• Office Hours: 9:00 AM – 6:00 PM
Partner in the ThreatDown Partner Program

ThreatDown EDR and MDR in Dubai

Endpoint detection and response for businesses that do not have a security team — with the option of ThreatDown's 24/7 analysts watching the alerts, and Nifty as the people you actually call. Deployed, tuned and supported locally, quoted in AED, and scoped honestly including what it does not cover.

ThreatDown EDR ThreatDown MDR Ransomware Rollback Managed Threat Hunting Patch Management DNS Filtering Nebula Console Migration from Legacy AV
24/7 SOCThreatDown analysts, on Elite and above
LocalDeployment and response from Dubai
ScopedWe tell you what it does not cover
From 5Endpoints upward — SMEs included
EDR & MDR UAE

EDR, MDR and Antivirus — What the Difference Actually Is


Quick Answer

Antivirus blocks known bad files. EDR records what happens on the endpoint, detects suspicious behaviour and gives someone the tools to investigate and contain it. MDR is EDR plus the someone. That last distinction is the one that matters commercially: EDR is a product you have to operate, and MDR is a service where a security operations centre operates it for you around the clock.

Most UAE SMEs who buy EDR and nothing else end up with a console nobody opens. If you have an IT team with capacity to investigate alerts, EDR alone is the right and cheaper answer. If you do not — and most businesses under a hundred users genuinely do not — then either buy the managed tier or accept that the detection capability is sitting unused. We will tell you which of those applies to you before quoting.

ThreatDown Services at a Glance

Service
ThreatDown EDR and MDR deployment, tuning, migration and ongoing support
Provider
NIFTY INFORMATION TECHNOLOGY LLC, Dubai — operating since 2014
Vendor programme
Partner in the ThreatDown Partner Program (ThreatDown is Malwarebytes' business brand)
Bundles
Core, Advanced, Elite and Ultimate — EDR in all of them, MDR from Elite upward
Console
Nebula, cloud-hosted — we configure it and you keep administrative access
Who watches alerts
ThreatDown's 24/7 SOC analysts on MDR tiers; Nifty handles deployment, tuning and local response
Coverage scope
Endpoints — workstations, laptops and servers. Not Microsoft 365, cloud or network telemetry
Minimum size
From around five endpoints, so small UAE businesses are in scope
Platforms
Windows, macOS, Windows Server and Linux endpoints
Commonly replaces
Consumer antivirus, expired endpoint licences and unmanaged Defender deployments
Free before you commit
Endpoint security review — what you are running, what is unpatched, what is unprotected
Bundles

Core, Advanced, Elite or Ultimate


The jump that costs money is Advanced to Elite, because that is where you stop buying software and start buying people. Everything below that line is a product decision; everything above it is a staffing decision.

Included Core Advanced Elite Ultimate
Next-gen antivirus & threat preventionYesYesYesYes
Endpoint Detection & Response (EDR)YesYesYesYes
Vulnerability & Patch ManagementYesYesYesYes
Security Advisor health scoringYesYesYesYes
Ransomware RollbackYesYesYes
Managed Threat HuntingYesYesYes
24/7 MDR — monitoring and response by ThreatDown analystsYesYes
DNS FilteringYes
Who operates it day to dayYou, or Nifty under contractYou, or Nifty under contractThreatDown SOC + NiftyThreatDown SOC + Nifty
Typical fitSmall teams with basic needsAn IT team that will actually use the consoleNo security staff, or 24/7 exposureAs Elite, plus web-layer control
Get a quoteGet QuoteGet QuoteGet QuoteGet Quote

Bundle names and contents are set by ThreatDown and are revised periodically. The summary above reflects the published bundle definitions as at August 2026 — we confirm exactly what is included in your quotation before you order.

