EDR: why antivirus alone is no longer enough

The antivirus icon is green — but an attacker logging in with a stolen password runs no virus. What EDR is, how it differs, and when your company needs it.

There is antivirus on every computer. The icon is green, a scan runs now and then, no alerts. Security: handled. That is how it looks in most companies — and for twenty years, it was enough.

Except an attacker who logs in with a stolen password runs no virus. There is nothing for the antivirus to find.

Attacks on smaller companies today rarely start with a “virus”. They start with a password — from phishing or from a data leak — a login through remote access, and then quiet work with perfectly ordinary tools that are already in the system. None of that is a malicious file. That gap is exactly what EDR exists for.

What EDR is — in plain language

EDR (Endpoint Detection & Response) watches behaviour, not files. It doesn’t only ask “is this file on the virus list”, but “why did the accountant log in at 3 a.m. from abroad”, “why did Word just launch PowerShell”, and “why is this machine encrypting thousands of files”. The second half of the name — Response — means it can act: cut a suspicious machine off the network before the problem spreads.

Antivirus vs. EDR, on one example

A scene we know from practice: your accountant receives an invoice. It looks like it came from your supplier — only the account number is different. The antivirus stays silent; there is no virus in the attachment, it is “just” fraud. EDR doesn’t see that phase either — but the moment an attacker gains access and starts behaving unlike your people, that behavioural pattern is precisely what EDR is built to catch. Antivirus catches known evil. EDR catches foreign behaviour.

An attack with no virus, step by step

To show what we mean — the typical course of an attack on a smaller company, as incident investigations describe it:

Step 1: a password. An employee uses the same password at work as in an online shop that got breached. Or types it into a convincing fake login page. No virus, no alarm.

Step 2: a login. The attacker signs into company e-mail with that password. To the system it is just a login — merely at an odd hour, from an odd place.

Step 3: silence and preparation. He sets a mailbox rule that forwards anything about invoices, and reads for weeks. He learns who pays whom, what your invoices look like, when they go out.

Step 4: the strike. At the right moment, your customer receives an invoice for a large order — yours, except for the account number. Or the attacker moves deeper through remote access and encrypts what he finds overnight.

The antivirus has nothing to catch in this whole story — there is no malicious file anywhere. EDR gets its chance at steps two and three: a login that breaks the pattern, a suspicious mailbox rule, behaviour your people don’t exhibit. That is exactly what it was built for.

When antivirus is enough — honestly

Yes, we’ll write this even though we sell EDR. A small company, everything in the cloud, two-factor authentication on, tested backups, no remote access into an internal network — there, a modern antivirus is a reasonable baseline and EDR can wait. Basics first: two-factor authentication and clean account hygiene stop more attacks than any additional tool.

When it stops being enough

Dozens of computers and people, shared drives or a server, remote access (accountant from home, a service company into production), data whose encryption would stop your operations — or an insurer whose cyber questionnaire asks about EDR directly. At that point EDR is the logical next step after the basics: patching, backups and two-factor authentication.

What EDR cannot do — so you don’t buy a miracle

EDR does not replace the basics. It won’t fix weak passwords without two-factor authentication, won’t replace backups or patching, and won’t stop a human who approves a fraudulent payment because the e-mail looked right. It is also not “buy and forget”: badly deployed EDR either cries wolf until everyone ignores it, or is tuned so gently it never cries at all. Anyone selling EDR as the answer to everything is selling a feeling. The order of investment should be: two-factor authentication and account hygiene → tested backups → patching → and only then EDR.

What EDR costs — and what the price is made of

Two components. The tool — licensed monthly per device or user; the software itself is accessible to small companies these days, in the hundreds of crowns per device per month depending on vendor and tier. The people — tuning, watching and responding; either your own (unrealistic for smaller companies) or as a managed service. The second component is what separates a tool from protection — and it is the one most often “saved on” by simply leaving it out. Add a one-off deployment: installing agents and two to four weeks of tuning while the system learns what normal looks like at your company. Our prices are public, as always: for your device count, the online calculator shows the number instantly.

What to ask an EDR provider

Four questions that separate a service from a box. “Who watches the alerts — including nights and weekends?” “What exactly will you do when the system reports file encryption at midnight?” The answer should be: we isolate the machine from the network within X minutes and call you by an agreed procedure. “What will we see?” A monthly summary a human can read, not access to a console you don’t understand. “What does deployment cost, and what does a month cost?” The price of EDR is always tool plus people. A quote for the tool alone means nobody planned the people.

One warning: EDR without a human is an expensive blinking light

EDR generates alerts — and someone has to read them and act, including on Friday night. A tool nobody watches is just a pricier green icon. That is why EDR for smaller companies is sold as a managed service: the tool plus the people who watch it. When you shop for EDR, ask mainly this: who is watching, and what will they do when it goes off at midnight?

Start with what shows from the outside

You don’t have to take our word for any of this. Run our free online security audit — 13 checks, 5 minutes, no meeting. Enter your company domain and see what the internet knows about your IT: leaked passwords, e-mail configuration, exposed services. The report lands in your inbox. No salesperson will call — we only get in touch if something changes for the worse.

Frequently asked questions

Is Microsoft Defender an EDR?

Depends which one. The Defender built into Windows is an antivirus. The paid Microsoft Defender for Business / for Endpoint tiers do include EDR capabilities — for companies on Microsoft 365 they are usually the most direct route.

Does a ten-computer company need EDR?

Usually not first. Two-factor authentication, backups and patching come before it (see the order of investment above). EDR earns its place once remote access, shared data or your insurer’s questionnaire enter the picture.