Managed security

Managed EDR

The detection, plus the person.

Managed EDR is endpoint detection and response, security software on every laptop, desktop and server that watches how a machine behaves rather than matching files it has seen before, with happier IT’s Canadian security operations centre attached to it. You get the software, the tuning, and the part that usually goes missing: people who read the detections at 3am and are permitted to act.

Who it's for

You very likely already have the software.

Four situations bring people to this page. Only one of them is a question about which product to buy.

The agent is deployed and the console is unread. The licence renews, the software checks in, and the last sign-in to the dashboard was during the rollout. Reading a detection console properly means someone on a rota who knows what normal looks like in your environment, which is a staffing problem rather than a software one.

Another provider runs your IT and you want the security half watched. This is a common and workable arrangement. It needs the boundary written down first, who monitors, who fixes, who owns the machine while it is isolated, and we will insist on agreeing that before we start.

An insurer asked whether your EDR is monitored, not just installed. Renewal forms have started separating the two, because the gap between them is where the cost sits.

You tried keeping it in-house and it cost somebody their evenings. Usually one capable person who did it well for six months and then quietly stopped. That is what a rota is for, and one person is not a rota.

How this differs from endpoint protection

Our endpoint protection page is about the control itself: choosing it, deploying it to verified coverage, tuning it, encrypting the disks. It answers “is every device covered?”

This page is the service wrapped around it: who reads the detections, during which hours, and what they may do without phoning you. It answers “and then what?” Most organizations need both, and quite a few already have the first.

What's included

What we deploy, and what we do with what it says.

The licence is the cheap half. Most of the list below is coverage, tuning, and human attention, the three things a product cannot sell you.

  • Behaviour-based detection on every device

    Rather than asking whether a file has been seen before, EDR asks whether what is happening makes sense: a process rewriting thousands of files, a script launched from a document, a tool requesting credentials it has no business wanting, a login tool running at 4am on a finance laptop.

  • Deployment to a coverage number you can check

    Rollout, then reconciliation against your asset list and your user directory, so what you receive is a figure for devices covered versus devices owned, not a general impression. The gap is usually a server nobody wants to restart and the laptops of people who have left.

  • Isolation, automatic or one-click

    A machine can be cut off from the network while staying reachable by us. The problem stops moving, the evidence stays intact, and the person using it gets a phone call from a named human rather than a mystery.

  • Human triage from our SOC in Canada

    A SOC is a security operations centre, the team that watches alerts and decides which matter. Ours is in Canada and staffed by happier IT employees rather than a subcontracted desk, which is unusual for a provider of our size.

  • Process termination and clean-up, not just alerting

    Stopping what is running, removing the pieces that would restart it after a reboot, and putting the machine back to a known state. Where a rebuild is the honest answer we will say so rather than declaring it clean and hoping.

  • A recorded timeline you can answer questions from

    EDR keeps a record of what happened on the machine, which is what lets somebody answer the question that actually gets asked afterwards: what did this touch, and did it reach anything with client data in it.

  • Tuning to your environment, monthly

    Every organization runs something unusual: an old line-of-business application, a bespoke script, a design plugin, a backup agent that looks alarming. Untuned tools bury the one real detection under a hundred false ones, and then nobody believes any of them.

  • A monthly report in plain English

    What was detected, what we did about it, coverage as a number, and anything needing your decision. Written so it can go to a director or an insurer without being translated first.

How it works

A pilot first, because rollouts collide with real work.

The failure mode is a fleet-wide deployment that meets one line-of-business application on a Monday morning. A fortnight of pilot removes almost all of that risk.

  1. Pilot on a deliberately awkward dozen

    Someone in accounts, someone working in the field, a designer, one server. A mixed sample surfaces the application conflicts while they are two tickets rather than sixty, and gives us before-and-after performance numbers on real machines.

  2. Roll out, then reconcile

    Deployment across the fleet, followed by the unglamorous part that decides whether any of it worked: comparing what reports in against what you own, and chasing the difference until it reaches zero or is written down with a reason.

  3. Watch, contain, report

    Detections route to our security operations centre under the containment authority you agreed. Rules are tuned monthly, coverage is rechecked, and you receive a report short enough that you will read it.

What it costs

Per device and per server, with the monitoring included.

The number worth comparing is not the licence. It is the licence plus the human attention, and quotes differ mostly in whether the second part is there at all.

Servers are the more expensive agent and the more important one, so check whether a competing quote includes them.

For happier IT managed IT A device without it is not a device we can look after honestly.

Where you already own a suitable licence inside a Microsoft plan, we will tell you and manage what you have rather than selling a second product to sit beside the first. That happens often enough to be worth checking before anyone quotes anything.

What “managed” has to mean

Three things, or the word is decoration. Somebody reads the detections. You know which hours they are staffed. They are permitted to isolate a machine at an agreed severity without phoning first.

If a quote answers “you do”, “software hours” and “no”, you are buying software. That can be the right decision, just price it as software and put the saving somewhere useful.

Why us for this

Every provider resells the same handful of platforms.

The vendor badge on a proposal tells you very little. Almost any Canadian provider can resell broadly the same endpoint platforms, at broadly the same price, with broadly the same detection quality. What differs is the twenty minutes after something fires at 2am on a Saturday.

happier IT’s analysts are our own employees, working from our own security operations centre in Canada with your environment and your ticket history in front of them. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific. Time from a critical detection to a person looking at it: minutes, not hours. The platform we deploy is SentinelOne, though who is watching it matters more than whose logo is on it.

We will also tell you what this does not do. EDR will not stop somebody typing their password into a convincing page, that is a job for email security and phishing prevention. It protects nothing on a device where it was never installed, which is why the coverage number matters more than the feature list. And it sees the device rather than the whole estate, which is the honest case for XDR once the device layer is genuinely done.

Go deeper

Questions

What people ask before they sign anything.

What is managed EDR?

Managed EDR is endpoint detection and response software plus a team who watch it. EDR is security software on each computer and server that monitors behaviour, records what happened, and can isolate the machine from the network on its own. “Managed” means somebody outside your organization is on a rota reading those detections, deciding which matter, and acting within an authority you agreed in advance. The software without the people is the common and less useful purchase.

What is the difference between EDR and managed EDR?

EDR is what you install; managed EDR is what happens when it fires. Unmanaged, a detection lands in a console and waits for somebody to open it, which in most organizations under 200 people is nobody, especially outside office hours. Managed, it lands with an analyst who checks it against the rest of your environment, isolates the device if that is warranted, cleans up, and tells you what it was. The software is roughly the same in both cases.

How is this different from your endpoint protection page?

Endpoint protection is about getting the control right: choosing the software, deploying it until every device is genuinely covered, tuning it, encrypting disks, keeping recovery keys somewhere findable. This page is about the service wrapped around it, who watches, during which hours, and what they may do. If nothing is deployed yet, start with that page. If it is deployed and unread, start here.

Should we buy XDR instead?

Not until the endpoint layer is genuinely done. XDR, extended detection and response, adds identity, email, cloud and network signals to the endpoint picture so one event can be followed across all of them. It costs more, and it earns that cost when you have several distinct systems to watch. If your world is laptops and Microsoft 365, managed EDR plus properly configured Microsoft 365 security covers most of what XDR would tell you, for less.

Can you monitor EDR that another provider deployed?

Usually yes, depending on the platform and whether the licence permits a second party to administer it. We will check that before quoting rather than after. The part that needs agreeing first is not technical: who owns the machine while it is isolated, who tells the user, and who does the rebuild if one is needed. Written down in advance, this arrangement works well. Left vague, it goes wrong at the worst moment.

Will you isolate a machine without asking us?

Only at the severities you authorised during onboarding. Isolating one device is quickly reversible and stops a problem spreading, so most clients authorise it outright. Wider actions, a server, a whole site, a company-wide password reset, generally require a call. You approve that document before we act on anything, you can change it whenever you like, and we review it with you every quarter.

What does managed EDR cost?

When comparing quotes, check whether servers are counted and whether anyone is actually reading the console.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.