Resource
EDR versus traditional antivirus
Traditional antivirus compares files against a list of known bad ones, which is why it misses anything new. Endpoint detection and response watches behaviour instead. That difference matters, but it comes with a condition most businesses miss: the tooling only works if somebody reads what it says.
What each approach detects
The gap is not marginal. Most modern attacks are specifically designed to defeat the first column.
| Threat type | Antivirus |
|---|---|
| Known malware fileDetected | Detected |
| Newly created variantUsually detected by behaviour | Usually missed |
| Fileless attack in memoryDetected | Missed |
| Legitimate tool used maliciouslyDetected by context | Missed |
| Stolen credential used normallyDetected by anomaly, if reviewed | Missed |
| Bulk file encryption startingDetected and can be halted | Sometimes detected late |
What EDR adds beyond detection
The recording capability matters as much as the blocking.
- A timeline of what a process did, which is how you learn what was actually reached
- The ability to isolate a device from the network while leaving it reachable for investigation
- Rollback of changes on some platforms, including certain encryption events
- Evidence that survives the incident, which several compliance frameworks require
- Visibility across every managed endpoint from one place rather than machine by machine
The condition nobody mentions
EDR generates alerts continuously, most of them benign. Its value appears only when somebody with the experience to tell the difference reviews them promptly.
Businesses of this size rarely have anyone rostered to look at a security console at two in the morning, which is exactly when the interesting alerts arrive. Attacks are timed for Friday evenings and public holidays deliberately.
This is why the honest comparison is not antivirus against EDR. It is antivirus against EDR with somebody watching it, which is a managed service rather than a licence purchase.
Common questions
Answered before you ask.
Is the EDR in our Microsoft licence good enough?
The tooling in the higher Microsoft tiers is genuinely capable and for many businesses there is no need to buy something else. The question is not whether the product is adequate, it is whether anyone reviews its output. A capable platform generating alerts nobody reads provides compliance evidence rather than protection.
Do we still need antivirus if we have EDR?
EDR platforms include the signature based detection that antivirus performs, so running both is usually duplication rather than defence in depth. Consolidating to one is normally cheaper and avoids the conflicts that come from two products both trying to inspect the same activity.
Will EDR slow our machines down?
Modern agents are considerably lighter than the antivirus suites people remember. Where a genuine conflict occurs, usually with line of business software doing something unusual, it is resolved with a scoped exclusion rather than by disabling protection.
Related
Read next.
Managed detection and response
24 by 7 human review of security alerts, with authority to contain.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Ransomware protection for small business
How attacks actually start, which controls stop them, and what to do in the first hour.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.