BLOG · COMPARISON ·

EDR vs XDR vs SIEM vs MDR: what each does and which a mid-size company needs

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • EDR uses an agent on workstations and servers to record activity on each host, detect attacks and contain them there; OMB memorandum M-22-01 of October 2021 describes it as continuous monitoring and collection of endpoint data combined with rules-based automated response and analysis
  • XDR builds on an EDR and adds sensors for email, network, identity or cloud, usually from the same vendor, correlating their alerts into one incident; ENISA’s guidance of June 2025 lists EDR and XDR tools among the examples of evidence for automated monitoring
  • A SIEM collects, centralises and analyses logs from any source and keeps them for investigation; the ASD and CISA guidance of 27 May 2025 notes that most SIEM pricing follows the volume ingested and that implementing one takes several people full-time
  • SOAR runs predefined playbooks, such as isolating the source of an event, and should follow a SIEM that already alerts accurately; MDR is a service in which a provider’s analysts watch the alerts of an EDR or XDR and respond with actions agreed in advance
  • Someone has to receive and act on alerts at night and at weekends, whether own staff on call, an MDR or SOC service or automated containment; Implementing Regulation 2024/2690 requires the providers it covers to initiate “a qualified and appropriate response” to an alarm in a timely manner

Eurokommerz × Vixen.UNO: Cyber Resilience  Talk to an expert →

EDR vs XDR vs SIEM vs MDR: the differences in short

EDR (endpoint detection and response) uses an agent on each workstation and server to record activity, detect attacks and contain them on that machine. XDR (extended detection and response) extends an EDR with sensors for email, network, identity or cloud, usually from the same vendor, and correlates their alerts into one incident. A SIEM (security information and event management) collects logs from any source, correlates them and keeps them for investigation, and SOAR (security orchestration, automation and response) automates response steps on its alerts. MDR (managed detection and response) is a service in which a provider’s analysts watch the alerts and respond.

TOOLWHAT IT COLLECTSSTRENGTHLIMIT
EDRprocess, file and network activity on hosts that run its agentdetail on each host and containment thereno activity from devices without its agent
XDRan EDR plus email, network, identity or cloud sensors, usually from one vendorone incident across those layers, with a response in eachother vendors’ sources only through integrations
SIEMlogs from any source, including firewalls, hypervisors and cloudcorrelation across all sources, retention, search, reportspricing mostly follows the volume ingested; needs tuning and skilled staff
SOARalerts from the SIEM and other toolspredefined response steps run automaticallyneeds a SIEM that already alerts accurately
MDRalerts of the tools named in the contractanalysts who triage and respond in the contracted hoursonly the sources and actions the contract names

OMB memorandum M-22-01 (2021); ASD and CISA guidance on SIEM and SOAR (May 2025); NIST SP 800-92 (2006). The XDR and MDR rows and the strength and limit columns are our assessment.

The NIST CSF 2.0 document of 26 February 2024 does not mention SIEM, EDR or XDR, and its abstract says: “The CSF does not prescribe how outcomes should be achieved.” EDR is one way to meet DE.CM-09, the monitoring of computing hardware and software, and NIST SP 800-61 Rev. 3 (April 2025) names SIEM and SOAR as example tools for event analysis and correlation (DE.AE-02 and DE.AE-03). Under DE.AE-08, incidents are declared when events meet the defined criteria, and the incident response plan should name who decides.

What EDR records on workstations and servers, and where it stops

OMB memorandum M-22-01, which set EDR requirements for US federal agencies in October 2021, says EDR combines “continuous monitoring and collection of endpoint data” with “rules-based automated response and analysis capabilities”. In the ASD and CISA list of priority logs for SIEM ingestion, the EDR data includes signature detections, network connections and ports, recently run commands and unsuccessful attempts to access files. For containment, NIST SP 800-61 Rev. 3 suggests letting tools act automatically in some cases, for example by “transferring a compromised endpoint to an isolated remediation network”.

EDR sees only the machines that run its agent. Firewalls, switches, BMCs and most OT controllers run none, and ransomware that encrypts virtual machines from the hypervisor, as our guide to hardening ESXi and vCenter against ransomware describes, works outside the guests where the agents run. An agent that goes silent is a signal as well: the ASD and CISA practitioner guidance says organisations “should have processes in place to identify when systems have stopped generating logs and telemetry”.

EDR vs XDR: more sensors, mostly from one vendor

EDR covers the endpoints, while XDR starts from an EDR and adds sensors for email, network, identity or cloud, usually from the same vendor, so one incident shows the activity across those layers. We found no definition of XDR from NIST, ENISA or ASD. ENISA’s technical implementation guidance (June 2025) lists “Endpoint detection and response (EDR) and Extended Detection and Response (XDR) tools in place” among the examples of evidence for automated monitoring under point 3.2.2 of Implementing Regulation (EU) 2024/2690.

Depending on the product, one incident can lead to a response in each layer: removing a phishing message from mailboxes, disabling the account and isolating the laptop that opened the attachment. Other vendors’ sources arrive through integrations, so ask which ones it ingests, in what detail, and whether they feed the correlation or are only stored.

