Security Operations

EDR vs XDR vs MDR vs SOC: what's the difference?

The terms EDR, XDR, MDR and SOC are often used interchangeably, when in fact they mean quite different things. This article outlines the differences and similarities between them, compares the levels of coverage offered and poses the questions you need to ask to find out which approach is right for you.

Natasha Scott 7 min read
EDR vs XDR vs MDR vs SOC: what's the difference?

One of the most common questions we get asked is the difference between these four acronyms. Customers often tell us that their partners and other vendors have recommended one of the four, but they’re unclear on what each one means and which they need.

The second problem is that they’re often described as interchangeable. They may be similar in some respects, but they are far from the same. And choosing between them is easier once you understand that they answer two different questions.

 

·       EDR and XDR are technologies – software tools that collect activity and flags threats.

·       MDR and a managed SOC are services - people who watch that technology, investigate what it finds and act upon it.

 

A tool without people raises alerts that nobody may be watching. People without the right tools can't see what's happening. The right people, processes and technology are essential ingredients for building cyber resilience, the decision every organisation has to make is which is the right combination for them.

 

What is EDR?

 

Endpoint detection and response (EDR) is software installed on the devices you manage. These include laptops, desktops, servers and, on most platforms, mobile devices. It records what happens on each device, spots behaviour that matches known attack techniques, and lets an analyst isolate a device or stop a process when suspicious activity or a compromise is detected.

 

Microsoft Defender for Endpoint, SentinelOne and CrowdStrike Falcon are well-known examples. EDR is the strongest control most organisations have on their devices. The caveat is that it can only see devices with the agent installed.

 

What is XDR?

 

Extended detection and response (XDR) takes the same idea further. It collects activity from endpoints, identities, email, cloud services and the network, and links related events into a single incident.

 

This is important because many attacks never touch a laptop. A phishing email, a sign-in from an unfamiliar country and a new mailbox forwarding rule might each look minor on their own. XDR recognises them as one account takeover. Like EDR, though, it's a platform. Someone still has to tune it, investigate what it finds and decide what to do about it.

 

What is MDR?

 

Managed detection and response (MDR) is a service. A provider's analysts monitor your environment around the clock, investigate alerts and contain threats on your behalf, usually using your existing EDR or XDR.

 

What makes MDR valuable is the response. Analysts can isolate a device or disable an account at 3am without waiting for someone in your team to answer the phone, under rules you agree in advance. For organisations without their own security operations team, it's often a solid starting point.

 

What is a managed SOC?

 

A security operations centre (SOC) is the team, process and technology that watches an organisation's security day and night. A managed SOC is that capability provided as a service.

 

It covers the same ground as MDR, but takes it further. For example, logs from business systems as well as security tools, threat hunting, threat intelligence, testing whether your controls work, and reporting your board and regulators can use. The distinction is less about coverage than about depth, and whether you need evidence of control as well as protection.

 

The most advanced Managed SOC providers will also offer different SOC tiers according to your specific needs. For example, some teams only require detection and alerting, as they have the in-house experience and coverage to investigate and contain incidents themselves. Others want to take a more proactive approach, with containment, investigation and root cause analysis, and improvement and governance included as standard. The most mature organisations are often looking for a service that goes beyond standard SOC capabilities and tend to opt for a service that includes threat hunting and CTI, automated response and orchestration, attack simulation and validation and resilience and risk reporting in addition.

 

How do they compare?

Which one do you need?