Two features worth understanding properly. Ransomware Rollback keeps a rolling record of file changes so encrypted files can be reverted on affected endpoints — genuinely useful, and genuinely not a backup. It works on endpoints within a limited time window; it does not protect a file server nobody installed the agent on, and it is not a substitute for the restore-tested backup that gets you out of a real incident. Vulnerability and Patch Management is included in every bundle and is, for most UAE SMEs, the single most valuable thing in the box — unpatched third-party software is how most endpoints actually get compromised, and it is the control most often missing entirely.

Delivery Model

Who Actually Does What — Stated Plainly


A lot of MDR marketing in this region is deliberately vague about whose analysts are watching. Here is the honest structure, because you should know who is on the other end before there is an incident.

ThreatDown's security operations centre

On Elite and Ultimate, ThreatDown's own analysts monitor your endpoint telemetry 24/7/365. They triage detections, hunt for threats across the estate, and take containment action — isolating an endpoint from the network, killing a malicious process, quarantining a file — either automatically under agreed playbooks or after escalating for your approval, depending on how the service is configured.

It is a pooled SOC rather than named analysts assigned to your account, and ThreatDown does not publish a formal committed response time. We would rather tell you that than let you assume an SLA that does not exist.

24/7/365 monitoringThreat huntingEndpoint isolation Process killPooled SOC

What Nifty does

We deploy the agents and migrate you off whatever you are running now, configure the Nebula console and the policies, tune out the false positives that would otherwise train your team to ignore alerts, and set the exclusions your line-of-business applications need. We handle patch policy, review the Security Advisor findings with you, and act on the local side of an incident — the rebuild, the restore, the user conversation, the follow-up.

And we are the number you call. A SOC that has isolated a laptop in Al Quoz at 3am is doing exactly the right thing; somebody still has to get that user working again in the morning.

DeploymentMigrationPolicy tuning Patch policyLocal responseEscalation contact

One boundary worth stating: MDR covers detection, containment and response on the endpoint. Full incident response — forensic investigation, breach assessment, regulatory notification support — is a separate engagement, not something included in a monthly endpoint subscription, with any vendor. If you have a compliance obligation that requires formal incident response capability, tell us at review stage so it is scoped properly rather than assumed.

Not sure what is actually protecting your endpoints right now? The free review lists every device, what security software is on it, what is unpatched and what is unprotected — in writing, at no charge.

Book a Free Endpoint Security Review
Scope

What Endpoint MDR Covers — and What It Does Not


This is the section most vendors leave out, and the one that prevents an expensive misunderstanding six months in. Endpoint MDR watches endpoints. It is not whole-business monitoring.

Attack surface Covered by ThreatDown EDR/MDR? What actually covers it
Workstations, laptops, servers Yes — this is the product The ThreatDown agent, with the console and, on MDR tiers, the SOC
Ransomware landing on an endpoint Yes Detection, containment, and rollback on Advanced and above — alongside a tested backup, not instead of one
Unpatched third-party software Yes Vulnerability and Patch Management, included in every bundle
Microsoft 365 mailbox compromise No Conditional access, MFA and tenant-level alerting — see Microsoft 365 security
Phishing email arriving in the first place Partly Email filtering at the gateway; the endpoint agent only sees it once something is opened or downloaded
Network intrusion, exposed services, VPN abuse No The firewall — see Fortinet solutions
Cloud and SaaS activity outside the endpoint No Platform-native logging and alerting, scoped per service
Identity attacks and credential theft Partly Identity protection is a developing area across the industry; confirm exactly what your subscription includes rather than assuming
Devices with no agent installed No Nothing. This is why deployment coverage is checked and reported, not assumed

Endpoint-only scope is normal for endpoint MDR and is not a criticism of ThreatDown — it is what the category is. The mistake to avoid is buying it believing your Microsoft 365 tenant, your firewall and your cloud services are now being watched by somebody. They are not, unless you have separately arranged that.

Straight Answer

When MDR Is the Right Buy — and When It Is Not


We say the same thing on our cybersecurity page and we will say it here, on a page that exists to sell this service: managed detection is a genuine control, but it presumes the fundamentals are already in place.