SIEM vs XDR and EDR: every log source, kept for investigation

The guidance on SIEM and SOAR that ASD’s Australian Cyber Security Centre and CISA published with partners on 27 May 2025 defines a SIEM as “a type of software platform that collects, centralises, and analyses log data”. NIST’s SP 800-92 of 2006, whose 2023 revision is still a draft, describes a SIEM server that “correlates events among the log entries, identifies and prioritizes significant events, and initiates responses to events if desired”.

The difference from XDR lies in the sources and the time span. A SIEM takes logs from any system, whether an XDR covers it or not: firewalls and VPN gateways, domain controllers and the directory service, hypervisors and vCenter, backup servers, cloud and SaaS audit logs. The ASD and CISA list of priority logs starts with EDR and network devices, then domain controllers and the directory service, in what it calls “a loose prioritisation by category of data source”, and its authors “discourage logging for the sake of logging”. A GPU server’s utilisation counters and XID errors, covered in our guide to GPU server monitoring with DCGM, belong in operational monitoring, while its sign-ins and administrator actions belong in the SIEM.

For organisations new to detection, the practitioner guidance suggests as a starting point “a minimum of one year for logs that record administrative and security-related events” and 90 days for informational logs. Implementing Regulation 2024/2690 requires the providers it covers to keep and back up logs for a predefined period, protected from unauthorised access or changes (Annex point 3.2.5), and our article on NIS2 incident reporting deadlines shows why the reports depend on them.

The executive guidance notes that most SIEM pricing models “are based on the quantity of data the SIEM ingests” and expects “multiple personnel” to work on implementing a SIEM or SOAR “on a full-time basis”. For an IT team of four, that decides whether the SIEM runs in-house, at a provider or later.

How SOAR automates the response, and when to add it

In the executive guidance’s words, a SOAR “automates some of the response to detected cyber security events and incidents” through predefined playbooks, such as isolating the source of an event in the network. The guidance says that, in general, “it is necessary to properly implement a SIEM and ensure it is accurately alerting cyber security events and incidents before implementing a SOAR”, and that automated actions “do not replace human incident responders but can complement them”.

For 200 to 2,000 staff we would start with a few tested steps in the SIEM or XDR rather than a separate platform: enrich the alert, open a ticket, isolate a laptop on a high-confidence detection and call the person on duty. Amid many false positives, the practitioner guidance warns, teams “may experience ‘alert fatigue’ and miss or delay their response”.

MDR vs EDR: a service that watches the tools

MDR is a managed service in which the provider’s analysts watch the alerts of an EDR or XDR, the provider’s own or yours, investigate them and respond with actions agreed in advance, such as isolating a host. Some contracts add SIEM alerts or cloud audit logs. We found no definition of MDR from NIST, ENISA or ASD either, so each contract sets the scope. NIST SP 800-61 Rev. 3 lists outsourcing a security operations centre (SOC) to a managed security services provider as one way to staff incident response, next to an internal team. NIS2 lists managed security service providers in Annex I, and Implementing Regulation 2024/2690 covers them.

The executive guidance recommends checking whether providers offer high-quality monitoring and incident response at all hours, have a good security posture, and are located in, or have offices in, other countries. In the contract it points to “the degree of visibility the service provider will provide back to your organisation” and “the division of responsibility and liability for detecting and responding to cyber security incidents”. It also notes that in-house staff can query users and start the response, while “outsourcing can produce visibility gaps, work duplication, and communication difficulties”. Ask, too, what happens to the telemetry and detection rules when the contract ends.

Who watches the alerts at night and at weekends

Alerts arrive at night and at weekends as well, and unless someone receives them, assesses them and acts, the tools only record what happened. For the digital providers it covers, Implementing Regulation 2024/2690 requires that “in case of an alarm, a qualified and appropriate response is initiated in a timely manner” (Annex point 3.2.4), with monitoring run “either continuously or in periodic intervals, subject to business capabilities” (point 3.2.2). Other companies can use the same wording as a reference.

Four arrangements can cover the hours outside the working day, alone or combined. Own staff on call can work when alerts are few and well tuned and the person on duty may isolate a server without asking. An MDR service handles the EDR or XDR alerts within its contract, while a SOC service working on the SIEM takes in more sources and needs access to your logs. Automated containment suits narrow, high-confidence cases, such as a laptop that starts encrypting file shares, with a review the next morning.

The choice is the company’s, and it needs writing down: who receives which alert, who stands in, who may isolate a server or disable an account at night, and whom that person calls when an incident looks significant. Those names and rights belong in the incident response plan, and our guide to what an incident response plan must contain sets out the rest.

Our cyber resilience service includes an incident response plan with roles, actions and deadlines. Tell us who receives security alerts today at night and at weekends, and what that person is allowed to switch off.

Typical combinations for 200 to 2,000 staff, and checks before you buy

The table is our recommendation for typical estates; sector, NIS2 status, OT and team size can shift it.

