Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
Most buyers purchase one and assume they bought all three. Six routes below; each answers a different one of those sentences — and each is its own guide.
Microsoft 365 E3 includes prevention (Defender for Endpoint P1). Detection is P2, in E5. Nobody at Microsoft is watching either at 2am unless you buy Defender Experts. Three purchases, one logo.
Something is on the device. Stop it, or find it before it spreads.
You have detection. Nobody is watching it at 2am.
The attack arrives as a message, not a file.
Find what's exposed before anyone attacks it.
Signals from everywhere, correlated in one place.
The workload isn't on a laptop. It's in someone else's data centre.
Events send people here more often than job descriptions. If one of these is your week, it already names your route.
Ransomware, or an active infection
Endpoint Protection
The SOC is one person and a phone
Managed Detection & Response
A supplier 'changed bank details' by email
Email Security
An audit asked for the patch cadence
Vulnerability Management
The regulator asked for 180 days of logs
SIEM & Log Management
A public bucket, or a cluster nobody owns
Cloud & Workload Security
Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:
Are you buying a tool, or someone to run it?
Buy EPP/EDR when you needed MDR and the console fills with alerts nobody reads until month three, when it is quietly closed. Buy MDR when you needed a tool and you pay for analysts to watch telemetry you could have handled — and lose the agent when the contract ends.
Vendor-neutral logs, or one vendor's sensors?
Buy XDR believing it is a SIEM and the regulator asks for the firewall and identity logs retained in India that it never ingested. Buy a SIEM believing it is XDR and you own an untuned archive with a per-gigabyte meter and nobody writing detections.
What could be attacked, or what is being attacked?
Buy a scanner after a breach and you have a longer list of what was already exposed — the breach is not on it. Buy EDR to satisfy a vulnerability audit and the auditor asks for the patch cadence the EDR never measured.
A laptop, or a container?
Buy your endpoint vendor's 'cloud security' and discover the agent cannot be installed in the image, the cluster or the serverless function. Buy agentless posture believing it protects and the cryptominer runs for a week in a perfectly configured account.
Compare any two terms
Prevention at the endpoint — blocks what it recognises.
The Endpoint Protection boundary section →EDR's recording joined with one vendor's email, identity, cloud and network sensors.
The Endpoint Protection boundary section →The difference
Two ends of the same ladder of scope: EPP blocks at the endpoint and needs nobody daily; XDR correlates across a vendor's sensors and needs a team (or an MDR). The tiers in between are EDR — and every price list sells the step from EPP to EDR as the expensive one.
These are widening or adjacent scopes, not tiers of quality — broader records more, costs more and needs more people to run. Each route’s guide resolves only the three or four its buyer confuses.
An EDR, a SIEM, a scanner, a CNAPP and a mail filter all produce work for a person every day. The licence is the smaller half of every purchase on this page; the headcount — yours, or the vendor’s through MDR — is the larger. Decide who operates before you decide what.
Endpoint-only MDR discovered during an email incident; XDR that meant “our stack”; posture sold as protection; a gateway that never saw Teams. Every route’s most common failure is a scope assumed. Read the named list of what is covered — sources, surfaces, authority — before the price.
CERT-In’s 180-day log retention in India; RBI, SEBI CSCRF and IRDAI naming empanelled audits; DPDP landing around May 2027. Residency (SentinelOne and Sophos Mumbai, Seqrite, Qualys, FortiSIEM Cloud, Log360, Proofpoint Mumbai) and India-built vendors (Seqrite, Mitigata, ManageEngine, Scalefusion) are on every shortlist where they are documented — and flagged, never assumed, where they are not.
Per endpoint, per user, per mailbox, per asset, per workload, per gigabyte a day — and then the renewal. Promotional first years, reseller street prices, credits, per-GB growth and July 2026’s Microsoft 365 rise all move at renewal. Every guide prices USD and INR tier- and term-matched, and says which number is year two.
The licence is the small number. The operator, the scope and the renewal are the purchase.
XDR is absorbing the SIEM for estates that run one vendor’s sensors. MDR is absorbing everything a vendor sells, because the people were always the product. And platform bundling (Microsoft E5, Palo Alto, Fortinet, Check Point) is competing with best-of-breed on one contract rather than one feature. Buying two of these today often means buying one thing twice — or buying the brand instead of the scope.
Buy for the seam that is moving, not last year’s org chart — and buy the scope, not the brand.
A large share of security buyers already hold a licence for part of the thing they are about to purchase — usually the prevention half.
If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.
Six meters live in this category. Which one you are quoted tells you which route you are in — order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.
Palo Alto Networks (Cortex, Prisma) is carried by TechBag’s sales team but has no intel pages yet, so it is named in the guides and not ranked. Trellix’s TechBag pages are its data-security line, not endpoint.
Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.
Talk to an advisorVendor-neutral · no gated content