IT security

EDR

Also known as: Endpoint Detection and Response

In short

EDR (Endpoint Detection and Response) continuously monitors endpoints for suspicious behavior and can stop attacks directly on the device.

Traditional antivirus software detects malware by matching it against known signatures and raises an alert when a file matches a known threat. EDR (Endpoint Detection and Response) goes further: it continuously observes what happens on an endpoint – which processes start, which files change, which connections get opened – and flags unknown attacks based on their behavior rather than a known signature.

In practice, an agent runs on every laptop, server, and often mobile device, logging this activity and reporting it to a central analysis point. When the system spots a suspicious pattern, such as a program that suddenly starts encrypting large numbers of files, it can automatically isolate the affected device from the network and stop the process before the damage spreads. Afterward, security staff can trace exactly how an attack began.

A common mistake is treating EDR as a replacement for traditional antivirus rather than a complement to it. An EDR system whose alerts nobody reviews offers no better protection than having none at all.

What it means in practice

For an SMB, EDR matters most on servers and on the devices of staff with access to sensitive data, because it catches attacks that traditional antivirus misses. A sign that it's missing is when an infection only becomes visible once files are already encrypted or data has already left the network. NDVDL deploys EDR on endpoints and folds alert review into ongoing support.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.