So what is EDR? Endpoint detection and response records what happens on your computers so somebody can work out what went wrong and stop it spreading. It watches behaviour as well as matching files against a list of known threats, and it keeps a history: which process started which other process, what changed on disk, what connected where, and which account was signed in at the time. Antivirus answers whether a given file is known to be bad. EDR answers a second question, which is what happened on this machine and who was watching when it did. Businesses under a hundred staff usually have the first answer and no route to the second.

What is EDR recording that antivirus never keeps

Antivirus decides at a single moment: block, quarantine, or allow. Once that moment passes, nothing is retained.

 AntivirusEDR
What it looks atFiles, against known signaturesProcess behaviour and sequences of events
What it keepsThe decision it madeA history you can investigate afterwards
The attack it handles wellMalware arriving as a fileValid credentials being misused, with no file involved
What it producesA block or a quarantineAlerts that need a human to interpret
What it costs youLittle, and often already includedA subscription, and either your time or somebody else’s

That difference matters against the pattern smaller UK businesses now meet, where an attacker signs in with valid credentials, phished or bought, then uses ordinary administrative tools. No malicious file exists, so nothing is there for a scanner to match.

Behavioural monitoring catches that shape by noticing the sequence: a sign-in from an unusual location, then a mailbox rule forwarding invoices elsewhere, then a reach for a file server the account has never touched. Each event is unremarkable alone. Together they are an incident, and only a system holding the history can see it, which is the reasoning behind identity threat detection. Both layers sit on the everyday controls covered by our managed IT support.

What the NCSC guidance says about antivirus, read in full

The NCSC’s device security guidance on antivirus and other security software does say that ‘advances in malware and changes in underlying platforms have limited the effectiveness of this approach’, meaning signature scanning. The same page also says malware infection, often ransomware, is one of the most common ways IT systems are compromised, and that ‘Windows, macOS and Android include built-in AV products by default and these will meet the needs of many organisations’.

Its strongest line is conditional. ‘If you are confident that your devices cannot execute known malware, AV offers very limited value’, and the guidance lists what would make that true: software arriving only through a public app store or an enterprise catalogue, or execution policies stopping code from non-trusted signers and from writable locations. The first two describe locked-down mobile platforms, and the page says you should not need AV on Chrome OS, Android and iOS by default. The others are reachable on Windows through application control, which most SME fleets have not implemented, and that is why the page says to make sure built-in protection is on.

Two things follow. The NCSC does not recommend EDR anywhere on that page, so a supplier telling you it does is overstating the case. And the NCSC addresses that guidance to cyber security professionals, large organisations and the public sector. Its separate Small Business Guide, written for organisations with 0 to 49 employees, reports that one in two small businesses suffers a cyber incident every year.

Detection without response is a dashboard nobody opens

Detection produces alerts, and alerts need somebody who understands them, at the hour they fire.

An alert landing in an inbox overnight and read next morning describes an intrusion that has finished. The tooling worked. The outcome matched having none.

Software gives you the recording. An outcome means somebody triages the alert, isolates the machine and calls you, while your office is empty. For a business with no security staff, only the second changes anything, which is why this market has moved towards services with analysts attached instead of licences with dashboards.

What a small business should do first

EDR is rarely the first purchase. The controls underneath earn more and cost less.

  1. Switch on the malware protection already built into your operating system and confirm it is updating. The NCSC’s guidance on what an antivirus product is makes the point that enabling built-in protection makes you instantly safer.
  2. Get multi-factor authentication onto every cloud service, including the small ones.
  3. Remove local administrator rights from everyday accounts.
  4. Patch third-party software on a schedule you can evidence.
  5. Then add detection, and decide who watches it.

Skip the first four and buy the fifth and you have an expensive recording of an incident they would have prevented. Our guide to building a cyber incident response plan covers the rehearsed response that contains one.

One caution on stacking. The NCSC advises against running more than one antivirus product on a device, because the benefit is minimal and the products can conflict. Detection should work with what the operating system already provides.

How Unite delivers detection, and whose analysts do the watching

We deliver endpoint detection through our partnership with Huntress, as our write-up of what happens when a threat is detected sets out, and it is worth being precise about who does what.

Huntress operates the security operations centre, and describes its own service as providing ’24/7 threat hunting, monitoring and response’. Its analysts triage alerts and can isolate a host. We deploy the agent, configure it against your estate, hold the account and act on what comes back.

That resolves the stacking caution. Huntress states that when Microsoft Defender Antivirus is paired with its EDR, ‘we’ll manage it for you at no additional cost‘, centrally managing configurations, exclusions and detections. So step one and the detection layer are one estate, managed together.

We do not run our own operations centre, and a provider your size claiming to is worth a follow-up question. What matters is whether somebody competent is looking in the middle of the night, and can reach your machines.

Deciding whether it is time

Three signs point to yes. You hold data whose loss would end customer relationships. An insurer or customer has started asking what runs on your endpoints. Or staff sign into cloud services from unmonitored devices.

Against that, if you have no multi-factor authentication, shared administrator accounts and a server on an unsupported operating system, spend the money there first.

For a straight answer on where your business sits, our managed IT and security service includes the security assessment: we review your setup, explain what the detection layer covers and give you a clear recommendation.