Buy MDR when

  • Nobody would see an alert at 2am. If your IT cover is one person during business hours, out-of-hours detection is the gap, and this is the cheapest credible way to close it.
  • You have a regulatory or contractual driver. A client security questionnaire, an insurer's requirement or a sector obligation changes the calculation entirely.
  • You have been hit before, or a business in your supply chain has. The risk stops being theoretical and the cost of the second incident is known.
  • Your team has EDR and never opens it. Paying for detection nobody acts on is worse value than paying for the managed tier.
  • Downtime is expensive — production, logistics, retail, anything where a day offline has a number attached.

Fix these first instead

  • MFA on every account that touches company data. Still the single highest-value control available, and still missing in a surprising number of UAE businesses.
  • A backup somebody has actually restored. Untested backup is a theory. Ransomware rollback on endpoints does not replace it.
  • Patching. Included in every ThreatDown bundle, which is a fair reason to start at Core rather than skip straight to Elite.
  • A firewall on supported firmware with reviewed rules, rather than one that has accumulated exceptions for six years.
  • Knowing which devices exist. MDR cannot protect a laptop nobody recorded and nobody enrolled.

Our actual position: for a typical UAE business under about a hundred users with no regulatory driver, the honest sequence is fundamentals first, EDR with patch management second, and MDR when either the fundamentals are done or a specific driver appears. Buying 24/7 monitoring for an environment with no MFA and untested backups is spending at the wrong end of the list, and we would rather sell you the right thing later than the wrong thing now. The free review tells you which stage you are at.

Delivery

What the Deployment Actually Covers


Endpoint security fails in deployment far more often than in detection. These are the parts that decide whether it works.

🔍

Endpoint discovery

Before anything is installed we establish what devices actually exist — including the laptop in someone's bag and the old server in the corner. Coverage gaps are the most common reason an endpoint product fails to prevent an incident.

🔄

Migration off your current AV

Clean removal of the incumbent product before or during rollout, because two endpoint agents fighting each other cause performance problems that get blamed on the new one. Staged by department rather than all at once.

Policy and exclusion tuning

Policies set for your environment and exclusions configured for the line-of-business applications that would otherwise be flagged — ERP, accounting, CAD, POS. Untuned detection trains staff to ignore alerts, which is worse than no alerts.

🔧

Patch policy configuration

Vulnerability and patch management switched on properly — operating system and third-party applications on a tested schedule, with critical patches expedited. Included in every bundle and frequently left unconfigured.

📊

Console setup and reporting

Nebula configured with sensible roles and notifications, and reporting you can hand to management or an insurer. You keep administrative access to your own tenant — it is yours, not ours.

🛡

Escalation and response

An agreed path for what happens when something is detected — who ThreatDown contacts, what they are authorised to do automatically, who at your end approves an isolation, and who does the local rebuild afterwards.

How It Works

From Review to Covered Estate


1

Free endpoint security review

What devices you have, what security software is on each, what is unpatched, what has no protection at all, and whether the fundamentals — MFA, backup, firewall — are in place. Written report ranked by risk, no charge, and useful even if you buy nothing.

2

Bundle recommendation and quotation

Which tier your situation actually justifies, priced per endpoint per month in AED, with the reasoning stated. If the answer is Core plus fixing your backup rather than Elite, that is what the proposal will say — and it will be a smaller number than you expected.

3

Pilot deployment

A small group of representative devices first — including whoever runs the heaviest line-of-business application — so exclusions and performance are proven before the whole company is touched. This step is why rollouts do not generate a flood of complaints.

4

Full rollout and migration

Staged by department, with the previous product cleanly removed, coverage verified device by device against the inventory, and the gaps chased rather than quietly accepted. You get a coverage report at the end showing what is protected and what is not.

5

Tuning, escalation setup and handover

False positives tuned out, patch policy live, MDR escalation path agreed and tested with your team, console roles configured, and documentation handed over. On managed tiers the SOC is watching from this point; on EDR tiers, either your team or ours is.

6

Review and renewal

Periodic review of detections, patch compliance and coverage, and a renewal conversation started ahead of expiry rather than on the day — the same way we handle Fortinet renewals. Ongoing management can fold into a managed IT contract or stay standalone.

Coverage

Endpoint Security Across the Emirates


Dubai

Deployment and on-site response across Business Bay, DIFC, Al Quoz, Jebel Ali, Dubai Silicon Oasis, DMCC, Deira and Bur Dubai — including the rebuild-and-restore work after an incident, which is the part that needs somebody local.

Abu Dhabi

Rollouts and scheduled support for offices and industrial sites in Mussafah, KIZAD, Al Reem, Yas Island and the city centre, with identical console configuration and escalation handling to Dubai clients.

Sharjah & Northern Emirates

Sharjah industrial and free-zone businesses, plus Ajman, Ras Al Khaimah, Umm Al Quwain and Fujairah — remote deployment throughout, with scheduled visits where devices need hands.

Agent deployment and console management are delivered remotely UAE-wide. The 24/7 monitoring on MDR tiers is delivered by ThreatDown's security operations centre, which is not UAE-based — if data residency or in-country monitoring is a requirement for your sector, raise it at review stage so it can be scoped properly.

FAQs

ThreatDown EDR and MDR — Common Questions


What is the difference between EDR and MDR?

EDR is a product: it records what happens on each endpoint, detects suspicious behaviour rather than only known-bad files, and gives someone the tools to investigate and contain an incident. MDR is that same technology plus the people who operate it — a security operations centre monitoring the alerts around the clock, triaging them and taking containment action. The practical test is simple: if nobody in your business will open a security console at 2am on a Friday, EDR alone gives you a recording of the incident rather than a response to it. Businesses with an IT team that has genuine capacity to investigate alerts are correctly served by EDR; most UAE SMEs under a hundred users are not.

Is ThreatDown the same as Malwarebytes?

ThreatDown is Malwarebytes' business brand — the same company, with the corporate endpoint products grouped under the ThreatDown name and the consumer antivirus product continuing as Malwarebytes. If you already know Malwarebytes as the tool that cleans up an infected home laptop, the business platform is a different proposition: centrally managed agents, an EDR detection engine, vulnerability and patch management, a cloud console called Nebula, and optional 24/7 managed detection and response. Nifty IT is a partner in the ThreatDown Partner Program and deploys and supports the business platform.

Do we actually need MDR, or is EDR enough?

It depends on whether anyone would act on a detection outside working hours. Buy the managed tier when your IT cover is one person during business hours, when a client questionnaire, insurer or regulator requires it, when you have been hit before, or when downtime has a real number attached. Stay on EDR when you have a team that will genuinely use the console. And if your fundamentals are not in place — MFA missing, backups never restored, firewall unpatched — fix those first, because 24/7 monitoring of a weak environment is spending at the wrong end of the list. We will tell you which of those three situations you are in before quoting.

Does ThreatDown MDR monitor our Microsoft 365 and cloud services?

No. ThreatDown EDR and MDR are endpoint-focused: they cover workstations, laptops and servers running the agent. Mailbox compromise in Microsoft 365, suspicious sign-ins, cloud and SaaS activity, and network-level intrusion are outside that scope and are covered by different controls — tenant-level alerting and conditional access on the Microsoft 365 side, and the firewall at the network layer. This is normal for endpoint MDR across the industry, but it is worth stating clearly, because assuming your whole business is being watched when only the endpoints are is an expensive misunderstanding.

How much does ThreatDown cost in Dubai?

It is priced per endpoint per month, and the drivers are which bundle you take, how many endpoints are in scope and the term length. The jump that matters is Advanced to Elite, because that is where you stop buying software and start buying analyst time — expect a meaningful step, and expect it to still be far cheaper than staffing 24/7 cover yourself. Multi-year terms normally reduce the annual figure. We quote in AED per endpoint with the bundle contents itemised, so you can see what the managed tier adds rather than comparing two totals with different things inside them.

Is there a minimum number of endpoints?

The platform starts from around five endpoints, which puts it within reach of genuinely small UAE businesses — a five to ten person office is a normal customer rather than too small to be served. That matters, because a lot of enterprise EDR and MDR products carry minimums that price small businesses out entirely and leave them on consumer antivirus. That said, small does not mean you should skip the fundamentals: at that size, MFA, a tested backup and patching still come before managed detection.

Does Ransomware Rollback mean we no longer need backups?

No, and this is the most important misunderstanding to clear up. Ransomware Rollback keeps a rolling record of file changes so that encrypted files on a protected endpoint can be reverted — it is genuinely useful and it has saved real incidents. But it works on endpoints running the agent, within a limited time window, and it does nothing for a file server nobody enrolled, a NAS, a cloud service or an incident discovered weeks later. It is a fast recovery option layered on top of backup, never a replacement for a restore-tested backup. Any provider who tells you otherwise is selling, not advising.

Will it conflict with our existing antivirus or Microsoft Defender?

Two active endpoint protection agents scanning the same files cause performance problems and false positives, and the blame invariably lands on whichever was installed most recently. So migration is part of the deployment: the incumbent product is cleanly removed as the new agent goes on, staged department by department rather than in one pass, with a pilot group first to prove exclusions and performance on your heaviest line-of-business applications. Defender is handled the same way — it steps back automatically when another registered protection product takes over, but we verify that rather than assume it.

Who responds when something is detected at 2am?

On Elite and Ultimate, ThreatDown's 24/7 security operations centre does the immediate work — triage, threat hunting and containment such as isolating the endpoint from the network, killing a process or quarantining a file, either automatically under agreed playbooks or after escalating for approval. Nifty is the local side: we agree the escalation path with you in advance, and we handle the morning after — the rebuild, the restore, the user who cannot work, the follow-up on how it got in. Both halves matter. A SOC that isolates a laptop at 3am has done the right thing, and somebody still has to get that person working again.

Does ThreatDown publish a guaranteed response time?

Not a formal committed detection or response SLA, and the SOC is pooled rather than assigning named analysts to your account. We would rather state that plainly than let you infer a guarantee that does not exist — it is a fair question to ask of every MDR provider you consider, and the answers vary more than the marketing suggests. What you can pin down is the escalation path: who gets contacted, what the analysts are authorised to do without waiting for approval, and what our own response commitment to you is under a support or managed contract. That last part is contractual and we will put it in writing.

Can you migrate us from our current antivirus product?

Yes, and it is how most of these deployments start — usually from expired endpoint licences, consumer-grade antivirus installed one machine at a time, or an unmanaged Defender deployment nobody is monitoring. The work is discovery first, so we know what devices actually exist including the ones not in anyone's inventory, then a pilot group, then staged removal and replacement by department, then verification device by device against that inventory. You get a coverage report at the end showing exactly what is protected and what is not — the gaps are the point of the exercise.

Does it include patch management, and can you run that for us?

Vulnerability and patch management is included in every ThreatDown bundle, including the entry tier, and for most UAE SMEs it is the most valuable thing in the box — unpatched third-party software is how endpoints actually get compromised, and it is the control most often missing altogether. It is also frequently bought and never configured. We set the patch policy up as part of deployment, with operating system and third-party applications on a tested schedule and critical patches expedited, and we can run it on an ongoing basis either standalone or inside a managed IT contract.

Find out what is actually protecting your endpoints

The free review lists every device, what security software is on each one, what is unpatched, what has no protection at all, and whether your fundamentals are in place. Written report ranked by risk — yours to keep whether or not you buy anything.

NIFTY INFORMATION TECHNOLOGY LLC · Burj Nahar Mall, M2 Floor, Office D2-4, Deira, Dubai · 04 355 1136 · [email protected]

Chat with us on WhatsApp