Home/Security

Prevention stops what it recognises. Detection finds what got through. Response needs a human.

Most buyers purchase one and assume they bought all three. Six routes below; each answers a different one of those sentences — and each is its own guide.

Microsoft 365 E3 includes prevention (Defender for Endpoint P1). Detection is P2, in E5. Nobody at Microsoft is watching either at 2am unless you buy Defender Experts. Three purchases, one logo.

Endpoint Protection

Something is on the device. Stop it, or find it before it spreads.

35 productsOpen the guide →
Often confused with Managed Detection & Response. The difference: a tool, versus someone to run it. Managed Detection & Response

Managed Detection & Response

You have detection. Nobody is watching it at 2am.

11 productsOpen the guide →
Often confused with Endpoint Protection. The difference: someone to run it, versus the tool they run. Endpoint Protection

Email Security

The attack arrives as a message, not a file.

21 productsOpen the guide →
Often confused with Endpoint Protection. The difference: the message before it lands, versus the file after it runs. Endpoint Protection

Vulnerability Management

Find what's exposed before anyone attacks it.

13 productsOpen the guide →
Often confused with Endpoint Protection. The difference: what could be attacked, versus what is being attacked. Endpoint Protection

SIEM & Log Management

Signals from everywhere, correlated in one place.

10 productsOpen the guide →
Often confused with Endpoint Protection. The difference: both claim correlation — vendor-neutral logs, versus one vendor's sensors. Endpoint Protection

Cloud & Workload Security

The workload isn't on a laptop. It's in someone else's data centre.

16 productsOpen the guide →
Often confused with Endpoint Protection. The difference: an agent on a laptop is not an agent on a container. Endpoint Protection
Second entry axis

Something just happened?

Events send people here more often than job descriptions. If one of these is your week, it already names your route.

Ransomware, or an active infection

Endpoint Protection

The SOC is one person and a phone

Managed Detection & Response

A supplier 'changed bank details' by email

Email Security

An audit asked for the patch cadence

Vulnerability Management

The regulator asked for 180 days of logs

SIEM & Log Management

A public bucket, or a cluster nobody owns

Cloud & Workload Security

The overlaps

Why people pick the wrong door

Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:

Endpoint ProtectionvsMDR

Are you buying a tool, or someone to run it?

Buy EPP/EDR when you needed MDR and the console fills with alerts nobody reads until month three, when it is quietly closed. Buy MDR when you needed a tool and you pay for analysts to watch telemetry you could have handled — and lose the agent when the contract ends.

SIEMvsEndpoint Protection / XDR

Vendor-neutral logs, or one vendor's sensors?

Buy XDR believing it is a SIEM and the regulator asks for the firewall and identity logs retained in India that it never ingested. Buy a SIEM believing it is XDR and you own an untuned archive with a per-gigabyte meter and nobody writing detections.

Vulnerability ManagementvsEndpoint Protection

What could be attacked, or what is being attacked?

Buy a scanner after a breach and you have a longer list of what was already exposed — the breach is not on it. Buy EDR to satisfy a vulnerability audit and the auditor asks for the patch cadence the EDR never measured.

Cloud & WorkloadvsEndpoint Protection

A laptop, or a container?

Buy your endpoint vendor's 'cloud security' and discover the agent cannot be installed in the image, the cluster or the serverless function. Buy agentless posture believing it protects and the cryptominer runs for a week in a perfectly configured account.

Compare any two terms

vs
EPPEndpoint Protection

Prevention at the endpoint — blocks what it recognises.

The Endpoint Protection boundary section →
XDREndpoint Protection

EDR's recording joined with one vendor's email, identity, cloud and network sensors.

The Endpoint Protection boundary section →

The difference

Two ends of the same ladder of scope: EPP blocks at the endpoint and needs nobody daily; XDR correlates across a vendor's sensors and needs a team (or an MDR). The tiers in between are EDR — and every price list sells the step from EPP to EDR as the expensive one.

The vocabulary — one line each

Nineteen terms, one line each. The depth lives in each route’s guide.

These are widening or adjacent scopes, not tiers of quality — broader records more, costs more and needs more people to run. Each route’s guide resolves only the three or four its buyer confuses.

  • EPPprevention at the endpoint — blocks what it recognises
  • EDRrecords the endpoint so a person can find and respond to what got through
  • XDREDR's recording joined with one vendor's email, identity, cloud and network sensors
  • MDRsomeone else's analysts running the EDR/XDR 24/7, within a contract
  • MSSPdevices managed and logs watched, escalated to you — breadth, not response
  • MXDRMDR over XDR telemetry — wider scope, more sources to onboard
  • Gatewaymail filtered in front of the tenant via MX — pre-delivery, DLP, continuity
  • APImail read behind the tenant via Graph / Google APIs — no MX change, sees internal and collaboration traffic
  • Scanningfind and rank known weaknesses, continuously
  • Exposure managementscanning plus cloud, identity, OT and attack paths in one risk view
  • Pentest (VAPT)humans proving an attacker can get in — often an empanelled report in India
  • BASattacker techniques run continuously to test what your defences catch
  • SIEMvendor-neutral log correlation, detections and cases — needs a tuner
  • Log managementcollect, keep, search — the first half
  • SOARautomation over whatever raises alerts — acts, does not detect
  • CSPMreads cloud accounts for misconfiguration — agentless, finds, does not block
  • CWPPruns on the workload — runtime detection and blocking
  • CIEMwho can do what to which cloud resource
  • CNAPPthe bundle: CSPM + CWPP + CIEM + code on one graph
Ground truths

What holds whichever route you take

Every route needs an operator

An EDR, a SIEM, a scanner, a CNAPP and a mail filter all produce work for a person every day. The licence is the smaller half of every purchase on this page; the headcount — yours, or the vendor’s through MDR — is the larger. Decide who operates before you decide what.

Scope is written in the contract, not the brochure

Endpoint-only MDR discovered during an email incident; XDR that meant “our stack”; posture sold as protection; a gateway that never saw Teams. Every route’s most common failure is a scope assumed. Read the named list of what is covered — sources, surfaces, authority — before the price.

India changes three answers

CERT-In’s 180-day log retention in India; RBI, SEBI CSCRF and IRDAI naming empanelled audits; DPDP landing around May 2027. Residency (SentinelOne and Sophos Mumbai, Seqrite, Qualys, FortiSIEM Cloud, Log360, Proofpoint Mumbai) and India-built vendors (Seqrite, Mitigata, ManageEngine, Scalefusion) are on every shortlist where they are documented — and flagged, never assumed, where they are not.

Every price has two meters

Per endpoint, per user, per mailbox, per asset, per workload, per gigabyte a day — and then the renewal. Promotional first years, reseller street prices, credits, per-GB growth and July 2026’s Microsoft 365 rise all move at renewal. Every guide prices USD and INR tier- and term-matched, and says which number is year two.

The licence is the small number. The operator, the scope and the renewal are the purchase.
TechBag
Where it's heading

The seams are moving

XDR is absorbing the SIEM for estates that run one vendor’s sensors. MDR is absorbing everything a vendor sells, because the people were always the product. And platform bundling (Microsoft E5, Palo Alto, Fortinet, Check Point) is competing with best-of-breed on one contract rather than one feature. Buying two of these today often means buying one thing twice — or buying the brand instead of the scope.

What you used to buyWhat you buy now
Endpoint protection
EPP / EDR / XDR
MDR
someone runs it
Email security
gateway / API
Vulnerability mgmt
find before attacked
SIEM & logs
correlate everywhere
Cloud & workload
CNAPP
One direction
XDR absorbing SIEM
one vendor's sensors, correlated, pre-tuned
CrowdStrikeSentinelOneMicrosoftTrend Micro
One direction
MDR absorbing everything
the people, sold with whatever they run
SophosBitdefenderMitigata
One direction
Platform bundling
one contract for endpoint, mail, cloud, SIEM
Microsoft E5Palo AltoFortinetCheck Point

Buy for the seam that is moving, not last year’s org chart — and buy the scope, not the brand.

Check what you already own

A large share of security buyers already hold a licence for part of the thing they are about to purchase — usually the prevention half.

  • Microsoft 365 E5 (or E5 Security) Defender for Endpoint P2 (full EDR), Defender for Office 365 P2, Identity and Cloud Apps. E3 has P1 only — prevention. Nobody watches either until you buy Defender Experts.
  • Your endpoint vendor sells the MDR, the email filter, the vulnerability view and the cloud module on the agent you run. Read the tier: it is rarely the deepest in each route, and it is often enough.
  • Your cloud provider Defender for Cloud, AWS Inspector / GuardDuty, Google Security Command Center — posture and more for their own cloud, on consumption, already half-bought.
  • Your mail platform Exchange Online Protection, Defender for Office 365 P1 (Business Premium; E3 from July 2026), Gmail's 99.9%. The floor is high; behavioural BEC is the gap.
  • Your RMM or UEM resells or embeds an endpoint engine (NinjaOne, Hexnode, Scalefusion, Acronis) — check which, and that it is not a second one.
  • Your firewall vendor Fortinet, Check Point, Cisco, Palo Alto bundle endpoint, mail, SIEM-lite and cloud into the platform contract. Fabric logging is not a SIEM until third-party logs are in.

If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.

Budget shape

What it costs, roughly

Six meters live in this category. Which one you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.

