EDR vs XDR vs MDR: What Indian Businesses Actually Need in 2026
The short answer: EDR is a tool that watches endpoints. XDR is a tool that correlates endpoints with identity, email, network and cloud. MDR is a service — someone else operating one of those tools around the clock. The first two are technology decisions. The third is a staffing decision, and for most Indian mid-market organisations it is the one that actually determines whether detection works.
The distinction matters commercially because vendors blur it deliberately. A platform sold as “XDR” that only ingests its own agent’s telemetry is EDR with a wider dashboard. A “managed XDR” contract with no named response authority is an alerting service. Both are common, and both are discovered after the contract is signed.
The three, precisely
EDR — Endpoint Detection and Response
An agent on laptops, desktops and servers records process execution, file and registry changes, and network connections, then flags suspicious behaviour and gives an analyst the ability to isolate the host, kill a process or roll back a change. EDR replaced signature antivirus because modern intrusions use legitimate tools — PowerShell, RDP, credential dumping from memory — that no signature matches.
What it does not see: a phishing mailbox rule, a login from an unusual location, a misconfigured S3 bucket, or lateral movement that never touches a managed endpoint. Those are the majority of the early stages of a real intrusion.
XDR — Extended Detection and Response
XDR correlates endpoint telemetry with at least identity and email, and usually network and cloud. The value is not more alerts, it is fewer: a suspicious PowerShell execution is noise on its own, and an incident when it follows an impossible-travel login and an inbox rule created ten minutes earlier. That correlation is the entire product. When you evaluate XDR, the only question worth asking is which sources does it ingest, and does it correlate them or merely display them side by side.
Ask for the connector list in writing. Ask whether ingesting your identity provider, your Microsoft 365 or Google Workspace tenant, your firewall and your cloud accounts is included or a separate licence. Ask what happens to detection quality if you decline one of them.
MDR — Managed Detection and Response
MDR is people. A provider runs the tooling, triages alerts, investigates, and — if the contract says so — takes containment action on your behalf. It exists because the failure mode of EDR and XDR is not detection, it is that the alert fires at 02:40 on a Sunday and nobody is looking.
The contract terms that decide whether MDR is worth anything:
- Response authority. Can they isolate a host themselves, or do they call you and wait? Named, in writing, with the specific actions pre-authorised.
- Time to investigate, not time to notify. A 15-minute notification SLA that hands you a raw alert has moved the work, not done it.
- Coverage hours in your timezone, and who is on shift at 03:00 IST.
- What you keep if you leave — the telemetry, the detection content, or nothing.
What Indian regulation forces into the decision
Three obligations turn this from a preference into a requirement, and they are the reason a purely endpoint-scoped tool tends to be insufficient here:
- CERT-In directions (28 April 2022): reportable cyber incidents must be reported to CERT-In within six hours of being noticed. Six hours is a detection-and-triage deadline, not a paperwork deadline. If nobody is watching overnight, the clock has already run before anyone opens the console.
- Log retention: the same directions require ICT system logs to be maintained for a rolling 180 days and stored within India. This is a hard question for any SaaS detection platform — ask where the telemetry physically lands, and get the answer in the contract, not the sales deck.
- Clock synchronisation: ICT system clocks must be synchronised to NIC or NPL NTP servers. Correlation across sources is worthless if the timestamps disagree, so this is a detection requirement as much as a compliance one.
Sector rules stack on top. Banks, NBFCs and payment operators are examined under the RBI’s CSITE framework, where monitoring coverage and incident response are assessed directly. Organisations processing personal data carry breach-notification duties under the DPDP Act 2023, which you cannot discharge without knowing what was accessed — which is a telemetry-retention question.
Choosing, without the vendor matrix
The decision follows headcount far more than company size:
- No dedicated security staff. MDR, on whatever platform the provider runs well. Buying XDR you cannot staff produces an expensive dashboard nobody opens; this is the single most common wasted security spend we see.
- One or two security people, business hours only. XDR plus MDR for out-of-hours. Your team owns tuning and context; the provider owns the night.
- A functioning internal SOC. XDR, and the argument becomes XDR versus SIEM. XDR is faster to value and opinionated about correlation; SIEM is more flexible and takes engineering. Regulated entities often need SIEM for retention and audit evidence regardless, in which case XDR sits in front of it for detection quality.
- Endpoint-only estate with real constraints. EDR is a legitimate stopping point — but be explicit that email and identity are uncovered, and compensate elsewhere.
Questions that separate real capability from a demo
- Show me a correlated detection across two different sources in my tenant during the trial — not a canned demo.
- Which of my sources are ingested at the licence tier you quoted?
- Where is my telemetry stored, and for how long, and can I meet 180-day in-India retention with it?
- What exactly can your analysts do without calling me first?
- How do I get an incident timeline suitable for a CERT-In report, and how fast?
- What is the tuning effort in the first 90 days, and who does it?
- On exit, what data comes with me?
The honest framing is that detection tooling is a means of shortening the gap between compromise and containment. Anything that does not measurably shorten that gap — because nobody watches it, because it cannot see the systems attackers actually use, or because the response authority is unclear — is not buying you security no matter what it is called.
Praxis-Q runs endpoint security and XDR readiness assessments, evaluates MDR contracts against CERT-In and sector obligations, and provides vCISO oversight for organisations running the tooling themselves. If you are choosing between these three, or suspect you bought one and needed another, talk to us.
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Sahil Dubey
Compliance & Security Expert
Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.
