GAM Tech Blog: IT Solutions & Cybersecurity Trends

Managed Detection and Response for Canadian SMBs 2026 | MDR vs EDR

Written by Adrian Ghira | Oct 1, 2026, 3:00:01 PM

At 2:14 on a Sunday morning, a set of credentials belonging to your controller is used to sign in from an IP address in a country where you have no staff, no clients, and no suppliers. Multi-factor authentication is satisfied, because the attacker phished the session token rather than the password. Over the next four hours the account is used to read the mailbox, create an inbox rule that quietly moves messages from your bank into an obscure folder, and register a new authenticator device.

Nothing breaks. No file is encrypted. No alarm sounds in your office, because your office is empty. Your endpoint protection generated three alerts, and all three are sitting in a console that nobody opens on weekends. On Monday at 8:40 a.m., your IT provider starts working through the ticket queue in the order it arrived.

That gap between 2:14 a.m. Sunday and whenever a human actually looks is the single most important variable in whether an incident becomes an inconvenience or a catastrophe. It is also the thing most Canadian businesses in the 20 to 200 user range have never measured, because the question is uncomfortable and the answer usually is not a number.

This article is about closing that gap. It covers what managed detection and response actually is, how it differs from the endpoint tool you may already be paying for, what it costs in Canada in 2026, and the four questions that separate a real service from a dashboard with a support email address. If your largest customer has recently sent you a security questionnaire, you have already encountered a version of this question in writing, and this is the answer to it. 

 

The Question Behind the Question

Strip away the formatting and almost every third-party security review, insurance application, and enterprise procurement questionnaire is testing four things: can someone log in as your staff, would you notice a compromise, could you recover and how fast, and is anyone accountable. The second one is where Canadian SMBs most consistently give an answer they cannot support.

The typical response goes something like this: we have endpoint protection on every machine, our IT provider monitors our systems, and we would be alerted to anything serious. Read closely, that is three separate claims, and in most environments we assess, only the first is verifiable.

"Our IT provider monitors our systems" usually means a remote monitoring and management agent watches for disk space, failed backups, offline devices, and patch status. That is operational monitoring, and it is genuinely valuable. It is not security monitoring. It does not detect an identity-based intrusion, an unusual PowerShell execution chain, or a legitimate administrative tool being used for illegitimate purposes.

"We would be alerted" usually means an email is generated. The question a reviewer, an underwriter, or an attacker cares about is what happens next, at what hour, by whom, with what authority to act. If the honest answer is that the email lands in a shared inbox reviewed during business hours, then the coverage window is roughly a quarter of the week, and attackers are disproportionately active outside it precisely because that is true almost everywhere.

This is not a criticism of internal IT staff or of general-purpose IT providers. Watching security telemetry is a distinct discipline with distinct staffing requirements, and it is unreasonable to expect a two-person internal team, or a help desk sized for ticket volume, to also operate a security operations function overnight.

 

EDR, MDR, XDR, and SIEM in Plain Language

The acronyms in this category are genuinely confusing, partly because vendors have an incentive to blur them. Here is the distinction that actually matters for a business decision.

EDR Endpoint Detection and Response

Software that runs on laptops, desktops, and servers. It watches behaviour rather than matching files against a list of known-bad signatures, records detailed telemetry about what processes did, and can take local action such as killing a process or isolating a device from the network. EDR replaced traditional antivirus because the attacks changed: according to the CrowdStrike 2026 Global Threat Report, roughly 82% of detections in 2025 involved no malware file at all. A scanner looking for files has nothing to match when the intrusion is a valid credential used badly.

The critical point about EDR is that it is a tool. It produces alerts. It does not decide which alerts matter, investigate the ambiguous ones, or take response action beyond what it has been pre-configured to do automatically.

MDR - Managed Detection and Response

A service. A staffed security operations centre watches the output of your EDR, and typically your identity and cloud telemetry as well, around the clock. Human analysts triage alerts, investigate, hunt for activity that did not generate an alert, and execute response actions on your behalf under a pre-agreed mandate.

The shorthand worth remembering: EDR is what gets watched. MDR is who watches it. Most Canadian SMBs need both, and neither one closes the gap on its own.

XDR - Extended Detection and Response

EDR's telemetry scope widened beyond the endpoint to include email, identity, cloud applications, and network. It is a meaningful improvement, because modern intrusions move across those layers rather than staying on one machine. It is still a tooling category, not a staffing model. XDR without anyone watching it is a larger volume of unread alerts.

SIEM - Security Information and Event Management

A log aggregation and correlation platform. It centralizes logs from across your environment and retains them, which matters for investigation and for compliance regimes with retention requirements. SIEM answers "what happened, and can we prove it" better than anything else. It is not a detection service, and an unmonitored SIEM is an expensive archive.