EPP · EDR
Per endpoint / device
$3–15 per endpoint per month, or $40–185 per device per year; $0 marginal when Defender is in your Microsoft 365 tier.
MDR
Per endpoint per month, plus the people
$7–45 per endpoint per month reported, on top of the agent; Mitigata quotes INR per estate with audits and insurance in the same conversation.
Email
Per mailbox
$2–15 per user per month; API behavioural layers $15–40 per user per year with contract minimums; Defender for Office 365 P1/P2 $2/$5.
Vulnerability
Per asset · per scanner · per application
$28–250 per asset per year; Nessus $4,790 per scanner; Action1 free to 200; Mitigata VAPT from ₹52,000 per application.
SIEM
Per GB a day · per source · per EPS
Splunk ~$1,000 per GB/day per year at 50 GB; CrowdStrike $5.95/GB PAYG; Log360 $300–1,995 a year per source tiers. The meter decides the bill.
Cloud
Per workload · per resource · credits
Wiz reported $6–30 per workload per year with ~$24k floors; FortiCNAPP from ~$25k; most of the field quote or credit priced; the native cloud tools on consumption.
Appendix — every vendor in the category, tagged by route
  • CrowdStrikeFalcon — EPP/EDR reference, Complete MDR, Exposure, Next-Gen SIEM, Cloud SecurityEPPMDRVMSIEMCloud
  • SentinelOneSingularity — endpoint with rollback, Vigilance MDR, AI SIEM, Cloud Security; Mumbai regionEPPMDRSIEMCloud
  • MicrosoftDefender for Endpoint P1/P2, Defender for Office 365 — already in E3 / E5 / Business PremiumEPPEmail
  • SophosIntercept X, XDR, MDR (largest pure-play), Email, Managed Risk, Cloud Native; Mumbai regionEPPMDREmailVMCloud
  • BitdefenderGravityZone — Business Security, EDR/XDR, PHASR, MDR, Email (2026), Cloud SecurityEPPMDREmailCloud
  • ESETPROTECT Entry → Elite, ESET MDR; on-prem or cloud consoleEPPMDR
  • Trend MicroVision One — Endpoint, XDR, Service One MDR, Email, CREM / ASRM, Cloud Security (credits)EPPMDREmailVMCloud
  • KasperskyNext, Endpoint Security Cloud, MDR, mail, SIEM (KUMA), Hybrid Cloud, Container — procurement caveatsEPPMDREmailSIEMCloud
  • SeqriteIndia-built: Endpoint Protection (on-prem / cloud), EDR, XDR; INR list, CERT-In empanelledEPP
  • XcitiumZeroDwell containment, EDR / XDR, OpenEDR (free ≤50), MDR incl. Managed EDR for DefenderEPPMDR
  • Check PointHarmony Endpoint, Harmony Email & Collaboration (API), CloudGuard CNAPPEPPEmailCloud
  • CiscoSecure Endpoint, Cisco XDREPP
  • FortinetFortiEDR, FortiMail, FortiSIEM (Mumbai cloud), FortiAnalyzer, FortiCNAPP (Lacework)EPPEmailSIEMCloud
  • AcronisCyber Protect — backup + EDR in one agent; Mumbai DCEPP
  • CoroSMB modular platform — Endpoint/EDR, Email, Managed SOCEPPMDREmail
  • NortonSmall Business — up to 20 devicesEPP
  • Hexnode · Scalefusion · NinjaOneUEM / RMM-adjacent endpoint security — Hexnode XDR, Scalefusion Veltar, NinjaOne Endpoint SecurityEPP
  • MitigataIndia: 24×7 SOC on your tools, CERT-In VAPT, compliance, IRDAI-regulated cyber insuranceMDRVM
  • BarracudaManaged XDR (via MSPs), Email ProtectionMDREmail
  • Abnormal AIAPI-based behavioural email security (BEC, account takeover)Email
  • ProofpointEmail Protection (gateway + API), Email Fraud Defense, Security Awareness; Mumbai DCEmail
  • MimecastEmail Security (gateway / API), Collaboration Security, Aware, DMARC AnalyzerEmail
  • CloudflareEmail Security (Area 1) inside Zero TrustEmail
  • ForcepointEmail Security — on-prem / hybrid gateway with DLPEmail
  • QualysVMDR with patching, TruRisk, WAS, Patch Management, TotalCloud; India platformVMCloud
  • TenableVulnerability Management, Nessus, Tenable One, OT Security, Cloud Security (100% agentless)VMCloud
  • Action1Vulnerability remediation — finds and patches endpoints; free to 200VM
  • SplunkEnterprise Security, Platform, SOAR — the reference SIEMSIEM
  • ManageEngineLog360 — India-built SIEM priced per source; on-prem or cloudSIEM
  • WizAgentless CNAPP reference — CSPM, CIEM, Code, Defend, DSPM (Google, 2026)Cloud

Palo Alto Networks (Cortex, Prisma) is carried by TechBag’s sales team but has no intel pages yet, so it is named in the guides and not ranked. Trellix’s TechBag pages are its data-security line, not endpoint.

Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.

Talk to an advisor

Vendor-neutral · no gated content