All professional firms
Antivirus is not enough: what EDR adds
· PS ProTech · 3 min read
Most firms have antivirus and assume the computers are covered. Antivirus is still worth having. It just no longer covers the attacks that do the most damage.
What antivirus does
Antivirus keeps a list of known malicious files and checks everything on your computer against it. When a file matches, it's blocked.
That works well against threats someone has already seen and catalogued. It's fast, quiet and cheap, and it stops a large amount of ordinary malware.
Its weakness is in the word "known." If a file isn't on the list, antivirus has no opinion about it.
How attackers get past it
They change the file. Malware can be altered slightly each time it's sent, so no two copies match. AI makes producing these variations trivial.
They don't use a malicious file at all. Many attacks now run through tools already on your computer, the same ones your IT provider uses to manage it. Nothing is installed, so there's nothing to match.
They sign in. With a stolen password, an attacker is a legitimate user as far as antivirus is concerned. Reading a mailbox or copying a client folder isn't malware.
What EDR does
EDR stands for endpoint detection and response. An endpoint is any device on your network: a laptop, a desktop, a server.
Where antivirus asks "is this file on the bad list?", EDR asks "is this behavior normal?" It watches what programs do and looks for the patterns an attack produces:
- A document that opens and immediately starts running commands.
- A program reading thousands of files in a minute and rewriting each one, which is what ransomware does.
- A sign-in tool being used to copy every saved password.
- A computer suddenly connecting to dozens of others on the network.
None of those involve a file anyone has seen before. All of them are visible to something watching behavior.
The "response" part
Detection is half of it. When EDR sees an attack in progress, it can act:
- Stop the program before it finishes.
- Cut the computer off from the network, so the attack can't spread, while keeping it reachable for investigation.
- Keep a record of everything that happened: what ran, what it touched, where it came from.
That record matters afterward. If you need to tell a client or an insurer what was accessed, "we don't know" is the most expensive answer. We cover that moment in the first hour of a ransomware attack.
Do you need both?
Yes, and they usually come together. Antivirus clears out the ordinary threats cheaply. EDR handles what gets past it. Running EDR without antivirus means your more capable tool spends its time on the easy cases.
Who watches the alerts?
EDR produces alerts, and an alert nobody reads protects nothing. A small firm has three options:
- Let it act automatically on clear-cut cases, which stops most attacks without a person involved.
- Have your IT provider review alerts during working hours.
- Add a monitoring service that investigates around the clock. That's what SIEM and MDR provides.
For most small firms, the first two are the baseline and the third is for those with more at stake.
What to check at your firm
- Is it on every computer? Including partners' laptops and any home computer used for work. One unprotected machine is the way in.
- Is it switched on and reporting? Protection that was installed two years ago and has since stopped updating is common.
- Can you prove it? Cyber insurers ask specifically for EDR, as we explain in what cyber insurers ask.
Antivirus, EDR and ransomware detection are on every computer in every plan we offer. See endpoint security for what's included, or check this and fourteen other basics with our security checklist.