So what do you actually buy?

For an organization with 20 to 200 users, the practical 2026 baseline is EDR or XDR tooling with MDR layered on top, and log retention sized to whatever your insurer, your regulator, or your largest customer requires. Buying tooling without the service is the most common and most expensive mistake in this category, because it produces a defensible-looking answer on a questionnaire and no actual coverage at 2 a.m.

 

The Dwell Time Problem

Dwell time is how long an intruder is present in your environment before they are detected and removed. It is the number that determines how bad an incident becomes, because almost everything expensive happens during the dwell period: reconnaissance, privilege escalation, mailbox reading, data staging, backup discovery, and finally whatever the attacker came to do.

IBM's Cost of a Data Breach research put the average time to identify and contain a breach at 241 days in 2025. That figure was reported as a nine-year low, and the improvement was attributed substantially to AI-assisted detection. Even so, eight months is a long time to have somebody reading your email.

Two things follow from this for a smaller organization.

First, detection speed is worth more than any single preventive control. Prevention fails eventually, and a business with 60 users cannot buy its way to a zero-failure posture. What it can do is compress the window between compromise and containment from months to hours. That single change alters the cost of an incident by an order of magnitude, and it is the specific thing MDR sells.

Second, the ransomware you are afraid of is the last step, not the first. Modern ransomware operators spend days to weeks inside a network before deploying anything, and a meaningful portion of that time is spent locating and destroying backups so that recovery is impossible. Every hour of that preparation is an hour in which detection would have prevented the outcome entirely. Our ransomware response playbook covers what to do once encryption has already happened; MDR is the layer that aims to make that playbook unnecessary.

 

What Attacks Against Canadian SMBs Actually Look Like Now

The threat picture that most SMB security spending was designed around, a malicious attachment landing on an unpatched machine, is no longer the dominant pattern. Four shifts matter for a detection conversation.

Identity is the primary front door. Phishing kits that sit between the user and the real login page defeat SMS codes and simple push approvals by relaying credentials and session tokens in real time. The attacker never needs your password after that; they hold a valid session. This is why our guidance on passkeys and phishing-resistant authentication sits alongside detection rather than instead of it, and why identity telemetry belongs in scope for any MDR service you evaluate.

Attackers use your own tools. PowerShell, remote management utilities, and legitimate remote access software are preferred over custom malware because they are already installed, already trusted, and generate activity that looks administrative. Detecting this requires behavioural context, not a signature. It also produces genuinely ambiguous alerts, which is exactly the category that needs a human analyst rather than an automation rule.

The help desk is now an attack surface. Social engineering aimed at IT support, to reset a password or register a new MFA device for an account the caller does not own, has become a reliable initial access route. This is one reason we do not use AI-only triage on inbound requests and why identity change events belong in a monitored telemetry stream.

Business email compromise still causes the largest direct losses. For a Canadian business in this size range, the incident most likely to cost real money is not encryption; it is a fraudulent payment or a vendor banking change approved under deadline pressure. Mailbox rule creation, impossible-travel sign-ins, and new device registrations are the detections that catch it, and they are identity events rather than endpoint events.

 

What Good MDR Includes and the Four Questions That Expose a Weak One

"MDR" is applied to a very wide range of offerings, from a fully staffed operations centre with contractual authority to isolate your servers, to an alert-forwarding service with a monthly PDF. These four questions separate them faster than any feature list.

1. Who takes action, and what are they allowed to do without calling me first?

This is the most important question and the one weak offerings answer least clearly. There is an enormous difference between a provider that notifies you of a confirmed intrusion and a provider that isolates the affected host, disables the compromised account, and revokes active sessions at 3 a.m. before calling you.

Ask for the containment mandate in writing. Which actions are pre-authorized, which require your approval, and who is on your side of the phone when approval is needed at 3 a.m. A service that can only notify has moved the alert closer to you without closing the gap.

2. What hours is the analyst function actually staffed, and by whom?

"24/7 monitoring" sometimes means software runs continuously while humans work business hours. Ask specifically whether analysts are staffed overnight and on statutory holidays, in which time zones, and whether coverage is provided in-house or subcontracted to a third party in another jurisdiction. If it is subcontracted, that is a sub-processor you may have to disclose on your own customers' security questionnaires, and a data residency question you should resolve before signing.

3. What telemetry is in scope?

Endpoint-only MDR misses the attack pattern most likely to hit you. At minimum, scope should include endpoint, Microsoft 365 or Google Workspace identity and email, and cloud administrative activity. Ask what happens with a server that cannot run an agent, and whether network and firewall telemetry can be ingested.

4. Who owns recovery when something gets through?

Detection and response is not remediation. If an incident requires rebuilding a domain controller, restoring from backup, and coordinating breach notification, find out now whether that work is included, billed separately, or explicitly out of scope. This is the seam where clients discover during an incident that their MDR provider and their IT provider each believed the other was responsible.

Two supporting checks worth making: ask for published MITRE ATT&CK evaluation results for the underlying detection platform rather than accepting a marketing claim about behavioural detection, and ask how many false positives you should expect per month and who absorbs the triage burden.

 

What MDR Costs in Canada in 2026

Pricing in this category is quoted several different ways, which makes comparison difficult. Three models are common: per endpoint per month, per user per month, and bundled into a fully managed IT agreement. Per-user pricing is usually the more honest comparison for a knowledge-work business, because a single employee may have a laptop, a desktop, and a phone.

Standalone, current Canadian market pricing for managed EDR with 24/7 MDR and identity monitoring generally lands somewhere in the range of $130 to $180 per user per month at the fully loaded end, and meaningfully less when it is bundled into a broader managed services agreement rather than bought as a separate security product. Three factors move a quote inside that band:

  • Response depth. Staffed overnight remediation with containment authority costs more than business-hours alerting. It is also the only version that closes the gap you are buying it to close.
  • Compliance scope. Healthcare under provincial health privacy law, legal practices under Law Society obligations, and financial services firms need longer log retention, defined breach notification processes, and reporting formatted for auditors. That adds cost.
  • Environment complexity. Servers, multiple sites, operational technology, and legacy systems that cannot run a modern agent all expand the monitored surface and the engineering effort.

The comparison that matters is not MDR against zero. It is MDR against the alternative, which is building the capability internally. A genuine 24/7 security operations function requires enough analysts to staff three shifts with holiday and vacation coverage, plus tooling, plus a manager. In Canadian salary terms that is a seven-figure annual commitment before software. For a 60-person business it is not a real option, which is why Gartner has projected that the majority of organizations would be consuming MDR as a service by 2026, up from roughly a third three years earlier.

The other comparison worth running is against incident cost. A business email compromise that moves a single fraudulent payment, a week of downtime, or a breach notification exercise across a client base will typically exceed a year of MDR fees. Our analysis of downtime cost and our guide to what cyber insurance actually pays for are both useful for building that number properly rather than guessing at it.

 

MDR and Your Insurance Renewal

Cyber insurance underwriting in Canada has tightened considerably, and detection capability has moved from a nice-to-have to a rated question. Applications now routinely ask whether you have endpoint detection and response deployed, what percentage of devices it covers, whether monitoring is 24/7, and who performs it.

Two practical warnings. First, partial coverage reads as no coverage to an underwriter, in the same way that MFA on 90% of accounts does. If EDR is deployed on laptops but not on the three servers running your line-of-business application, answer the question accurately and expect it to matter. Second, an inaccurate answer on an application is materially worse than an unfavourable one, because it gives a carrier grounds to deny a claim at precisely the moment you need it paid.

The upside is that a documented MDR arrangement is one of the more effective levers available for improving terms, and unlike most security investments it produces evidence a non-technical underwriter can evaluate: a named provider, defined coverage hours, and monthly reporting.

 

A 30-Day Evaluation Plan

If you have decided this gap is worth closing, this sequence gets you to a defensible decision in about a month without a lengthy procurement exercise.

  1. Week 1 - establish what you already have. Inventory every endpoint and server, and record what security agent is on each. Identify the devices with nothing. Confirm whether your Microsoft 365 licensing already includes an EDR-capable agent, because many businesses are paying for one and not using it.
  2. Week 1 - measure your current coverage window. Ask your current provider two questions in writing: what hours are security alerts reviewed by a person, and what is the longest plausible interval between a detection and a human seeing it. The answer is your baseline.
  3. Week 2 - define your containment mandate before you shop. Decide in advance what you want a provider authorized to do without waking you: isolate an endpoint, disable an account, revoke sessions, block an IP. This turns a vague comparison into a specific one.
  4. Week 2 - scope your telemetry requirement. Endpoint plus identity plus email at minimum. Add cloud administrative activity and firewall logs if you have compliance obligations or a customer questionnaire that asks.
  5. Week 3 - run the four questions against two or three providers. Get the containment mandate, staffing model, telemetry scope, and remediation ownership in writing. Compare on those, not on dashboards.
  6. Week 3 - check the sub-processor and data residency chain. Where is your telemetry stored, who else touches it, and can you disclose that accurately to your own customers.
  7. Week 4 - validate with a real test. Ask each finalist how they would have detected the 2:14 a.m. scenario at the top of this article, step by step, and what they would have done without calling you. The quality of that answer is the product.
  8. Week 4 - align the renewal. Bring the selected arrangement to your insurance broker before your next renewal rather than after, so the improvement is priced in. 

 

GAM Tech Differentiators: Detection and Response for Canadian SMBs

GAM Tech has supported Canadian businesses with 20 to 200 users since 2012, from eight offices across Alberta, British Columbia, Ontario, and Quebec, with bilingual support in Ottawa and Montréal.

On detection and response specifically, what distinguishes our approach:

  • Our support team is internal and never outsourced. The person who answers at 3 a.m. is a GAM Tech employee, not a subcontracted overflow desk in another jurisdiction. For your own customers' security questionnaires, that means one fewer sub-processor to disclose.
  • No AI-only triage. Automation handles enrichment and correlation. A human decides what matters and what happens next, which is the part that cannot be safely automated when the alert is ambiguous and the action is disruptive.
  • A 5-minute response commitment, delivered on the overwhelming majority of tickets, backed by 24/7 coverage rather than an on-call rotation.
  • Security-first architecture and SOC2 certification. We hold SOC2 certification ourselves, which means the controls we recommend are controls we are independently audited against. We are also B Corp certified and Canadian-owned, built without outside capital.
  • Project packs are included in our managed services agreements. Deploying agents to unprotected servers, tuning detections, and building the evidence package for an insurer or a customer questionnaire are not separate scoping exercises every time.
  • Reporting built for the audiences that ask. Monthly detection and response reporting formatted for a board, an insurance application, or a third-party risk reviewer, rather than a raw alert console you have to interpret.

 

Frequently Asked Questions

What is managed detection and response? MDR is a service in which a staffed security operations centre monitors your security telemetry around the clock, investigates alerts, hunts for undetected activity, and takes response action on your behalf. EDR is the software that generates the telemetry; MDR is the team that watches it and acts.

What is the difference between EDR and MDR? EDR is a tool that runs on your devices and produces alerts plus local response capability. MDR is a managed service that operates that tool for you with human analysts available 24/7. Buying EDR without MDR means the alerts are generated but only reviewed when someone happens to look.

Do we still need antivirus if we have EDR? Modern EDR platforms include the file-blocking capability that traditional antivirus provided, so a separate product is generally unnecessary and can cause conflicts. Signature-based antivirus alone is no longer adequate, because the large majority of current detections involve no malicious file at all.

How much does MDR cost for a Canadian small business? Priced as a standalone security service, managed EDR with 24/7 MDR and identity monitoring commonly runs in the range of $130 to $180 per user per month fully loaded in Canada in 2026, with response depth, compliance scope, and environment complexity moving the number. It is frequently less expensive bundled into a fully managed IT agreement than purchased separately.

Can our internal IT team do this instead? They can operate the tooling, and many do it well. What an internal team of one to three people cannot realistically provide is analyst coverage overnight, on weekends, and through holidays and vacations, along with the specialized security operations expertise that is a different discipline from IT administration. Most organizations in this size range use MDR to extend an internal team rather than replace it.

Is MDR the same as a SOC? A security operations centre is the team and facility that performs monitoring and response. MDR is how an organization rents that capability as a service instead of building and staffing one internally.

Do we need a SIEM as well as MDR? Not always. MDR operates whatever telemetry layer you have. A SIEM becomes worth its cost when you have compliance or contractual obligations requiring extended log retention and searchable historical records, which is common in regulated sectors and increasingly requested in enterprise customer contracts.

How quickly should an MDR provider respond to a confirmed intrusion? Containment should begin in minutes, not hours, and it should not depend on reaching you first. Ask for the pre-authorized containment actions in writing, because a provider that can only notify you has not closed the overnight gap.

Will MDR generate a lot of false positives we have to deal with? A well-tuned service absorbs the triage burden rather than passing it to you, and you should expect only investigated, confirmed items to reach your team. Ask a prospective provider how many items per month they expect to escalate to you, and treat a vague answer as a warning.

Does our cyber insurance require MDR? Requirements vary by carrier, but detection capability is now a rated question on most Canadian applications, covering whether EDR is deployed, what share of devices it covers, and whether monitoring is 24/7 and by whom. Answer accurately, because an inaccurate application answer creates grounds for a claim denial. 

 

Find Out What Your Coverage Window Actually Is

The uncomfortable question at the top of this article has a specific answer at your organization right now, and it is measurable. How many hours could pass between a detection on one of your systems and a qualified person looking at it? If you do not know, that is the finding.

GAM Tech offers a detection and response assessment across all eight of our Canadian markets. We inventory what is deployed where, identify the devices and services with no coverage, measure your current alert-to-human interval, and give you the written answers you need for your next insurance renewal or customer security questionnaire, whether or not you engage us to close the gap.

Call 1-833-GAM-TECH or book a consultation. Since 2012, SOC2 certified, B Corp certified, 24/7 internal staff, never outsourced.