
MDR, SIEM or antivirus: what does a UK SME actually need?
MDR, SIEM or antivirus - what does an SME actually need?
Endpoint protection blocks known threats and is a baseline, not a strategy. A SIEM collects and correlates logs but needs people to run it. MDR combines detection technology with a team who investigate and respond on your behalf. For most UK SMEs the practical answer is endpoint protection plus MDR, with SIEM only where compliance requires it.
Endpoint protection
Modern endpoint protection - often sold as EDR - goes well beyond signature-based antivirus. It detects behaviour, isolates devices and records what happened.
Covers: malware, ransomware behaviour, suspicious processes on managed devices.
Does not cover: attacks that use valid credentials and never touch an endpoint, cloud and email compromise, insider activity, and anything on a device that is not enrolled.
The real limitation: it generates alerts. Somebody has to read them. In most SMEs, nobody does, consistently, outside working hours.
SIEM
A security information and event management platform collects logs from across your estate - endpoints, identity, firewalls, cloud, applications - and correlates them to spot patterns no single source would reveal.
Strengths: breadth of visibility, log retention for audits, custom detection rules, incident investigation.
Costs beyond the licence: SIEM is priced on data volume, and volume grows. More significantly, a SIEM is a platform, not an outcome. It needs tuning, rule maintenance and analysts. An untuned SIEM produces thousands of alerts a week, and an alert nobody triages provides no protection while still costing money.
Sensible when: you have compliance-driven log retention requirements, or a security team to run it.
MDR
Managed detection and response is a service rather than a product. A provider deploys detection technology across your estate, monitors it around the clock with a security team, investigates alerts, and takes or recommends response action.
Includes: monitoring, triage, investigation, threat hunting, containment, and reporting.
The distinction that matters: MDR includes people. You are buying the analyst hours, not just the console.
Compared
Endpoint protection | SIEM | MDR | |
|---|---|---|---|
Type | Product | Platform | Service |
Coverage | Devices | Whole estate, if fed | Whole estate |
Detection | Automated | Rule-based | Automated plus human |
Investigation | You | You | Provider |
Response | Automated containment | None built in | Provider acts |
24-hour cover | Tooling only | Only if staffed | Included |
Needs internal staff | Minimal | Significant | Minimal |
What most UK SMEs should do
Endpoint protection on every device. Baseline. Required for Cyber Essentials in any case.
Identity protection. MFA everywhere, conditional access, privileged access controls. A large share of incidents begin with a valid credential rather than malware.
MDR. This is where the step change in outcome sits - the move from tools that alert to a team that acts.
SIEM only if you need it. Compliance-driven retention, complex estates, or an internal security function.
Buying a SIEM before you have anyone to run it is the commonest expensive mistake in this category.
Questions to ask an MDR provider
Which data sources do you monitor - endpoint only, or identity, email and cloud too?
Is response included, or only notification?
Are you authorised in advance to contain a device, or must you wait for approval at 3am?
What are your notification timeframes by severity?
Who staffs the monitoring, where, and at what hours?
What does the monthly report contain?
Where NVOY fits
We deliver managed cyber security as part of a single relationship that also runs your IT - so detection, containment and remediation happen without a handover. See IT Security, or read could your business recover from a cyber incident?
BLOGS