 

At the most basic level, you need a tool that sees the right things, and people to act on it. How that gets delivered can be decided by asking the right questions:

 

  1. Who is watching and can respond out-of-hours? If nobody in your organisation can be reached out of hours with the authority to take a system offline, you need a service, not just a tool.
  2. How much of the response do you want to keep? If your team can investigate and contain once they're alerted, detection and alerting may be enough. If not, look for a tier where the provider investigates and responds with you, or on your behalf.
  3. What does your business run on? If most of it runs in Microsoft 365, cloud platforms and SaaS, endpoint coverage alone leaves the main routes in unwatched.
  4. Who else has access to your systems? Suppliers, contractors and managed service providers with remote or privileged access are a common way in, and their activity rarely shows up on your endpoints. If third parties can reach critical systems, their sessions need watching too.
  5. How often does your estate change? Acquisitions, new brands, cloud tenants and SaaS tools all add systems that need monitoring. If your environment changes often, detection has to keep pace with it, and that tuning is ongoing work for someone.
  6. How quickly would you have to report an incident? Under UK GDPR, a personal data breach must be reported to the ICO within 72 hours of becoming aware of it, and regulated firms often have tighter obligations to their own regulators. Meeting those deadlines means knowing what happened, not just that something did, so you need someone who can investigate as well as detect.
  7. Who needs evidence? If regulators, insurers, banks or clients expect proof of monitoring and control, a managed SOC's reporting is part of what you're buying.

How Talanos supports growing businesses

 

We are able manage the EDR or XDR platform you already use, whether that's Microsoft Defender, SentinelOne, CrowdStrike or another major platform. That can run on its own, but most organisations are better served by our Managed Detection and Response service or one of our three managed SOC tiers: Reactive, Proactive and Adaptive. All three triage every alert within 15 minutes, around the clock.

 

If you're unsure which is right for you, our team is always available to run through the options.

 

Frequently asked questions

 

Is XDR better than EDR?

It isn’t really a case of being better or worse; XDR simply covers more of your technology estate. XDR includes endpoint data and adds identity, email, cloud and network activity. That doesn't mean that EDR is redundant, as most XDR platforms rely on EDR agents for their endpoint visibility.

 

What's the difference between MDR and XDR?

XDR is a technology platform that correlates security signals from across your environment. MDR is a service in which analysts monitor and respond to threats, often using an XDR platform to do it. You can own XDR without MDR, but then your own team has to run it.

 

Do I still need EDR or XDR if I buy MDR?

Usually yes. Most MDR services run on your EDR or XDR, so the tool provides the visibility, and the service provides the people.

 

Is MDR the same as a SOC?

No. MDR focuses on detecting and responding to threats. A managed SOC includes that and adds threat hunting, threat intelligence, control testing and board-level reporting.

 

Can we start with MDR and move to a managed SOC later?

Yes. Many organisations start with the level of cover their current maturity calls for and move up as their programme develops. With a provider that offers tiers, that's a change to the service level, not a new procurement.

 

Can a managed SOC use the tools we already have?

In most cases. A good provider will operate your existing platforms and tell you where they leave gaps, rather than insisting you replace them.

 

Where does NDR fit?

Network detection and response (NDR) watches traffic moving across your network, which helps catch attackers moving between systems and devices that can't run an agent. Some XDR platforms include network data; others rely on a separate NDR tool. Like EDR and XDR, it's a technology that still needs people to act on it.

 

Do we need a SIEM as well?

Possibly. XDR and MDR focus on detecting and responding to threats. A SIEM also collects and keeps logs from business systems for investigation and compliance. Many organisations need both, or a platform that combines them. Our guide to SIEM-to-XDR migration explains when replacing a SIEM makes sense.

 

Does a managed SOC replace our IT team?

No. Your IT team keeps running your systems. A managed SOC watches them for threats, investigates and responds, and works with your team on anything that affects the business. Most clients find it frees up time for their IT team, and allows them to concentrate on projects that add greater value to the business.

 

What does each one cost?

It depends mostly on the size of your estate, the volume of data involved and how much of the response the provider handles. Our guide to SOC outsourcing costs explains how providers price these services and what to check before comparing quotes.

Share this article
Get in touch

Ready to strengthen your cyber resilience?

Talk to one of our specialists about how Talanos can support your team.

Book a consultation →