COMPANY PROFILETOOLSWHO WATCHES AT NIGHTWATCH OUT FOR
About 200 staffEDR on all workstations and servers; firewall, VPN, directory, hypervisor and backup logs in a central store kept for one yearan MDR service on the EDR, or an on-call rota with written authority to isolatealerts on the central store, such as failed administrator sign-ins
500 to 1,000 staffXDR, plus a SIEM for the sources the XDR does not cover and for retentionMDR for XDR alerts; on-call staff or a SOC service for SIEM alertstwo alert queues: decide which console leads an investigation
1,000 to 2,000 staffSIEM as the central record, EDR or XDR, SOAR for tested playbooksown team by day; a SOC or MDR service at night and at weekendsseveral people working on the SIEM full-time, as ASD and CISA expect

Our recommendation; the staffing remark follows ASD and CISA’s executive guidance on SIEM and SOAR (May 2025).

Before you buy or renew, check the following.

  1. List every system and the tool that sees it, and mark the gaps, such as hypervisors, BMCs, OT gateways and SaaS admin portals.
  2. Set retention per log type and compare it with what the EDR or XDR console keeps.
  3. Alert when a log source or an EDR agent stops sending, and monitor the log platform from outside. For the providers it covers, the implementing regulation lists the stopping and pausing of logs among the events to log where appropriate (point 3.2.3), and point 3.2.6 requires synchronised time sources where feasible and redundant monitoring and logging systems, monitored “independent of the systems they are monitoring”.
  4. Test detection with techniques from MITRE ATT&CK, MITRE’s public knowledge base of adversary tactics and techniques, in the “regular and repeated exercises” the practitioner guidance recommends.

Central logging and device posture are also steps in our zero trust roadmap for mid-size companies.

EDR/XDR on workstations and servers and event centralisation in a SIEM are part of our cyber resilience service. Send us your headcount, sites and current log sources through the form below.

What we do

Firewalls, intrusion prevention (IPS), email and web traffic filtering, EDR/XDR on workstations and servers and event centralisation in a SIEM, on Trend Micro, Cisco and other vendors’ solutions, are part of our Cyber Resilience service, with engineering by our partner Vixen.UNO. The same service includes an incident response plan with roles, actions and deadlines. Who acts on alerts outside office hours is a decision your company makes, and the plan should name that person and a deputy. The first call is free of charge, and the technical assessment gives you a risk map and a prioritised action plan, at a price fixed before work begins.

FAQ

What is the difference between EDR and XDR?
EDR uses an agent on workstations and servers to record process, file and network activity on each host, detect attacks and contain them there, for example by isolating the machine from the network. XDR starts from an EDR and adds sensors for email, network, identity or cloud, usually from the same vendor, correlating their alerts into one incident. Sources from other vendors reach an XDR only through integrations, whose depth differs between products.
What is the difference between XDR and SIEM?
XDR correlates alerts mainly from one vendor’s sensors and responds through them, while a SIEM collects, centralises and analyses logs from any source, such as firewalls, VPN gateways, the directory service, hypervisors and backup servers, and keeps them for investigation and reporting. The two can work together, with the XDR passing its incidents to the SIEM, which holds the record across all sources. ASD and CISA note that most SIEM pricing depends on the volume of data ingested and that a SIEM needs skilled staff on an ongoing basis.
SIEM vs EDR: do I need a SIEM if I have EDR?
EDR sees only the machines that run its agent, so firewalls, switches, VPN gateways, hypervisors, BMCs, backup appliances and cloud services need their logs collected somewhere else. A SIEM is one place for them, and a company without staff to run one can start with central log collection and retention and add a SIEM, or a provider who runs it, later. As a starting point for organisations new to detection, ASD and CISA suggest keeping logs of administrative and security-related events for at least one year.
What is the difference between MDR and EDR?
EDR is software on the endpoints, while MDR is a managed service in which a provider’s analysts watch the alerts of an EDR or XDR, investigate them and respond with actions agreed in advance, such as isolating a host. The EDR or XDR can be the provider’s own or one you already run, and some contracts add SIEM alerts or cloud audit logs. Before signing, check the hours covered, the sources watched, the actions the provider may take without asking you and the visibility it gives back to you.
What is SOAR and does a mid-size company need it?
SOAR (security orchestration, automation and response) automates part of the response by running predefined playbooks when specific events occur, for example isolating the source of an event, blocking network traffic or revoking credentials. ASD and CISA advise implementing a SIEM that alerts accurately before a SOAR and say that automated actions complement human incident responders rather than replace them. For 200 to 2,000 staff we would start with a few tested automated steps in the SIEM or XDR rather than a separate platform.
Who should watch security alerts outside office hours?
That is a decision each company has to make: its own staff on call with written authority to act, an MDR or SOC service, automated containment for narrow high-confidence cases, or a combination of these. Whoever it is needs the right to isolate a host or disable an account at night and a named person to escalate to. For the digital providers it covers, Implementing Regulation (EU) 2024/2690 requires a qualified and appropriate response to an alarm to be initiated in a timely manner.

Send us your headcount and sites, the endpoint protection and log sources you run today, and who receives security alerts at night and at weekends. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna