Back to blog
Security·

EDR for Indian Companies: What Actually Works in 2026

Security operations centre monitoring endpoint detection and response dashboards for an Indian company

The 3 AM call from a 90-person logistics firm in Peenya

In March 2026 a transport company we support — 92 staff, three sites, roughly 140 endpoints — got hit by a commodity infostealer wrapped inside a fake shipping manifest. Their existing security stack was three-year-old antivirus with a definition file last updated eleven days prior because the renewal had lapsed into a grace period nobody tracked. The malware ran for six hours before anyone noticed. By then, credentials for their Tally server, their WhatsApp Web sessions, and two Gmail accounts used for customer invoices had been exfiltrated to a Telegram bot. Recovery cost them ₹3.4 lakh in emergency consulting, ₹78,000 in overtime, and one full working day of zero dispatch operations. The fix — an actual EDR deployment with 24x7 monitoring — costs them ₹1,05,000 per year. They spent three times that in a week.

That is the honest pitch for endpoint detection and response for Indian companies. Not a Gartner quadrant. Not an acronym. A number on a P&L that either hurts now or hurts much more later.

EDR is not antivirus with a bigger dashboard. It is software that watches what processes do — parent-child relationships, network calls, registry writes, file touches — and flags behaviour that looks wrong even when no signature matches. That distinction matters enormously in 2026 because roughly 70% of the malware we see on Indian SMB networks is either fileless (lives in memory, PowerShell scripts, WMI abuse) or freshly compiled and packed so that no AV vendor has a signature yet. Signature files cannot catch what has never been seen. Behaviour rules can.

This piece is about what EDR really costs an Indian company of 20 to 500 staff, how the alert triage workload breaks down, why most SMBs should not run it themselves, and where the honest limits are. If you want to skip to the service angle, our endpoint computing practice covers procurement, deployment and monitoring in one place.

What traditional antivirus actually catches in 2026

I want to kill a myth first. Antivirus is not useless. Windows Defender, at its 2026 build, is genuinely good at catching known malware, commodity ransomware, and the stuff that arrives via email attachments. If your organisation is 15 people running Window 11 24H2 with Defender turned on and patched, your baseline is not zero.

But here is where it falls over, in order of how often we see it:

Signed binaries doing bad things. A digitally signed executable from a legitimate but compromised vendor will not trigger Defender. It has a valid certificate. It is allowed to run.

Living-off-the-land attacks. When an attacker uses certutil.exe, bitsadmin, or wmic — all legitimate Windows tools — to download payloads, AV sees normal admin behaviour. Detection has to come from anomaly analysis, not signature matching.

Lateral movement inside a flat network. AV on each endpoint has no idea that the same credential just logged into four machines in twelve minutes. EDR correlates; AV does not.

Slow-burn exfiltration. One gigabyte of customer data leaving over six weeks, disguised as nightly backup traffic, is invisible to every antivirus on the market.

There is also a practical cost point. Traditional AV consoles on Indian SMB networks are usually neglected. Nobody checks them. Nobody reads the weekly report because it is 400 emails long. Even when the AV had a detection, it was muted.

Side-by-side: AV vs EDR in an Indian SMB context

CapabilityTraditional AV (e.g. Defender, Quick Heal, K7, Seqrite)EDR (e.g. Sophos Intercept X, CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender for Endpoint P2)
Known malwareGood, near-instant signature deploymentGood
Fileless / memory-resident attacksPoorStrong
Behavioural detection (LOLBins, WMI abuse)MinimalCore capability
Process lineage and root-cause viewNoneFull attack chain reconstruction
Lateral movement detectionNoneCorrelation across endpoints
Response actions (isolate, kill, quarantine)RarelyStandard — one-click endpoint isolation
Forensic data retention7–30 days logs, rarely exported30–180 days rolling telemetry
Typical Indian SME cost per endpoint per year (2026)₹600–₹1,400₹1,800–₹4,500
Realistic staffing requirement0 (if you ignore the alerts)0.5–1.5 FTE if self-managed

The gap that matters is not detection sensitivity. It is response. AV tells you something might be wrong in a log nobody reads. EDR lets a human isolate an endpoint from a browser console in under thirty seconds even if that human is in Coimbatore and the endpoint is in a Bangalore office.

What EDR costs in India in 2026

Let me put real numbers. These are street prices we see from Indian distributors and OEM direct, exclusive of GST (18% IT services slab), and they assume you buy through a partner rather than direct from the vendor.

Standalone EDR licences (per endpoint, per year, 2026)

Product50–150 endpoints150–500 endpointsNotes
Sophos Intercept X Advanced (with XDR)₹2,600–₹3,400₹2,100–₹2,800Includes 24x7 MDR option at extra cost
CrowdStrike Falcon Pro₹3,800–₹5,200₹3,200–₹4,300Premium product, thin Indian SMB channel support
SentinelOne Singularity Control₹3,400–₹4,600₹2,900–₹3,900Strong behaviour engine, needs skilled operators
Microsoft Defender for Endpoint P1₹1,150–₹1,600₹950–₹1,400Cheapest legitimate EDR-grade tier; requires Intune and Defender config discipline
Microsoft Defender for Endpoint P2₹2,900–₹3,700₹2,400–₹3,100Adds automated investigation and response
K7 Endpoint Security (Pro)₹850–₹1,300₹700–₹1,050Indian product, Indian support hours; lighter on behavioural detection
Seqrite Endpoint Security (EPS Pro)₹900–₹1,500₹750–₹1,200Indian, integrates with Quick Heal ecosystem

Your actual invoice depends on multi-year commitment (usually 15–20% off on three-year terms), the number of servers versus desktops (servers often cost 1.5x), and whether you bundle with a firewall. A 50-engineer firm in Whitefield running Sophos EDR + NGFW on a three-year deal typically lands around ₹2,000 per endpoint per year blended.

Managed EDR (per endpoint per month, 2026)

ApproachCost per endpoint / monthIncluded
Standalone licence, self-managed₹150–₹400 (licence only)Software, updates, you do triage
Licence + basic SOC monitoring (business hours)₹350–₹650Alerts triaged 9am–7pm IST, escalation
Licence + 24x7 SOC with response authority₹650–₹1,200Round-the-clock triage, isolation, remediation
Full MDR service (vendors like Sophos MDR, CrowdStrike Falcon Complete, SentinelOne Vigilance)₹900–₹1,800Vendor SOC, IR retainer, threat hunting

A 120-endpoint deployment with 24x7 managed EDR lands between ₹9,00,000 and ₹15,00,000 a year, licence inclusive. A comparable self-managed deployment costs ₹2,50,000–₹4,50,000 in licences, plus you need someone to actually staff it.

That last clause is where most Indian SMBs get the maths wrong.

The staffing trap nobody warns you about

EDR software on its own generates noise. A single Sophos console managing 150 endpoints on a moderately active Indian office network produces somewhere between 40 and 300 alerts per day depending on tuning. Most are false positives from legitimate but unusual behaviour — an accounting manager installing a new banking utility, a developer pushing production builds, a Windows feature update triggering unusual process trees.

If you are self-managing, you need to either tune aggressively or hire. On paper, one analyst can handle 100–150 endpoints with good tuning. In practice, on an Indian SMB network with the mix of legacy software that actually exists — Tally, Busy, old SAP clients, custom .NET apps, an ancient Delphi-based ERP still running on one machine in the accounts department — the noise floor is higher. Plan on one full-time analyst per 200 endpoints if you do this properly.

An entry-level SOC analyst in Bangalore commands ₹5.5–₹8 lakh a year in 2026. A good one — someone who can distinguish a red team exercise from a real intrusion — is ₹12–₹18 lakh. Add 30% for shift differentials when you want 24x7 coverage, plus attrition. You are now looking at ₹25–₹40 lakh a year in payroll to monitor an EDR deployment that cost you ₹4 lakh. That ratio is why managed EDR exists.

What a realistic SMB staffing model looks like

Company sizeEndpointsSelf-managedManaged
20–50 staff25–70Not viable — no one to triageBuy managed EDR; add MDR if budget allows
50–150 staff70–200Possible with one dedicated analyst; expect 30% alert backlogBuy licensed EDR + business-hours managed monitoring
150–300 staff200–400Requires 1.5–2 FTE analyst (₹18–₹30 lakh/yr)24x7 managed EDR is materially cheaper
300–500 staff400–800Viable only with in-house SOC team of 3+ (₹50 lakh+ payroll)Hybrid — managed SOC for detection, internal team for response

If you are a 30-person company and someone sells you self-managed EDR, ask them who is going to wake up at 2 AM to look at the console. If the answer is "the IT guy", you have bought a subscription to a screen nobody watches.

The alert triage burden, honestly

Let me show you what a realistic week looks like with a 120-endpoint managed deployment we run for a healthcare client in Bangalore. This is de-identified, but the shape is typical.

Monday: 8 alerts. Two are Windows Defender detections of an old cracked utility on a radiology workstation (real issue: unlicensed software). Three are LOLBin usage from legitimate IT admin scripts. One is a USB device mounted after hours — turned out to be a doctor bringing scans from home. Two are phishing URLs clicked but blocked at DNS.

Tuesday: 22 alerts. Big spike because Patch Tuesday updates ran overnight and triggered unusual process activity across the fleet. Zero real threats, but each alert still needed a minute or two of checking.

Wednesday: 5 alerts. One matters — an endpoint attempting to reach a command-and-control IP in Russia. Isolated in 40 seconds. Investigation showed the endpoint had been hit by a malvertising redirect five hours earlier. No data lost. This is the day the client's ₹12 lakh a year paid for itself three times over.

Thursday: 14 alerts. Mostly a new CRM agent triggering unusual network calls.

Friday: 9 alerts. One credential-stuffing attempt against the VPN gateway that also touched an endpoint. Two-factor block fired. Logged.

One real incident in a week. That is the ratio. The rest is triage, tuning, tuning, tuning. Anyone who tells you EDR is a hands-off product has never opened a console.

Why the Big Four Indian ERP/legacy-software stacks complicate EDR

The blank-slate deployments you read about in vendor whitepapers do not exist in most Indian SMBs. Your average 80-person trading company in Bangalore is running:

  • Tally Prime on four machines, one of them an old Windows 10 machine in the director's cabin
  • Busy Accounting on the sales floor
  • Two custom .NET apps written in 2016 by a developer who moved on
  • A shared folder with 12-year-old Excel macros in daily use
  • WhatsApp Desktop on 60 machines
  • Chrome at version 118 because an internal app broke on 120

EDR has to live on top of this. Tuning becomes important because otherwise you will drown in alerts from legitimate-but-weird behaviour. Microsoft Defender for Endpoint in particular needs tuning — out of the box on an Indian SMB it flags a lot of Tally and Busy activity as suspicious because those apps do things like write to random locations, spawn child processes unexpectedly, and access network shares aggressively.

We have a standard tuning pass we run for every new deployment:

  1. Baseline two weeks of telemetry before enforcing any automated response.
  2. Whitelist internal applications by hash, not by path.
  3. Downgrade non-critical detections (USB mount outside hours, crypto-mining heuristics on developer machines) to informational.
  4. Configure exclusions for backup software — Veeam Backup & Replication v12 and Synology Active Backup for Business both trigger process-injection detections on server endpoints if excluded incorrectly.
  5. Escalate only four classes to immediate human response: credential dumping, ransomware behaviour, outbound C2, and privilege escalation.

The first week of tuning is where most of the value is created or lost. Skip it and your analysts hate you.

Managed vs self-run EDR: the real trade-off

I will argue for managed here, but not absolutely. There are three cases where self-managed EDR is the right answer:

You already have a SOC. If you run a 24x7 operations team already, adding EDR telemetry to their workflow is incremental. Do not pay for what you can absorb.

You are highly regulated and cannot share telemetry with a third party. RBI-regulated NBFCs, certain defence-adjacent manufacturers, and companies handling government data often cannot send endpoint telemetry outside their premises. In these cases, on-premises EDR with internal SOC is the only compliant path.

You have a genuinely skilled security lead. Not the network admin who also handles printers. A security engineer who reads CVE feeds, understands Windows internals, and has run an incident end-to-end. If you have one of those, self-managed saves you 40–60% and gives you tighter control.

For everyone else — and that is 85% of the Indian SMBs we talk to — managed is the wrong word to resist. The vendor SOC sees thousands of alerts a week across hundreds of customers. The patterns they know cold, your analyst learns by reading blogs.

Comparison at 150 endpoints, one-year total cost (2026)

ItemSelf-managedManaged (business hours)Managed (24x7)
EDR licence (Sophos Intercept X Advanced)₹3,60,000₹3,60,000₹3,60,000
Engineering/tuning (partner professional services)₹45,000IncludedIncluded
SOC staffing (0.5–1.5 FTE)₹8,00,000–₹20,00,000
Managed monitoring fee₹5,40,000₹11,00,000
Incident response retainerOptional, ₹1,50,000OptionalIncluded in most contracts
Estimated annual cost₹12,05,000–₹24,05,000₹9,00,000₹14,60,000

Self-managed looks cheaper only before you count the salaries. Once you do, business-hours managed wins on cost and 24x7 wins on coverage. The self-managed column only makes sense if you already have the headcount.

Where EDR is not the answer

I am going to be blunt about three scenarios where throwing EDR at your problem is wasteful:

You have not fixed patching. If your Windows fleet is three months behind on updates, or your FortiGate firewall firmware has CVEs from 2024, EDR will not save you. Attackers will use the known hole, and your EDR will dutifully log the intrusion after the fact. Patch first. It costs almost nothing by comparison.

You have no backup that actually restores. Ransomware recovery without backup is not recovery — it is negotiation. Before you spend ₹10 lakh on EDR, spend ₹2.5 lakh on a serious backup that actually restores. Synology DS923+ with Active Backup for Business, a Veeam Backup & Replication v12 licence on a dedicated box, and offsite copies to an S3-compatible bucket in Mumbai. Test the restore. EDR is worth more when backup works.

You have 8 employees and no remote access. Defender for Business at ₹1,150 per endpoint per year plus good patching and MFA is enough for a small shop. EDR on a network that has no egress, no remote work, and no valuable data is theatre.

If any of those describe you, fix it before buying EDR. Any decent partner will tell you this. If yours does not, they are selling, not advising.

What to look for in an EDR partner in India

Four things, in order:

Local incident response capability. When something goes live at 11 PM, who answers? A US SOC with a ticketing system will take 40 minutes to acknowledge. A Bangalore-based partner with on-call engineering will be on a call in 10. For an Indian company running critical operations, minutes matter.

Understanding of Indian compliance context. DPDP Act 2023 obligations, CERT-In directives from April 2022 requiring 6-hour incident reporting for certain incident categories, and RBI cybersecurity framework requirements for financial entities. Your EDR logs are evidence. They need to be exportable in the format a regulator will accept.

Tuning discipline in the contract. Ask them explicitly how many tuning hours are included per quarter. The answer should be ten or more per 100 endpoints. If they say "tuning is included", ask when the last tuning pass happens and who signs it off.

Genuine references at your scale. Not an enterprise logo on their website. Talk to two clients in the 50–200 endpoint range. Ask them how many false positives they see per month, and how quickly their partner isolates a real threat. If the references cannot answer those questions specifically, the partner has never actually operated a deployment.

If you want to talk through what that looks like in practice, our team does this daily — the contact page is a good starting point, and you can also see what the deployment side of our practice looks like on the end-computing services page.

A worked 90-day deployment plan

Here is what a realistic EDR rollout looks like for a 150-endpoint Indian SMB. Not vendor-marketing-day-one-magic. Actual calendar.

Days 1–14: Foundation

  • Inventory every endpoint. If your asset list is a spreadsheet someone maintains manually, fix that first. You cannot protect what you cannot name.
  • Patch Windows to current build. Yes, all of them. This is non-negotiable.
  • Confirm MFA on email, VPN, and any cloud admin console.
  • Confirm your backup actually restores to a fresh machine. Test one full restore.

Days 15–30: Pilot

  • Deploy EDR to 15 endpoints — mix of IT, finance, and one departmental head.
  • Run in monitor-only mode. No blocking.
  • Collect two weeks of telemetry. Review with your partner against a tuning checklist.

Days 31–50: Tuning

  • Apply exclusions based on pilot telemetry.
  • Configure response playbooks: when a ransomware detection fires, who is paged, what is the isolation SLA.
  • Set up reporting. Weekly summary to IT, monthly to management.

Days 51–75: Broad rollout

  • Deploy in waves of 30–40 endpoints. Waves of 200 cause support tickets.
  • Run monitor-only for week one of each wave, then enforce.
  • Test response: trigger a benign detection, verify isolation works, verify notification reaches the on-call.

Days 76–90: Steady state and validation

  • Full enforcement across the fleet.
  • First false-positive tuning pass based on one month of live data.
  • Tabletop exercise: walk through a realistic phishing-to-ransomware scenario. Time it.
  • Handover to managed monitoring.

By day 90, you should be blocking, isolating, and logging with confidence. If you are not, your partner skipped the tuning phase.

Bang for the rupee: a worked ROI at 150 endpoints

Let me close the loops with actual maths, because Indian SMB buyers care about this more than any product feature.

Cost of managed 24x7 EDR at 150 endpoints, 2026: ₹14,60,000 per year.

Cost of one moderate incident (phishing → credential theft → attempted wire fraud or ransomware staging):

  • Emergency incident response consulting: ₹2,00,000–₹4,00,000
  • Lost productivity (2 days, 80 affected staff at ₹800/hour average): ₹10,00,000
  • Forensics and notification (if personal data leaked, DPDP implications): ₹1,50,000–₹8,00,000
  • Reputational and customer-trust costs: not quantifiable but real

One incident with material impact costs more than two years of managed EDR. The maths is not subtle. What Indian SMBs actually underestimate is the frequency, not the severity. We see phishing attempts on a 150-endpoint network at 200–500 per month, blocked at email gateway. Of those, 3–8 per year result in an endpoint compromise. Of those, one or two per year become material. The question is not if but when.

FAQ: endpoint detection and response for Indian companies

What is the difference between EDR and antivirus?

Antivirus matches files against known malware signatures. EDR watches what processes actually do — where they came from, what they spawn, what they connect to — and catches malicious behaviour even when no signature exists. In 2026, EDR catches modern attacks like fileless malware and living-off-the-land techniques that antivirus misses entirely. Both together is the correct configuration.

How much does EDR cost per endpoint in India in 2026?

Standalone EDR licences run ₹1,800–₹4,500 per endpoint per year depending on product and volume. Managed EDR with business-hours monitoring is ₹350–₹650 per endpoint per month; 24x7 managed is ₹650–₹1,200. A 150-endpoint deployment with 24x7 managed monitoring typically lands between ₹14 lakh and ₹18 lakh a year inclusive of GST.

Can a small Indian company with 30 employees afford EDR?

Yes, but buy it in the right shape. Microsoft Defender for Endpoint P1 at ₹1,150–₹1,600 per endpoint per year plus Defender for Business makes sense for a 30-person shop with no on-site SOC. For 30 endpoints, managed EDR starts around ₹1,30,000 a year. Cheaper than one ransomware incident. Do not buy enterprise EDR licences you cannot staff.

Does EDR work if my employees use personal devices?

Partially. You can deploy EDR on personally owned Windows and macOS laptops via Intune enrolment if the employee consents, but BYOD deployment is often resisted. Better to enforce EDR on company-owned endpoints and use conditional access to block unmanaged devices from company email and files. Zero-trust access controls cover the gap that EDR cannot.

Do Indian regulations require EDR specifically?

No Indian regulation names EDR as a mandatory product. But RBI's cybersecurity framework, SEBI's CSCRF, and CERT-In's April 2022 directions require incident detection, logging, and reporting. EDR is the most practical way to meet the detection and evidence-retention obligations. DPDP Act 2023 also implies reasonable security safeguards — EDR evidence strengthens your position if you ever face a breach notification obligation.

What happens if my EDR provider's SOC misses a real attack?

This is the honest risk with any managed service. Ask three things before signing: what is your mean time to acknowledge (MTTA) a critical alert, what is the SLA if you miss one, and what cyber liability insurance do you carry. A good partner will quote MTTA under 15 minutes, SLA credits, and ₹5 crore or more in professional indemnity. If they cannot, walk away.

What to actually do this quarter

Open your current security stack and answer three questions honestly. Do you know what process spawned the last alert on any endpoint in the last sixty days? Can you isolate an endpoint from a browser in under a minute? If a ransomware note appeared on a workstation this evening, what is your first action, second, and who do you call?

If any of those answers is "I don't know" or "the IT guy will figure it out", you are running antivirus and calling it security. The gap is not technology. It is the operational muscle around detection and response.

Start with a 15-endpoint pilot. Pick your most exposed users — finance, HR, the director's laptop. Run two weeks of monitoring with a partner who will actually walk through the telemetry with you. Then decide. That pilot costs ₹60,000–₹1,20,000 all-in for two weeks, and it will tell you more about your real risk posture than any vendor pitch ever will.

If you want to shortcut that pilot with a team that has done this across 1200+ Indian organisations since 2001, talk to SynergyScape and we will run the numbers for your size.