Article

EDR vs antivirus: what changes when you deploy endpoint detection and response

Antivirus tries to block known-bad files. Endpoint detection and response records what happens on each device, spots suspicious behaviour and lets someone investigate and contain an attack, which only helps if someone is watching and ready to act.

The short answer

AntivirusEndpoint detection and response (EDR)
Main jobPrevent known malicious files and programs from runningDetect suspicious behaviour, investigate it and respond
How it decidesSignatures, reputation and some behaviour rulesContinuous recording of process, file, network and user activity, analysed for attack patterns
What you getBlocked or quarantined filesAlerts with a timeline of what happened, plus response actions
Response optionsQuarantine or delete a fileIsolate a device from the network, stop processes, collect evidence, roll back some changes
Who operates itMostly automaticNeeds people to triage alerts and act, in-house or through a provider

Most modern endpoint security products include both functions. The real change when you move to EDR is not the software but the operating model: someone must review alerts and respond, including outside business hours.

Why antivirus alone is no longer enough

Many attacks today use no malicious file at all. Attackers sign in with stolen credentials, use built-in administration tools, or run scripts in memory. Antivirus may see nothing unusual. EDR looks for sequences of behaviour, such as an office document launching a scripting tool that then contacts an unfamiliar server, and records enough context to reconstruct what happened.

Microsoft, for example, describes Defender for Endpoint as a platform that helps organisations "prevent, detect, investigate, and respond to advanced threats" and lists EDR alongside next-generation protection, attack surface reduction, vulnerability management and automatic attack disruption (Microsoft Learn). Other platforms, such as CrowdStrike and SentinelOne, offer comparable capabilities.

Can EDR run alongside existing antivirus?

Often, yes. Some products are designed to work next to another vendor's antivirus. Microsoft's EDR in block mode, for example, can act on behavioural detections when Microsoft Defender Antivirus is running in passive mode behind a non-Microsoft antivirus product, although some protections are unavailable in that configuration, and the feature requires Defender for Endpoint Plan 2 (Microsoft Learn). Running two full products in active mode on the same device usually causes conflicts; follow each vendor's guidance.

What changes when you deploy EDR

1. Alerts need owners. EDR produces alerts that need a human decision: is this real, and what do we do? Decide who reviews them, how quickly, and what happens overnight and on weekends. Options are an internal security team, a managed detection and response (MDR) service, or a managed service provider monitoring on your behalf.

2. Response needs authority. Isolating a laptop or a server interrupts work. Agree in advance who may isolate which devices, when business owners are called, and how a device is released. Where a branch or site depends on a single server and a link that is already unreliable, decide this before an incident, not during one.

3. Tuning takes time. Early weeks bring false positives from line-of-business software, scripts and administration tools. Plan a tuning period and document every exclusion with a reason.

4. Coverage must be complete. An attacker will use the device you forgot. Include servers, Mac and Linux devices, virtual desktops and remote laptops, and alert on devices that stop reporting. Devices that spend long periods offline, for example because of power or connectivity problems, will report late, so separate "offline" from "gone missing" in your alert rules.

5. Visibility raises privacy questions. EDR records detailed activity on devices employees use. Tell staff what is collected and why, restrict who can view the data, and set retention periods. The Nigeria Data Protection Act 2023 (NDPA) applies to employee personal data as well as customer data, so a lawful basis, transparency and sensible retention matter here; take advice from your legal adviser or data protection officer if unsure.

6. It connects to everything else. EDR is most useful when joined with identity, email and cloud signals, so an investigation can follow an attack from a phishing email to a compromised account to a device.

Licensing and cost drivers

Costs depend on the number and type of devices, the product tier and whether monitoring is included. EDR capabilities are often limited to higher tiers. In Microsoft's range, for example, EDR in block mode requires Plan 2, and Microsoft 365 E5 includes Defender for Endpoint Plan 2 (Microsoft Learn). Because most endpoint security licences are priced in US dollars, exchange-rate movements affect the naira cost over a multi-year term, so check the billing currency and renewal terms. Check what your existing licences already include before buying another product. Human monitoring, whether in-house or through a provider, is usually a larger ongoing cost than the licence.

A practical rollout

  1. Inventory every endpoint and server, and the software that needs exclusions.
  2. Pilot on a representative group, including IT and a few heavy users of specialist software.
  3. Start in a detect-only or audit mode where the product supports it, review what would have been blocked, then move to prevention.
  4. Turn on tamper protection so users and malware cannot disable the agent.
  5. Write response playbooks for common alerts: suspicious sign-in on a device, ransomware behaviour, credential theft tools.
  6. Roll out in waves, watching performance and support tickets.
  7. Test with safe simulation tools to confirm alerts reach the right people and that isolation works.
  8. Review monthly: alert volumes, coverage gaps, exclusions and response times against the targets you set.

Readiness checklist

Coverage

  • Complete device inventory, including servers and non-Windows devices
  • Alerting for devices that stop reporting

Operations

  • Named owners for alert triage during and outside business hours
  • Authority to isolate devices agreed with management
  • Response playbooks for the most likely incidents

Configuration

  • Pilot group and audit period planned
  • Exclusions documented with reasons
  • Tamper protection enabled

Governance

  • Staff informed about monitoring; access and retention of EDR data defined
  • Existing licences reviewed for included EDR features

Limitations

EDR shortens the time between an attack starting and someone noticing, but it does not replace the basics. Security agencies such as CISA consistently list patching, strong authentication, tested backups, access control and an incident response plan alongside security software (CISA). If you need help selecting, deploying or monitoring EDR, see our EDR deployment and management service.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Microsoft Defender for Endpoint, Microsoft Learn
  2. Endpoint detection and response in block mode, Microsoft Learn
  3. #StopRansomware, Cybersecurity and Infrastructure Security Agency (CISA)

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts