Cybersecurity services
Practical cybersecurity: assessments, endpoint protection, email security, training, incident readiness and 24/7 monitoring for managed-service clients.
Endpoint detection and response (EDR) watches what happens on laptops, desktops and servers, not just which files arrive. We help you choose an EDR platform, roll it out without disrupting work, tune it so alerts mean something, and monitor it 24/7 for managed-service clients.
Endpoint detection and response (EDR) is security software that runs on each laptop, desktop and server, records what happens on it, and flags behaviour that looks like an attack. When something suspicious happens, such as a process trying to dump passwords or encrypt files, EDR can alert an analyst and, if needed, isolate the device from the network while the rest of the organisation keeps working.
The software is only part of the value. Promatics handles the whole lifecycle: selection, deployment, tuning and management, and, for managed-service clients, 24/7 monitoring and response.
EDR catches what gets past other defences, so it works best as one layer among several:
Many cyber insurers now ask specifically whether EDR is deployed on all endpoints and whether its alerts are monitored. We document coverage and monitoring, so you can answer those questions accurately.
We deploy and manage EDR platforms including Microsoft Defender for Endpoint and Defender for Business, CrowdStrike Falcon, SentinelOne and Fortinet's FortiEDR. The right choice depends on your devices, the licences you already own, how alerts will be monitored and your budget. If you already pay for EDR through another subscription, we start there.
An EDR alert is only useful if someone looks at it. For managed-service clients, we provide round-the-clock monitoring of key infrastructure, computers and servers, including nights and holidays. Alerts are triaged against agreed playbooks: some are closed as harmless, some lead to a call to your named contact, and serious ones can lead to isolating a device straight away. Response targets are set in the service agreement.
You receive regular reports showing detections, device coverage, devices that have stopped reporting and any recommended changes.
EDR platforms send device telemetry to the vendor's cloud, which is usually hosted outside Nigeria. Where data location matters to you, we check the storage locations each vendor offers and record the choice made. We also review the vendor's terms with the Nigeria Data Protection Act 2023 in mind, including its rules on transfers outside Nigeria, and with any requirements from your sector regulator, such as the CBN for banks and payment service providers. This is not legal advice.
The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.
Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.
Each stage ends with something you can review before the next one starts.
Count devices, check current protection and licences, and confirm requirements from insurers or clients.
Output: Endpoint inventory and platform recommendation.
Deploy to a small group, check performance, and test the business applications that matter most.
Output: Pilot results and adjusted policies.
Deploy group by group, remove old antivirus, and confirm every device is reporting in.
Output: Coverage report.
Review early alerts, set exclusions carefully, and test detection and device isolation.
Output: Tuned policies and test evidence.
For managed-service clients, 24/7 monitoring and triage using agreed playbooks, with regular reporting.
Output: Monitoring reports and reviewed playbooks.
We do not publish package prices. Each estimate is based on an agreed scope, in naira, with taxes shown separately. These are the things that move the number most:
Antivirus mostly blocks known malicious files. EDR records behaviour on the device, such as unusual processes, credential theft or movement between machines, and lets an analyst investigate and isolate the device. Read more in EDR vs antivirus.
Possibly not. Some Microsoft 365 plans, such as Business Premium, include Defender for Business. We check what you already own before recommending anything new.
Modern EDR agents are designed to be light, but some business applications need testing or carefully chosen exclusions. That is why we pilot before rolling out to everyone.
For managed-service clients, alerts are monitored 24/7 and handled according to agreed playbooks, which can include isolating a device from the network. Response targets are set in the service agreement.
No. EDR is one layer. It works alongside MFA, email security, patching and tested backups.
Practical cybersecurity: assessments, endpoint protection, email security, training, incident readiness and 24/7 monitoring for managed-service clients.
The practical difference between antivirus and EDR, what deploying EDR changes for your team, and how to roll it out without disrupting users.
We monitor, manage, support and secure your IT systems and users under one agreement, for a fixed and predictable monthly fee.
Tell us how many devices you have and what protects them today. We will reply to arrange a conversation.