By J. Mesa
Your cyber insurance renewal form asks whether you run EDR on all endpoints. You run antivirus. Are those the same thing? They are not, and the gap between them explains why businesses with up-to-date antivirus still get hit by ransomware.
What is antivirus?
Antivirus is software that scans files and programs for known malicious code and blocks or removes what it finds. Traditional antivirus works from signatures. A signature is a fingerprint of a known piece of malware. The vendor updates the list, and the software compares each file against it.
Modern products, often sold as next-generation antivirus, add machine learning and behavior checks that catch some malware nobody has seen before.
What is EDR?
EDR stands for endpoint detection and response. An endpoint is any device that connects to your network: a laptop, a desktop, a server. EDR software records what happens on each endpoint, looks for suspicious behavior, alerts you, and gives you tools to investigate and contain an attack.
Think of antivirus as a lock that keeps known burglars out. EDR is a camera system with a guard: it watches what happens inside, notices someone acting wrong, and lets you lock the room they are in.
What is the difference between antivirus and EDR?
- What it looks for. Antivirus looks for bad files. EDR looks for bad behavior.
- When it acts. Antivirus acts at the moment a file arrives or runs. EDR keeps watching after that moment.
- What it records. Antivirus logs a detection. EDR records processes, network connections, logins, and changes, so you can trace how an attack unfolded.
- How you respond. Antivirus quarantines a file. EDR lets you isolate a computer from the network, stop a process, and in some products roll back changes.
- Who it needs. Antivirus runs with little attention. EDR produces alerts that a trained person must review.
Why is antivirus no longer enough?
Attackers changed their methods.
- Stolen logins. Many break-ins use a real username and password. No malicious file exists for antivirus to catch.
- Living off the land. Attackers use tools already built into Windows, such as PowerShell and remote administration utilities. To antivirus, those look like normal programs.
- Fileless attacks. Malicious code runs in memory and never touches the disk.
- Custom malware. Criminals alter their code for each victim, so no signature matches.
- Hands-on attacks. In a modern ransomware case, a person works inside the network for days: stealing data, finding backups, and disabling security tools before the encryption starts. Each step is a chance to catch them, and antivirus sees few of those steps.
EDR is built to notice that chain. A word processor that launches a command prompt, which downloads a tool, which starts copying password data, tells a story no single file reveals.
What is MDR?
MDR stands for managed detection and response. It is EDR software plus a team of security analysts who watch the alerts for you around the clock, investigate, and act.
For a small business this matters more than the software. EDR raises an alert at 2 a.m. on a Saturday. Someone has to see it, decide whether it is real, and isolate the machine before the attack spreads. Few small businesses have that person. An MDR provider does.
What is XDR?
XDR, or extended detection and response, widens the view beyond endpoints to include email, identity systems, cloud services, and the network. It connects events across those sources. An XDR tool might link a suspicious sign-in to your email with odd activity on a laptop an hour later. Many EDR vendors now sell XDR as the next tier up.
Does my small business need EDR?
In most cases, yes. Choose EDR or MDR if any of these apply:
- You hold sensitive data: patient records, financial records, card data, or client files
- A regulation such as HIPAA, PCI DSS, or the FTC Safeguards Rule covers you
- You are applying for or renewing cyber insurance
- You run servers or have staff working remotely
- Downtime of a few days would threaten the business
A very small office with a few computers, everything in the cloud, and no regulated data can start with the protection built into Windows, turned on and kept current, alongside multi-factor authentication and backups. Revisit that choice each year.
Do cyber insurers require EDR?
Many now do. Applications ask whether EDR runs on all workstations and servers, and some carriers decline or surcharge businesses without it. Answer accurately. If the form says EDR covers every endpoint and a claim investigation finds half your machines unprotected, the insurer has grounds to contest the claim.
How much does EDR cost?
Prices vary by vendor and volume. Rough ranges for a small business:
- Business antivirus: $3 to $6 per device per month
- EDR software: $5 to $15 per device per month
- MDR, with monitoring included: $10 to $30 per device per month
Many managed IT providers bundle EDR or MDR into their monthly fee. Ask yours what you have today.
Is Microsoft Defender good enough?
Be precise about which Defender. The name covers several products.
- Microsoft Defender Antivirus comes free with Windows 10 and 11. It is a solid antivirus. It is not EDR.
- Microsoft Defender for Business adds EDR features for companies with up to 300 users. It is included in Microsoft 365 Business Premium and sold on its own.
- Microsoft Defender for Endpoint is the enterprise product.
If you already pay for Business Premium, you own an EDR tool. Someone still has to deploy it to every device and watch its alerts.
How do I choose an EDR or MDR product?
Ask these questions.
- Who watches the alerts, and during what hours?
- What actions will the provider take without calling me first, and which ones need my approval?
- How fast do they respond to a serious alert?
- Does the product cover Windows, Mac, and servers?
- Can it isolate a device and roll back ransomware changes?
- How does it perform in independent tests, such as the MITRE ATT&CK evaluations?
- Can someone with administrator rights on a computer turn it off? Good products resist tampering.
- What reports will I receive, and can I show them to my insurer or an auditor?
- Does it work with my IT provider’s tools?
Can I run antivirus and EDR together?
Most EDR products include their own antivirus component and replace the old one. Running two antivirus engines side by side causes slowdowns and conflicts. Follow the vendor’s guidance, and remove the old product fully before installing the new one.
Does EDR replace my other protections?
No. EDR detects and limits an attack in progress. You still need the controls that prevent one and the ones that let you recover:
- Multi-factor authentication
- Prompt software updates
- Tested, offline backups
- Email filtering
- Limited administrator rights
- Staff training, since many attacks start with a phishing email
What are the common mistakes?
- Installing EDR on workstations and skipping the servers, where the valuable data lives
- Leaving a few “problem” computers unprotected
- Sending alerts to an inbox nobody reads
- Running the product in alert-only mode, so it reports attacks and blocks nothing
- Assuming the IT provider monitors alerts without confirming it in writing
- Buying the tool and never testing whether anyone responds
Your next step
Ask your IT provider three questions this week: which endpoint protection do we run, is it on every computer and server, and who responds to an alert at night? Cerberus Cybersecurity reviews endpoint protection as part of our risk and compliance assessments and helps you answer insurance applications with evidence. Contact us to schedule a review.