A security analyst reviewing endpoint alerts on multiple monitors

Business ContinuityCybersecurity

What is EDR? How endpoint detection and response protects you

Endpoint detection and response (EDR) is security software on each laptop, desktop and server that records what programs and users do, flags behavior that looks like an attack, and can cut a device off from the network in seconds. Antivirus asks whether a file is known to be bad. EDR asks whether what is happening looks like an attack, whatever the file is called.

That difference matters at 11 p.m. on a Friday, when a bookkeeper’s laptop starts renaming and encrypting files on the shared drive using legitimate Windows tools and a program no scanner has seen before. Antivirus stays quiet. EDR is built to catch it.

What is EDR doing on each device

An endpoint is any device that connects to your network: laptops, desktops, servers, and often phones and tablets. The EDR agent continuously records which programs start, what files they touch, which network connections they make and what changes they make to the system. That data is analyzed for patterns that look like an attack. When it finds one, it alerts a security team and can act on its own. Microsoft describes EDR’s core functions as detection, investigation, and isolation and remediation, backed by threat intelligence about known attacker techniques.

How EDR compares with antivirus, XDR and MDR

Traditional antivirus mostly compares files to signatures of known malware. That still blocks a lot, but many attackers now use stolen passwords, remote access tools your IT team also uses, or scripts built into Windows, and none of those look like a malicious file. A spreadsheet that launches PowerShell, which downloads a file and starts encrypting hundreds of documents, is suspicious no matter what anything is named.

Monitor and laptop showing code on a desk
TermWhat it does
AntivirusBlocks known malware, mainly by signature
Endpoint protection platform (EPP)Antivirus plus prevention features such as device control, firewall policy and attack surface reduction rules
EDRContinuous recording, behavioral detection, investigation tools and response actions such as isolation
XDR (extended detection and response)EDR plus signals from email, identity, network and cloud services, correlated into one view
MDR (managed detection and response)People: a security operations center that watches the alerts around the clock and responds for you

Isolation is the feature that matters most

48%

of breaches in Verizon’s 2026 Data Breach Investigations Report involved ransomware, up from 44% the year before

Ransomware is a race. Once attackers are inside, they move from the first device to file servers, backups and other systems, and the difference between one encrypted laptop and a business-wide outage is often how quickly someone isolates that first machine. An isolated device stays connected to the security platform but can’t talk to anything else, so the attack stops spreading while analysts investigate. EDR also keeps a timeline of which account was used, which files were touched and where the attacker tried to go next, which is what you need when an insurer or regulator asks questions.

Who watches the alerts

EDR produces alerts at all hours, and many need a person to decide whether they are real. An alert nobody reads until Monday is just a detailed record of how the attack happened. That is why most small and mid-sized organizations run EDR as a managed service. For us it is standard: every client has a 24/7 security operations center reviewing alerts and isolating devices when needed, then handing us a clear summary of what to fix.

If you are comparing providers, ask:

  • Who reviews alerts at 2 a.m. on a Sunday, and can they isolate a device without waiting for approval?
  • Which devices are covered: workstations, servers, Macs and anything else that touches company data?
  • How are you notified, and what report do you get after an incident?
  • How long is endpoint activity data kept for investigations?
  • How does the security team coordinate with whoever restores your systems from backup?

Microsoft says Microsoft 365 Business Premium includes EDR with automated investigation and remediation for businesses with up to 300 users. A license is a starting point. Someone still has to configure it, onboard every device and respond to what it finds.

The basics EDR depends on

  • Patch operating systems, browsers, apps and firmware on a schedule. Firmware is easy to forget because it doesn’t nag like Windows Update.
  • Retire unsupported systems. Windows 10 reached end of support on October 14, 2025. Most of our clients have moved to Windows 11, and we replaced the machines that couldn’t run it.
  • Check Secure Boot and TPM. Windows 11 requires TPM 2.0 and Secure Boot capable firmware. Microsoft’s original 2011 Secure Boot certificates began expiring in June 2026, so confirm your devices received the 2023 certificates through Windows Update or firmware updates.
  • Use MFA everywhere and remove local admin rights from daily-use accounts.
  • Use application control, which stops many attacks before EDR has to step in.
  • Encrypt every laptop and set up remote lock and wipe.

EDR, compliance and recovery

No small-business regulation names EDR, but it maps well to what the rules ask for. The HIPAA Security Rule calls for procedures to guard against, detect and report malicious software and to monitor log-in attempts. The FTC Safeguards Rule requires covered financial firms to monitor and test their safeguards. EDR’s alerts, isolation records and incident timelines are the evidence that those controls work. Containment also limits how much you have to restore, and the timeline tells you which restore point is clean, which ties EDR directly to business continuity. For how it fits with other layers, see our post on defense in depth and our explainer on malware vs ransomware.

The question to settle now is who would respond to an attack on your network tonight. Book an intro call and we will walk through how our cybersecurity coverage would handle it.

FAQ

Frequently asked questions

What is EDR?

EDR is security software on each laptop, desktop and server that records what programs and users do, flags behavior that looks like an attack and can cut a device off from the network in seconds. Antivirus checks whether a file is known to be bad; EDR checks whether the activity looks like an attack, whatever the file is called. Most small organizations run it as a managed service, with a security team watching alerts around the clock.

What does EDR stand for?

EDR stands for endpoint detection and response. An endpoint is any device that connects to your network, such as a laptop, desktop, server, phone or tablet.

Sources: Verizon 2026 Data Breach Investigations Report; Help Net Security: Verizon 2026 DBIR findings, May 2026; Microsoft: What is EDR?; Microsoft Learn: Defender for Business FAQ; Microsoft Learn: Windows 10 release information and end of support; Microsoft Learn: Windows 11 requirements; Microsoft Learn: Update Secure Boot certificates for Windows devices; eCFR: 45 CFR 164.308, HIPAA administrative safeguards; eCFR: 16 CFR 314.4, FTC Safeguards Rule elements.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.