Managed security
XDR as a Service
Six consoles, one story.
XDR, extended detection and response, joins the security signals from your endpoints, identities, email, cloud services and network into one place, so a single event can be followed across all of them instead of appearing as five unrelated alerts. It costs more than managed EDR. It earns that for organizations with several distinct systems to watch, and not for everybody.
Who it's for
The alert that means nothing until you see the other four.
XDR solves one specific problem: signals that are individually unremarkable and together tell you something. If you do not have that problem, buy the cheaper thing.
The same event appears in three consoles and nobody joins them. A sign-in from an unfamiliar location, a new mailbox rule, and a tool running on a laptop. Separately, each is a shrug. Together, in order, they are a story, and joining them is a job somebody has to have.
You run more than one estate. Microsoft 365 plus a cloud platform, plus servers in the building, plus a network that runs machinery or building systems. Every additional estate is another console and another set of assumptions about what normal looks like.
You need to answer “what did this reach” in a day. Privacy legislation, cyber-insurance claims and client contracts all ask that question with a short clock attached. Answering it from five separate logs takes a fortnight. Answering it from one timeline takes an afternoon.
Your managed EDR keeps stopping at the edge of the device. The endpoint layer is deployed, covered and watched, and the questions you now have are about accounts, mailboxes and cloud files rather than machines. That is the honest moment to look at this.
Who does not need XDR
If your organization is laptops, Microsoft 365 and not much else, most of the correlation XDR sells you already happens inside Microsoft 365, because identity, email and files are one platform.
In that case, managed EDR plus properly configured Microsoft 365 security gets you most of the way for meaningfully less. We would rather tell you that on the first call.
What's included
The signals we connect, and what we do with them together.
The value is entirely in the joins. A list of connected sources with nobody correlating them is a more expensive version of the problem you already have.
-
Endpoint signal
Everything managed EDR already produces: process behaviour, isolation, and the recorded timeline of what happened on each machine. This is the foundation layer, and XDR without it is built on sand.
-
Identity and sign-in signal
Who signed in, from where, on what device, and whether a second factor was used. Identity is where most incidents in cloud-first organizations begin, and it is the signal most often collected and never looked at.
-
Email signal
Delivered messages, quarantine actions, new forwarding and mailbox rules, and links clicked after delivery. A rule quietly forwarding invoices to an outside address is invisible on the endpoint and obvious here.
-
Cloud and SaaS signal
Administrative changes, file sharing to outside parties, new application consents, and permission grants in your cloud platforms. The consent somebody clicked through in 2023 is the kind of thing this surfaces.
-
Network and firewall signal
Traffic patterns, blocked connections and outbound destinations from your firewalls and network gear, so a device that is behaving oddly can be checked against where it has actually been talking.
-
Correlation into one timeline
The actual product. One incident record showing the sequence across identity, email, endpoint and cloud, in order, with timestamps, instead of five tickets in five systems that nobody has time to line up by hand.
-
Retention long enough to investigate
Most investigations look backwards further than people expect, and the question is usually about something that started weeks before anyone noticed. Retention is agreed in writing up front because it costs money and it is the thing quietly cut to make a price competitive.
-
The same human triage and containment
Analysts in our security operations centre in Canada read the correlated incidents and act within the authority you set. Correlation makes their job possible. It does not do their job.
How it works
Connect what is worth connecting, in that order.
Connecting everything at once produces a bill and a noise problem. We connect in order of what each source will actually tell you.
-
Inventory the signals worth collecting
A short exercise listing every system that produces security-relevant logs, what each would add, and what it costs to retain. Some sources earn their place immediately, some never do, and we will say which is which rather than connecting everything available.
-
Connect, correlate, baseline
Sources are connected in priority order: identity and endpoint first, then email and cloud, then network. Then a quiet period learning what normal looks like across the joined picture, which is different from normal in any single console.
-
Tune, hunt and review
Correlation rules are tuned monthly against your environment, threat hunting runs across the joined data rather than one source at a time, and every quarter we check that the connected sources still match the systems you run.
What it costs
Priced per user and per connected source.
The pricing model matters more here than anywhere else on this site, because the common one charges you by the gigabyte and then discourages you from connecting anything.
