount - and is often required outright at higher cover limits. Detection and response has moved from nice-to-have to the price of a sensible premium.
Three controls decide whether you're covered at all: multi-factor authentication everywhere (email, remote access, admin accounts), EDR or MDR on every device and server and tested off-site backups. After that they rate you on a written and tested incident-response plan, documented patching, security-awareness training and privileged-access management. Two things to know: the questionnaire is now a warranty - misstating a control can void a claim - and insurers increasingly verify your answers with their own scans rather than taking your word for it.
Not necessarily, and this trips a lot of directors up. Cyber Essentials asks for "malware protection", and antivirus satisfies that control - so you can hold Cyber Essentials and still not have the EDR or MDR your insurer's questionnaire asks for separately. They're related but different bars. Cyber Essentials is well worth having - the government reports far fewer insurance claims from firms that hold it, and free cover for smaller turnovers - but treat it as the floor, then check the insurer's endpoint question on its own terms.
Next-generation antivirus (NGAV) uses behaviour and machine learning rather than signatures alone, so it catches more than classic antivirus - but it's still mainly about prevention at the point of attack. EDR goes further: it records what happens on the device, lets you investigate after the fact and can respond by isolating or rolling back. On an insurance questionnaire, "NGAV" is a step up from antivirus but usually below a full "EDR on all endpoints" requirement - read the question carefully, because the words are chosen deliberately.
XDR (extended detection and response) widens the same idea beyond the laptop: it pulls detection signals from your email, cloud accounts and network into one view, not just your endpoints. It's a bigger tool, not a replacement for the team - like EDR, XDR only helps if someone is watching and acting on what it finds, which is why it's usually run under an MDR service (sometimes badged "MXDR", managed XDR). For most small and medium UK firms it's a later-stage upgrade, not the first move: get detection and response that's actually monitored in place first. And if your insurer's form doesn't mention XDR - most don't - you almost certainly don't need to worry about it yet.
Dark-web monitoring scans criminal marketplaces and breach dumps for your company's leaked credentials - staff email addresses and passwords exposed in other companies' breaches - and warns you so you can reset them before they're used. It's not a substitute for EDR or MDR; it's an early-warning layer that pairs well with them, because stolen logins are now one of the commonest ways in. It's a sensible addition for most firms and is built into our upper tiers rather than sold as an add-on.
No, and be wary of anyone who says otherwise. No security service can promise you'll never be breached. What good MDR does is cut the time between something getting in and someone stopping it - from the days a breach typically goes unnoticed down to minutes - which is what limits the damage, the downtime and the payout. It reduces risk and contains impact; it doesn't eliminate risk. Good providers are clear about that distinction.
Sources
- CrowdStrike, 2026 Global Threat Report (covering 2025) - malware-free detections and breakout time - crowdstrike.com, February 2026
- Mandiant (Google Cloud), M-Trends 2026 - global median dwell time - cloud.google.com, March 2026
- gov.uk, Cyber Security Breaches Survey 2025/2026 - 43% of businesses breached, phishing the most common attack - gov.uk, 2026
- Bitdefender, 2026 Cybersecurity Assessment - living-off-the-land techniques in 84% of high-severity attacks - bitdefender.com, June 2026
- Microsoft, Digital Defense Report 2025 - AI-written phishing click-through rates - microsoft.com, October 2025
- IBM, Cost of a Data Breach 2025 (UK edition) - UK average breach cost £3.29m - ibm.com, 2025
- NCSC, Device Security Guidance: Antivirus and other security software - ncsc.gov.uk, accessed July 2026
- gov.uk, Cyber Essentials scheme overview and management information - updated 13th March 2026
- Microsoft Learn, Microsoft Defender for Business overview and FAQ - learn.microsoft.com, accessed July 2026
- Coalition, 5 Essential Cyber Insurance Requirements, and UK MDR premium discount - coalitioninc.com, accessed July 2026
- At-Bay, 2026 InsurSec Report - ransomware victims with EDR deployed - at-bay.com, 2026 (US insurer data)
- Marsh, Cyber resilience: 12 key controls, and Cyber risk predictions for 2026 (UK) - marsh.com, 2026
- Palo Alto Networks, EDR vs Antivirus and MDR vs EDR - paloaltonetworks.com, accessed July 2026
- CrowdStrike, Falcon Complete Next-Gen MDR documentation - crowdstrike.com, accessed July 2026
- Todyl, How cyber-insurance requirements are changing, and Huntress, Does EDR reduce your cyber-insurance premium - 2026