Retention beyond the standard period is priced separately and named in the quote rather than assumed.
What moves it:
- How many sources. Identity and endpoint are the baseline. Each additional estate, a cloud platform, an industrial network, a line-of-business system, adds real ingestion and real tuning work.
- How long you keep the data. Investigation depth and audit obligations both push this up, and it is the honest place the money goes.
- Whether managed EDR is already in place. If it is, this is an extension. If it is not, that comes first and is quoted first.
Bundled with SOC as a service it is cheaper than the two bought separately, because it is the same analysts and the same tuning cycle.
Why we do not price on data volume
Charging by gigabyte ingested creates an incentive that works against you: every time you improve visibility, your bill rises, so the sensible commercial decision is to connect less and see less.
If a quote you are comparing is priced that way, ask what happens to the number when you add a second office or turn on verbose firewall logging. Ask before signing, not at the first renewal.
Why us for this
XDR is a category name. Ask what is actually connected.
Vendors disagree about what XDR means, and the acronym has been applied to products ranging from a genuinely correlated platform to an endpoint tool with two extra connectors. Nothing about the three letters tells you what a given provider is selling, so the only useful question is which of your systems are connected and who reads the result.
happier IT will answer that with a list, in the quote, before you sign anything. Sources connected, retention period, what is deliberately excluded and why. If a source is not worth connecting for you, it will not be on the list and we will say why rather than padding the number.
The correlation is only half of it. The other half is the analysts in our own security operations centre in Canada, who are happier IT employees rather than a subcontracted desk. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.
And the honest limit: XDR improves what you can see and how quickly you can answer questions. It does not reduce the number of controls you need underneath it. An organization with excellent correlation and no tested backup has bought the wrong thing first.
Go deeper
- Managed EDR The layer underneath, and usually first.
- What is a SIEM? The close relative, and how it differs.
- SOC as a service Who reads the correlated incidents.
Questions
What people ask before they sign anything.
What is XDR?
XDR stands for extended detection and response: a security platform that collects signals from more than one place, endpoints, identity, email, cloud services, network, and correlates them so one event can be followed across all of them. The “extended” part is the whole idea. EDR sees the device. XDR sees the device, the account that was using it, the message that arrived first and the file that was shared afterwards, as one sequence.
What is the difference between EDR and XDR?
Scope. EDR, endpoint detection and response, watches laptops, desktops and servers, and it is very good at that. XDR takes the same idea and extends it across identity, email, cloud and network, so an alert can be checked against everything else happening at the time. XDR costs more and it only pays back when you genuinely have several estates to join. Get the endpoint layer complete and monitored first; managed EDR is that page.
What is the difference between XDR and SIEM?
A SIEM, security information and event management, collects logs from anything that produces them and lets you build your own correlation rules, which is powerful and needs skilled people to run. XDR is more opinionated: it connects a defined set of security sources and arrives with the correlation already built. In practice most providers, including us, run something with characteristics of both. Ask which sources are connected rather than which acronym is on the invoice.
Do we need XDR?
Probably not yet, if your organization is laptops and Microsoft 365 with nothing else significant. Identity, email and files are one platform there, so a good deal of the correlation already exists inside it. XDR earns its cost when you have genuinely separate estates, a cloud platform alongside on-premises servers, or an operational network alongside the office one, or when you must answer “what was reached” quickly and repeatedly. We will tell you which category you are in.
Does Microsoft Defender XDR count as XDR?
Yes, for organizations whose world is largely Microsoft. It correlates across endpoints, identity, email and cloud applications inside the Microsoft platform, and many organizations already own a good deal of it inside a Microsoft 365 licence they are paying for. The gaps appear at the edges: a firewall, an operational network, a cloud platform from another vendor. We check what you already own before proposing anything additional.
How long do you keep the data?
Retention is the quiet variable in this market. Investigations look further back than people expect, and a short retention period is the easiest way to make a price look competitive without the buyer noticing until the moment it matters.
What does XDR cost?
When comparing quotes, ask three things: which sources are actually connected, how long data is retained, and whether the price rises with data volume. The third one is what turns a competitive quote into an uncomfortable renewal.
Related
Where to go next.
Go deeper
The layers around it
Related services
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.